Clé USB infecté

kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention   -  
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour,

Si joint une photo du contenue de mon flash, je crois qu'il est infecté et mon antivirus ne peux pas le nettoyer




--
A voir également:

3 réponses

Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685
 
Salut,

C'est une infection qui se propage par disques amovibles ( clefs USB, disques externes, cartes flash etc.. )
Tous les disques amovibles insérés depuis que Windows est infecté doivent être vérifiés et nettoyés sinon le simple fait de double-cliquer sur ta clef USB/disque dur externe va réinfecter ton système. Tu trouveras un lien explicatif sur la propagation de ces infections et sur comment s'en protéger :
=> https://forum.malekal.com/viewtopic.php?t=3350&start=

Pour nettoyer les disques amovibles, suivre dans l'ordre les étapes du tutoriel : insère un à un tes clefs USB et disques durs externes que tu as pour les nettoyer. Envoie ensuite les rapports sur http://pjjoint.malekal.com/ et donne les liens menant à ces rapports pour que l'on puisse les consulter.

1°) Remediate VBS Worm

1°) Brancher toutes les clefs USB et autres périphériques amovibles.
  • Télécharger Remediate VBS Worm
  • Lancer l'option B
  • Taper la lettre de la clef USB, par exemple, E et entrée

[color=red]ATTENTION: NE PAS INDIQUER LE LECTEUR DE TON DISQUE DUR ![/color]
  • Va dans "Mon ordinateur" puis disque "C", un rapport "Rem-VBS.log" doit s'y trouver.

Ouvre ce rapport avec le bloc-notes et copie/colle le contenu ici dans une prochaine réponse.


Veuillez appuyer sur une touche pour continuer la désinfection...
0
kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention   1
 
Rem-VBSworm v7.0

=========== - General info:

Running under: khazri on profile: C:\Users\khazri
Computer name: KHAZRI-PC

Operating System:
Microsoft Windowsÿ7 dition Int‚grale

Boot Mode:
Normal boot

Antivirus software installed:

Executed on: 30/03/2016 @ 11:06:17,69

=========== - Drive info:

Listing currently attached drives:
Caption Description VolumeName

C: Disque fixe local

D: Disque fixe local Data

E: Disque CD-ROM

F: Disque amovible GSP1RMCHPXF




Physical drives information:
C: \Device\HarddiskVolume2 NTFS
D: \Device\HarddiskVolume3 NTFS
F: \Device\HarddiskVolume6 NTFS

=========== - Disinfection info:


=========== - USB drive info:

f: selected

USB Device ID:
IDE\DISKTOSHIBA_MK4055GSX_______________________FG011M__\5&38781D8&0&0.0.0

USBSTOR\DISK&VEN_VERBATIM&PROD_STORE_N_GO&REV_1100\1212000000001246&0




Fichier supprim‚ - f:\autorun.inf
WARNING!! Possible Andromeda/Gamarue infection!!
Listing root contents of f:
Le volume dans le lecteur F s'appelle GSP1RMCHPXF
Le num‚ro de s‚rie du volume est EAAC-DEF3

R‚pertoire de F:\

29/04/2015 11:36 120ÿ659 Microsoft_Word.WsF
29/04/2015 11:36 120ÿ659 Microsoft Word.WsF
12/10/2015 21:48 371ÿ156 Download_film.wsf
12/10/2015 21:48 371ÿ156 Download film.wsf
03/12/2015 00:43 107ÿ542 BronCoder.wsf
24/02/2016 10:26 <REP> RECYCLER (2)
24/02/2016 10:27 0 _[$]_TESTFILE_[$]_
24/02/2016 10:27 163ÿ840 @%~%~@%@%~@~@%@@.1
24/02/2016 10:27 124 desktop.ini
24/02/2016 10:27 3 autorun (2).inf
24/02/2016 10:28 <REP> RECYCLER_DETEC
27/03/2016 21:00 <REP> rayan
30/03/2016 10:30 40 RECYCLER
30/03/2016 10:30 <REP> ÿ
30/03/2016 10:31 <REP> .Trashes
30/03/2016 10:31 <REP> Adobe
30/03/2016 10:31 <REP> Adobe (2)
11 fichier(s) 1ÿ784ÿ011 octets
7 R‚p(s) 7ÿ973ÿ949ÿ440 octets libres

USB drive disinfected and files unhidden!!

