Analyse FRST

Falcão12 Messages postés 232 Statut Membre -  
Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour,

J'aurais besoins d'une analyse de 3 fichiers de FRST que j'ai obtenu (pour pouvoir supprimer un virus).

Voici les 3 lien:
- https://pjjoint.malekal.com/files.php?id=20150118_h11r6l8k10h8

- https://pjjoint.malekal.com/files.php?id=20150118_j12l6b8g10y11

- https://pjjoint.malekal.com/index.php

Merci d'avance

1 réponse

  1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Salut,

    Voici la correction à effectuer avec FRST.
    Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

    Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
    Copie/colle dedans ce qui suit :

    ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
    ProxyServer: [.DEFAULT] => http=127.0.0.1:49474;https=127.0.0.1:49474 [Attention - Possible Proxy Malicieux]
    CHR HKLM\...\Chrome\Extension: [gfkbfjcbkhnmiignagpkiijohkcdkffb] - No Path
    Task: {177AE4E7-6EC4-42AF-884A-35517AFAFE5A} - \RegClean Pro_DEFAULT No Task File <==== ATTENTION
    Task: {2110A460-1304-4F88-9556-E74471D778CA} - System32\Tasks\TaskUserUpdate_wp => C:\Users\Edin\AppData\Roaming\~dstvcot.exe
    Task: {2E3F4C48-2AB7-41E0-B772-09D22A72B527} - System32\Tasks\WIN-fdfEfEfAfC => C:\Users\Edin\AppData\Roaming\~cqtpjxo.exe
    Task: {517F9993-8FAB-4601-8B91-2D722E7C28E1} - System32\Tasks\Jj7k3jGfKMJ0vqa => C:\Users\Edin\AppData\Roaming\0Zx6OUS\yOtiIqE.exe
    Task: {77550FB4-20A4-4C02-9704-4512799A8DA9} - System32\Tasks\WIN-statsSystem => C:\Users\Edin\AppData\Local\Microsoft\WinU\~mxgexox.exe
    Task: {788C9060-24F4-41A2-8A03-42267855FB2D} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\Edin\AppData\Roaming\~dqczbwj.exe
    Task: {7A753B64-D569-4CAA-9B51-BE121EA2F967} - \RegClean Pro No Task File <==== ATTENTION
    Task: {AA1C23C6-CD76-4B50-8FF2-02FCD776E1CC} - System32\Tasks\gtaUpt => C:\Program Files\shopperz\zaeed.bat
    Task: {ACA42A1B-57E4-4898-978D-0A5B5D7D9D54} - \RocketTab Update Task No Task File <==== ATTENTION
    Task: {B097E451-0EE5-48E6-B7B1-486B391F3BE9} - System32\Tasks\WIN-statsAdmin => C:\Users\Edin\AppData\Local\Microsoft\WinU\~nacvttg.exe [2014-08-06] () <==== ATTENTION
    Task: {EAE1295A-673E-4418-994E-9421450BD7DF} - \BlockAndSurf Update No Task File <==== ATTENTION
    Task: {FF3B7C2B-823F-4400-8BDB-7AFA139EA441} - \SmartWeb Upgrade Trigger Task No Task File <==== ATTENTION
    C:\Users\Edin\AppData\Local\Microsoft\WinU
    2014-12-22 11:39 - 2015-01-17 23:20 - 00000000 ___DC () C:\Users\Edin\AppData\Roaming\EYhkJge
    2014-12-21 21:52 - 2015-01-17 23:20 - 00000000 ___DC () C:\Users\Edin\AppData\Roaming\hiM552n
    2014-12-21 20:47 - 2015-01-17 23:20 - 00000000 ___DC () C:\Users\Edin\AppData\Roaming\3EtNUDT
    2014-12-21 11:31 - 2015-01-17 23:20 - 00000000 ___DC () C:\Users\Edin\AppData\Roaming\15oWwWJ
    2015-01-17 23:20 - 2014-11-21 21:25 - 00000000 ___DC () C:\Users\Edin\AppData\Roaming\EF9kTEg
    2015-01-17 23:20 - 2014-11-21 21:25 - 00000000 ___DC () C:\Users\Edin\AppData\Roaming\anmwp9N
    2015-01-17 23:20 - 2014-11-21 20:21 - 00000000 ___DC () C:\Users\Edin\AppData\Roaming\hoTNjpV
    2015-01-17 23:20 - 2014-11-21 20:21 - 00000000 ___DC () C:\Users\Edin\AppData\Roaming\9YutNcI
    2015-01-17 23:20 - 2014-11-21 20:21 - 00000000 ___DC () C:\Users\Edin\AppData\Roaming\0Zx6OUS

    Une fois, le texte coller dans le bloc-note.
    Menu Fichier puis Enregistrer sous.
    A gauche, place toi sur le bureau.
    Dans le champs en bas, nom du fichier mets : fixlist.txt
    Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

    Relance FRST et clic sur le bouton Fix
    Selon comment un redémarrage est nécessaire (pas obligatoire).
    Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

    Redémarre l'ordinateur

    0