*LABAL* besoin d'aide ZHPDiag ou autre

Ringolito -  
Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour,

J'ai vu apparaitre le programme *LABAL* au démarrage dans Ccleaner. Quelqu'un à déjà eu ce soucis mais concernant les malware je me dis que chaque cas est spécifique et que j'en ai peut être d'autres...

Voici le lien ZHPDiag si quelqu'un peut m'aider
http://pjjoint.malekal.com/files.php?id=ZHPDiag_20150213_n15k9p12k13i14

Et voici un log AdwCleaner:
# AdwCleaner v4.110 - Logfile created 13/02/2015 at 20:32:04
# Updated 05/02/2015 by Xplode
# Database : 2015-02-13.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Ringolito - RINGOLITO-PC
# Running from : C:\Users\Ringolito\Downloads\adwcleaner_4.110.exe
# Option : Scan

[ Services ] *****
[ Files / Folders ] *****

Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Users\Ringolito\AppData\Local\globalUpdate
Folder Found : C:\Users\Ringolito\AppData\Roaming\OpenCandy

[ Scheduled tasks ] *****
[ Shortcuts ] *****
[ Registry ] *****

Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\BabylonToolbar
Key Found : HKCU\Software\facemoods.com
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Iminent
Key Found : [x64] HKCU\Software\BabylonToolbar
Key Found : [x64] HKCU\Software\facemoods.com
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Iminent
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AC129BF9-68BF-4BC4-A1DC-ECB62712FF99}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Found : [x64] HKLM\SOFTWARE\Conduit
Key Found : [x64] HKLM\SOFTWARE\facemoods.com
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AC129BF9-68BF-4BC4-A1DC-ECB62712FF99}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}

[ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17631

-\\ Mozilla Firefox v35.0.1 (x86 fr)

-\\ Google Chrome v40.0.2214.111

AdwCleaner[R0].txt - [2611 bytes] - [13/02/2015 20:32:04]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2670 bytes] ##########

Merci d'avance !

3 réponses

  1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Salut

    fais nettoyer et donne le rapport.

    --
    0
    1. Ringolito
       
      Salut Malekal et merci pour ta réponse !

      # AdwCleaner v4.110 - Logfile created 13/02/2015 at 21:35:01
      # Updated 05/02/2015 by Xplode
      # Database : 2015-02-13.1 [Server]
      # Operating system : Windows 7 Ultimate Service Pack 1 (x64)
      # Username : Ringolito - RINGOLITO-PC
      # Running from : C:\Users\Ringolito\Downloads\adwcleaner_4.110.exe
      # Option : Cleaning
              • [ Services ] *****
              • [ Files / Folders ] *****


      Folder Deleted : C:\Program Files (x86)\globalUpdate
      Folder Deleted : C:\Users\Ringolito\AppData\Local\globalUpdate
      Folder Deleted : C:\Users\Ringolito\AppData\Roaming\OpenCandy
              • [ Scheduled tasks ] *****
              • [ Shortcuts ] *****
              • [ Registry ] *****


      Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
      Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}
      Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AC129BF9-68BF-4BC4-A1DC-ECB62712FF99}
      Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
      Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
      Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}
      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AC129BF9-68BF-4BC4-A1DC-ECB62712FF99}
      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
      Key Deleted : HKCU\Software\BabylonToolbar
      Key Deleted : HKCU\Software\facemoods.com
      Key Deleted : HKCU\Software\GlobalUpdate
      Key Deleted : HKCU\Software\Iminent
      Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
      Key Deleted : [x64] HKLM\SOFTWARE\Conduit
      Key Deleted : [x64] HKLM\SOFTWARE\facemoods.com
              • [ Web browsers ] *****


      -\\ Internet Explorer v11.0.9600.17631


      -\\ Mozilla Firefox v35.0.1 (x86 fr)


      -\\ Google Chrome v40.0.2214.111


      AdwCleaner[R0].txt - [2821 bytes] - [13/02/2015 20:32:04]
      AdwCleaner[S0].txt - [2554 bytes] - [13/02/2015 21:35:01]

      ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2613 bytes] ##########
      0
    2. Ringolito
       
      Je vois encore Labal dans ccleaner.
      0
    3. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
       
      et bien enlève le.


      Suis ce tutorial : https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
      Cela va générer deux rapports FRST.
      Envoie comme expliqué, ces deux rapports sur le site http://pjjoint.malekal.com et donne les trois liens pjjoint de ces rapports afin qu'ils puissent être consultés.
      0
    4. Ringolito
       
      Addition:
      http://pjjoint.malekal.com/files.php?id=20150213_g9n15e14b5x9

      FRST:
      http://pjjoint.malekal.com/files.php?id=20150213_l5t6z6x9c15

      Shortcut:
      http://pjjoint.malekal.com/files.php?id=20150213_i12j6c15g11d7
      0
    5. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
       
      Voici la correction à effectuer avec FRST.
      Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

      Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
      Copie/colle dedans ce qui suit :

      HKU\S-1-5-21-443190479-4111740154-2375072180-1000\...\Run: [*LABAL*] => [X]

      Une fois, le texte coller dans le bloc-note.
      Menu Fichier puis Enregistrer sous.
      A gauche, place toi sur le bureau.
      Dans le champs en bas, nom du fichier mets : fixlist.txt
      Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

      Relance FRST et clic sur le bouton Fix
      Selon comment un redémarrage est nécessaire (pas obligatoire).
      Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

      Redémarre l'ordinateur
      0
  2. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    ça n'a pas fonctionné.

    Doit falloir aller la supprimer manuellement.

    Touche Windows + R
    tape regedit et OK.
    Déroule à gauche :
    HKEY_USERs => S-1-5-21-443190479-4111740154-2375072180-1000
    => Software
    => Microsoft
    => Windows
    => Run
    et tu vires *LABAL*
    0
    1. Ringolito
       
      Je ne vois pas de dossier Run. Par contre il y en a un dans Windows > CurrentVersion mais je vois pas LABAL...
      0
    2. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
       
      sinon fais une recherche dans HKEY_USERs sur LABAL, touche F3.
      0
  3. Utilisateur anonyme
     
    Bonjour, pour se promener dans la base du registre
    exemple le virus de la gendarmerie se cache sous la clé SHELL section Winlogon exemple lorsque la machine démarre le virus aussi donc parfois bloque l'accès au bureau .
    pour contourner le virus qui bloque un RUN normal NORMAL BOOT , utiliser un autre RUN système le SAFE BOOT " les options avancées "
    F8
    PS: attention RUN , WINLOGON parfois la clé est occupé par un programme système exemple un antivirus payant avec ses propres paramètres de démarrage ou un logiciel d'empreinte digital

    https://forums.commentcamarche.net/forum/affich-31151593-windows-plante-antivirus-ne-trouve-rien
    0