=========== - USB drive info:

f: selected

USB Device ID:
IDE\DISKTOSHIBA_MK4055GSX_______________________FG011M__\5&38781D8&0&0.0.0

USBSTOR\DISK&VEN_VERBATIM&PROD_STORE_N_GO&REV_1100\1212000000001246&0




WARNING!! Possible Andromeda/Gamarue infection!!
Listing root contents of f:
Le volume dans le lecteur F s'appelle GSP1RMCHPXF
Le num‚ro de s‚rie du volume est EAAC-DEF3

R‚pertoire de F:\

29/04/2015 11:36 120ÿ659 Microsoft_Word.WsF
29/04/2015 11:36 120ÿ659 Microsoft Word.WsF
12/10/2015 21:48 371ÿ156 Download_film.wsf
12/10/2015 21:48 371ÿ156 Download film.wsf
03/12/2015 00:43 107ÿ542 BronCoder.wsf
24/02/2016 10:26 <REP> RECYCLER (2)
24/02/2016 10:27 0 _[$]_TESTFILE_[$]_
24/02/2016 10:27 163ÿ840 @%~%~@%@%~@~@%@@.1
24/02/2016 10:27 124 desktop.ini
24/02/2016 10:27 3 autorun (2).inf
24/02/2016 10:28 <REP> RECYCLER_DETEC
27/03/2016 21:00 <REP> rayan
30/03/2016 10:30 40 RECYCLER
30/03/2016 10:30 <REP> ÿ
30/03/2016 10:31 <REP> .Trashes
30/03/2016 10:31 <REP> Adobe
30/03/2016 10:31 <REP> Adobe (2)
30/03/2016 11:06 <REP> Autorun.inf
11 fichier(s) 1ÿ784ÿ011 octets
8 R‚p(s) 7ÿ973ÿ949ÿ440 octets libres

USB drive disinfected and files unhidden!!
0
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685
 
Tu as quoi comme antivirus ?
0
kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention   1
 
smadav
0
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685 > kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention  
 
Désinstalle le.
Installe Avast!, active surtout les détections LPI pour détecter les programmes parasites et publicitaires.

Fais un scan de ta clef avec Avast.

puis :

Suis le tutoriel FRST. ( prends le temps de lire attentivement - tout y est bien expliqué ).

Télécharge et lance le scan FRST, 3 rapports FRST seront générés :
  • FRST.txt
  • Shortcut.txt
  • Additionnal.txt


Envoie ces 3 rapports sur le site http://pjjoint.malekal.com/ et en retour donne les 3 liens pjjoint qui mènent aux rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.
0
kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention   1
 
j'ai eu un message d'erreur en installant avast. y a t'il une version d'installation complète
0
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685 > kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention  
 
Quel message d'erreur ?
0
kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention   1
 


--
0
kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention   1
 
je suis connecté à Internet à travers un proxy, peux être je dois introduire les paramètre de ma connexion quelque part
0
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685 > kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention  
 
tu peux donner le contenu du journal d'installation ?
Tu as bien désinstallé SmartAv ?
0
kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention   1
 
