kaitnou
-
15 mai 2008 à 16:12
Ajbol
Messages postés3014Date d'inscriptionjeudi 16 novembre 2006StatutMembreDernière intervention23 janvier 2012
-
26 mai 2008 à 17:32
Bonjour,
Alors voilà, ma mère a reçu depuis un de ses contacts, un virus. J'ai vérifié avec un anti malware et Msnfix, et voici leurs rapports :
Malwarebytes' Anti-Malware 1.12
Version de la base de données: 752
Type de recherche: Examen complet (C:\|)
Eléments examinés: 121684
Temps écoulé: 29 minute(s), 56 second(s)
Processus mémoire infecté(s): 2
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 29
Valeur(s) du Registre infectée(s): 4
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 15
Fichier(s) infecté(s): 36
Processus mémoire infecté(s):
C:\Program Files\Svconr\Svconr.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Odile\Application Data\speedrunner\SpeedRunner.exe (Adware.SurfAccuracy) -> No action taken.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\AppID\{ff46f4ab-a85f-487e-b399-3f191ac0fe23} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\testcpv6.bho (Trojan.Agent) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.Agent) -> No action taken.
HKEY_CLASSES_ROOT\testcpv6.bho.1 (Trojan.Agent) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\speedrunner (Adware.SurfAccuracy) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\shoppingreport (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\Software\SpeedRunner (Adware.SurfAccuracy) -> No action taken.
HKEY_CLASSES_ROOT\AppID\testCPV6.DLL (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\BO1jiZmwnF2zhi (Trojan.Agent) -> No action taken.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\ShoppingReport (Adware.Shopping.Report) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Svconr (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpeedRunner (Adware.SurfAccuracy) -> No action taken.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Trojan.Agent) -> Data: spc.dll -> No action taken.
Dossier(s) infecté(s):
C:\Program Files\ShoppingReport (Adware.Shopping.Report) -> No action taken.
C:\Program Files\ShoppingReport\Bin (Adware.Shopping.Report) -> No action taken.
C:\Program Files\ShoppingReport\cs (Adware.Shopping.Report) -> No action taken.
C:\Program Files\ShoppingReport\Bin\2.0.21 (Adware.Shopping.Report) -> No action taken.
C:\Program Files\Temporary (Trojan.Agent) -> No action taken.
C:\Program Files\JavaCore (Trojan.Downloader) -> No action taken.
C:\Program Files\Svconr (Trojan.Agent) -> No action taken.
C:\Program Files\Spcron (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\db (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\dwld (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\report (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\res1 (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\speedrunner (Adware.SurfAccuracy) -> No action taken.
Fichier(s) infecté(s):
C:\Program Files\Spcron\Spc.dll (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Odile\Application Data\SpeedRunner\SRUninstall.exe (Adware.SurfAccuracy) -> No action taken.
C:\Documents and Settings\Odile\Application Data\SpeedRunner\SRUninstall.MSNFix (Adware.SurfAccuracy) -> No action taken.
C:\Documents and Settings\Odile\Local Settings\Temp\outerinfo.ico (Malware.Trace) -> No action taken.
C:\Documents and Settings\Odile\Local Settings\Temporary Internet Files\Content.IE5\GLAROIKQ\17PHolmes[1].cmt (Trojan.DownLoader) -> No action taken.
C:\Program Files\JavaCore\JavaCore.MSNFix (Trojan.Insider) -> No action taken.
C:\Program Files\JavaCore\UnInstall.MSNFix (Adware.Insider) -> No action taken.
C:\Program Files\Mozilla Firefox\components\srff.dll (Adware.SurfAccuracy) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP436\A0021446.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP439\A0023471.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP440\A0023475.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP440\A0023498.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP440\A0023501.dll (Adware.ZenoSearch) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP440\A0023505.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP442\A0024544.exe (Adware.SurfAccuracy) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP442\A0024545.exe (Trojan.Insider) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP442\A0024547.exe (Trojan.Dropper) -> No action taken.
C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP442\A0024548.exe (Trojan.Downloader) -> No action taken.
C:\WINDOWS\b128.MSNFix (Trojan.Downloader) -> No action taken.
C:\WINDOWS\mrofinu1423.exe.MSNFix (Trojan.DownLoader) -> No action taken.
C:\WINDOWS\mrofinu1423.MSNFix (Trojan.DownLoader) -> No action taken.
C:\Program Files\ShoppingReport\Uninst.exe (Adware.Shopping.Report) -> No action taken.
C:\Program Files\ShoppingReport\cs\persist.dbs (Adware.Shopping.Report) -> No action taken.
C:\Program Files\Temporary\inPV.exe (Trojan.Agent) -> No action taken.
C:\Program Files\Svconr\Svconr.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\Config.xml (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\persist.dbs (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\ShoppingReport\cs\res1\WhiteList.dbs (Adware.Shopping.Report) -> No action taken.
C:\Documents and Settings\Odile\Application Data\speedrunner\config.cfg (Adware.SurfAccuracy) -> No action taken.
C:\Documents and Settings\Odile\Application Data\speedrunner\config.MSNFix (Adware.SurfAccuracy) -> No action taken.
C:\Documents and Settings\Odile\Application Data\speedrunner\SpeedRunner.exe (Adware.SurfAccuracy) -> No action taken.
MSNFix 1.716
C:\Documents and Settings\Odile\Mes documents\Mes fichiers re‡us\MSNFix\MSNFix
Fix exécuté le 15/05/2008 - 15:24:17,57 By Odile
mode normal
************************ Recherche les fichiers présents
Merci beaucoup pour votre aide, l'ordinateur de ma mère a été nettoyé et fonctionne maintenant mieux qu'avant!
Il reste encore quelques petits trucs à régler mais dans l'ensemble, ça va.
Merci encore.
Katinou
Ajbol
Messages postés3014Date d'inscriptionjeudi 16 novembre 2006StatutMembreDernière intervention23 janvier 2012404 26 mai 2008 à 17:32