2016-03-31 09:35:00Infoinstcont[3492,1320]--
2016-03-31 09:35:00Infoinstcont[3492,1320]2016/03/31 09:35:00 START: Avast installer/updater
2016-03-31 09:35:00Infoinstup[3492,1320]Command: '"C:\Users\khazri\AppData\Local\Temp\_av_iup.tm~a03300\instup.exe" /cookie:mmm_net_dlp_000_119_b /edition:1 /ga_clientid:b11fb58c-4265-402e-9946-b89f712ac1a9 /guid:6114c996-9d54-42fe-9c82-65077a08e3b7 /prod:ais /sfx:lite /sfxstorage:C:\Users\khazri\AppData\Local\Temp\_av_iup.tm~a03300'
2016-03-31 09:35:00Infoinstup[3492,1320]CPU: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz,2
2016-03-31 09:35:00Infoinstup[3492,1320]OS: Windows 7 x86
2016-03-31 09:35:00Infoinstup[3492,1320]Memory: 63% load. Phys:723464/1961980K free, Page:2210392/3923960K free, Virt:2019240/2097024K free
2016-03-31 09:35:00Infoinstup[3492,1320]DISKs: C:\ - 110GB free / 186GB total
2016-03-31 09:35:00Infoinstup[3492,1320]DISKs: D:\ - 87GB free / 184GB total
2016-03-31 09:35:00Infoinstup[3492,1320]Running module version: instup.exe - '11.1.2245.1540'
2016-03-31 09:35:00Infoinstup[3492,1320]Running module version: Instup.dll - '11.1.2245.1540'
2016-03-31 09:35:00Infosimutex[3492,1320]Checking for the mutex ownership.
2016-03-31 09:35:00Infosimutex[3492,1320]The mutex is signaled. We are owners of the mutex.
2016-03-31 09:36:04Infoguiwizard[3492,1320]Running module version: HTMLayout.dll - '3.3.2.224'
2016-03-31 09:36:04Infoguiwizard[3492,1320]Loaded module version: C:\Users\khazri\AppData\Local\Temp\_av_iup.tm~a03300\HTMLayout.dll - '3.3.2.224'
2016-03-31 09:36:04Infoguiwizard[3492,1320]Setup gui was successfully started.
2016-03-31 09:36:04Infoinstupcore[3492,1320]Sfx setup update has started.
2016-03-31 09:36:04Infoservers[3492,1320]Server definition(s) loaded for 'C:\Users\khazri\AppData\Local\Temp\_av_iup.tm~a03300\servers.def': 29 (maintenance:0)
2016-03-31 09:36:04Infoservers[3492,1320]ChooseServer: selected server 'Download j0765644 AVAST9 Server' with current url 'http://j0765644.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:36:16Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://j0765644.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 1
2016-03-31 09:36:16Infoservers[3492,1320]ChooseServer: selected server 'Download t1774167 AVAST9 Server' with current url 'http://t1774167.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:36:29Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://t1774167.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 2
2016-03-31 09:36:29Infoservers[3492,1320]ChooseServer: selected server 'Download r7579564 AVAST9 Server' with current url 'http://r7579564.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:36:43Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://r7579564.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 3
2016-03-31 09:36:43Infoservers[3492,1320]ChooseServer: selected server 'Download v6002936 AVAST9 Server' with current url 'http://v6002936.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:36:57Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://v6002936.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 4
2016-03-31 09:36:57Infoservers[3492,1320]ChooseServer: selected server 'Download d7847891 AVAST9 Server' with current url 'http://d7847891.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:37:10Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://d7847891.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 5
2016-03-31 09:37:10Infoservers[3492,1320]ChooseServer: selected server 'Download w9489315 AVAST9 Server' with current url 'http://w9489315.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:37:24Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://w9489315.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 6
2016-03-31 09:37:24Infoservers[3492,1320]ChooseServer: selected server 'Download p7749313 AVAST9 Server' with current url 'http://p7749313.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:37:38Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://p7749313.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 7
2016-03-31 09:37:38Infoservers[3492,1320]ChooseServer: selected server 'Download v6002936 AVAST9 Server' with current url 'http://v6002936.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:37:51Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://v6002936.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 8
2016-03-31 09:37:51Infoservers[3492,1320]ChooseServer: selected server 'Download h6924687 AVAST9 Server' with current url 'http://h6924687.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:38:05Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://h6924687.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 9
2016-03-31 09:38:05Infoservers[3492,1320]ChooseServer: selected server 'Download r7579564 AVAST9 Server' with current url 'http://r7579564.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:38:19Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://r7579564.iavs9x.u.avast.com/iavs9x/servers.def.vpx'. Next try: 10
2016-03-31 09:38:19Infoservers[3492,1320]ChooseServer: selected server 'Download m5270201 AVAST9 Server' with current url 'http://m5270201.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:38:21Errorpkgengine[3492,1320]DownloadPackage(download): 'C:\Users\khazri\AppData\Local\Temp\_av_iup.tm~a03300\servers.def.vpx', ip: unknown, has failed with code: 41222 (0x0000A106) [Host unreachable]
2016-03-31 09:38:21Infoservers[3492,1320]ChooseServer: selected server 'Download j0765644 AVAST9 Server' with current url 'http://j0765644.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:38:33Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://j0765644.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 1
2016-03-31 09:38:33Infoservers[3492,1320]ChooseServer: selected server 'Download z5453051 AVAST9 Server' with current url 'http://z5453051.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:38:46Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://z5453051.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 2
2016-03-31 09:38:46Infoservers[3492,1320]ChooseServer: selected server 'Download n8162145 AVAST9 Server' with current url 'http://n8162145.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:39:00Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://n8162145.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 3
2016-03-31 09:39:00Infoservers[3492,1320]ChooseServer: selected server 'Download s4981491 AVAST9 Server' with current url 'http://s4981491.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:39:14Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://s4981491.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 4
2016-03-31 09:39:14Infoservers[3492,1320]ChooseServer: selected server 'Download r6806778 AVAST9 Server' with current url 'http://r6806778.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:39:27Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://r6806778.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 5
2016-03-31 09:39:27Infoservers[3492,1320]ChooseServer: selected server 'Download l3179313 AVAST9 Server' with current url 'http://l3179313.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:39:41Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://l3179313.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 6
2016-03-31 09:39:41Infoservers[3492,1320]ChooseServer: selected server 'Download l3179313 AVAST9 Server' with current url 'http://l3179313.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:39:55Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://l3179313.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 7
2016-03-31 09:39:55Infoservers[3492,1320]ChooseServer: selected server 'Download m5270201 AVAST9 Server' with current url 'http://m5270201.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:40:08Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://m5270201.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 8
2016-03-31 09:40:08Infoservers[3492,1320]ChooseServer: selected server 'Download p8397477 AVAST9 Server' with current url 'http://p8397477.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:40:22Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://p8397477.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 9
2016-03-31 09:40:22Infoservers[3492,1320]ChooseServer: selected server 'Download w9489315 AVAST9 Server' with current url 'http://w9489315.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:40:36Errordldwrap[3492,1320]GetFileWithRetry: An error 41222 (0x0000A106) [Host unreachable] has occured when downloading a file from 'http://w9489315.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx'. Next try: 10
2016-03-31 09:40:36Infoservers[3492,1320]ChooseServer: selected server 'Download z5453051 AVAST9 Server' with current url 'http://z5453051.iavs9x.u.avast.com/iavs9x' of type 'URL_TYPE_DOWNLOAD_PROGRAM'.
2016-03-31 09:40:38Errorpkgengine[3492,1320]DownloadPackage(download): 'C:\Users\khazri\AppData\Local\Temp\_av_iup.tm~a03300\prod-pgm.vpx', ip: unknown, has failed with code: 41222 (0x0000A106) [Host unreachable]
2016-03-31 09:40:38Errorpkgengine[3492,1320]LoadLatestProdAndParts: download product file 'prod-pgm.vpx' has failed. Status: 41222 (0x0000A106) [Host unreachable]
0
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685 > kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention  
 
ha ouaip il ne parvient pas à télécharger les fichiers.
Surement ton proxy oui.
0
kawther84 Messages postés 321 Date d'inscription   Statut Membre Dernière intervention   1
 
0