Mon micro est infecté que faire ?

Résolu/Fermé
galou35 - 12 juin 2008 à 23:39
galou35 Messages postés 2 Date d'inscription mercredi 30 avril 2008 Statut Membre Dernière intervention 20 juin 2008 - 20 juin 2008 à 11:02
Bonjour,

j'ai eu ce soir une alerte de XP antivirus qui me dis qu'il y a 69 infections sur mon PC et j'ai bitdefender free edition v10 qui est installé. Je fais quoi ?
Le scan de bit defender donne :


//-----------------------------------------------------------------
//
// Produit BitDefender Free Edition v10
// Produit 10.2
//
// Créé le: 12/06/2008 23:08:01
//
//-----------------------------------------------------------------


Statistiques

Chemin cible: C:\
D:\
Dossiers : 2707
Fichiers : 52369
Processus Mémoire analysés : 47
Archives : 14
Fichiers enpaquetés : 2677
Virus trouvés : 1
Fichiers infectés : 2
Processus Mémoire infectés : 0
Fichiers suspects : 0
Alertes : 0
Fichiers désinfectés : 0
Fichiers effacés : 0
Fichiers déplacés : 2
Erreurs I/O : 28
Temps d'analyse :=00:18:07
Fichiers/seconde :48

Statistiques Spywares

Registres analysés : 306
Registres infectés : 0
Cookies analysés : 0
Cookies infectés : 0
Fichiers spyware infectés : 0
Menaces Spyware détectées : 0


Définitions virus : 1260622
Plugins d'analyse : 16
Plugins archives : 42
Plug-ins décompression : 7
Plug-ins messagerie : 6
Plug-ins système : 5

Options d'analyse

Détection
[X] Analyser le secteur de boot
[X] Processus mémoire
[ ] Analyser les archives
[X] Analyser les fichiers enpaquetés
[X] Analyser la messagerie

Masque fichiers
[ ] Programmes
[X] Tous les fichiers
[ ] Extensions définies par l'utilisateur:
[ ] Exclure les extensions: ;

Action

Objets infectés
[ ] Ignorer
[X] Désinfecter
[ ] Effacer
[ ] Mettre en quarantaine
[ ] Demander l'action

Seconde action
[ ] Ignorer
[ ] Effacer
[X] Mettre en quarantaine
[ ] Demander l'action

Options d'analyse
[X] Activer les alertes
[ ] Activer l'heuristique
[ ] Afficher tous les fichiers dans le journal
[X] Fichier journal: C:\Documents and Settings\All Users\Application Data\Bitdefender\Desktop\Profiles\Logs\full_scan\1213304881.log

Options d'analyse Spyware

[X] Analyse contre les risques non-viraux
[ ] Ecarter de l'analyse les dialers et les applications
[X] Clés de registres
[X] Cookies


Résumé:

C:\WINDOWS\system32\scui.cpl Infecté: Trojan.Generic.273695
C:\WINDOWS\system32\scui.cpl Désinfection impossible
C:\WINDOWS\system32\scui.cpl Déplacé
C:\System Volume Information\_restore{BE5F38AA-1F9A-46F9-A5B7-335900894203}\RP14\A0003457.cpl Infecté: Trojan.Generic.273695
C:\System Volume Information\_restore{BE5F38AA-1F9A-46F9-A5B7-335900894203}\RP14\A0003457.cpl Désinfection impossible
C:\System Volume Information\_restore{BE5F38AA-1F9A-46F9-A5B7-335900894203}\RP14\A0003457.cpl Déplacé
et celui de XP antivirus 2008 (que je n'ai pas?!) :
XP Antivirus 2008 system scan report.
Report generated 12.06.2008 23:26:08

Type Run type Name Details
Spyware C://windows/system32/iesetup.dll Spyware.IEMonster.d "Steals passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs.
Adware autorun Zlob.PornAdvertiser.ba Adware that displays pop-up/pop-under advertisements of pornographic or online gambling Web sites.
Spyware autorun Spyware.IMMonitor program that can be used to monitor and record conversations in popular instant messaging applications.
Backdoor C://windows/system32/svchost.exe Win32.Rbot.fm An IRC controlled backdoor that can be used to gain unauthorized access to a victim's machine.
Trojan autorun Infostealer.Banker.E Steals sensitive information from the infected computer (e.g. logins and passwords from online banking sessions).
Dialer C://windows/system32/cmdial32.dll Dialer.Xpehbam.biz_dialer A Dialer that loads pornographic material. The url information shows Hardcore Pornographic pages.
Spyware autorun Spyware.KnownBadSites Uses the Windows hosts file to redirect your browser to a malicious site when you try to access a valid site.
Trojan autorun Trojan.Tooso Trojan.Tooso is a trojan which attempts to terminate and delete security related applications.
Trojan C://windows/system32/explorer.exe Trojan.MailGrabber.s Trojan horse that gets access to e-mail accounts on the infected computer.
Trojan C://windows/system32/alg.exe Trojan.Alg.t Trojan program that can compromise your private information stored on the hard drive.
Rogue C://Program Files/TrustedAntivirus TrustedAntivirus A corrupt and misleading anti-virus program that may be usually installed with the help of malcous Trojans and other malware
Rogue C://Program Files/SecurePCCleaner SecurePCCleaner Rogue Security Software: fake Security software that uses deceptive means for installation and purpose.
Trojan C://windows/system32/ Trojan.BAT.Adduser.t This Trojan has a malicious payload. It is a BAT file. It is 1129 bytes in size.
Spyware C://windows/system32/ Spyware.007SpySoftware Program designed to monitor user activity. May be used with or without consent.
Trojan C://windows/hidden/ Trojan.Clicker.EC Trojan.Clicker.EC is an information stealing Trojan that masquerades as a legitimate system file so as to avoid detection and subsequent removal.
Dialer C://windows/hidden/ Dialer.Trafficjam.a Dialer.Trafficjam.a is a premium-rate phone dialer that automatically invokes paid access to various porn-related Web sites.
Trojan hidden autorun Trojan.Poison.J Trojan.Poison.J is a key-logging Trojan for the Windows platform.
Adware Registry Adware.eXact.BargainBuddy A browser helper object that monitors internet browsing sessions in an attempt to redirect search queries and distribute unsolicited advertisements.
Worm C://windows/system32/ Win32.Delbot.AI Win32.Delbot.AI is a worm and IRC backdoor that exploits system and software vulnerabilities in order to provide remote access to the host PC.
Worm C://windows/temp/ Win32.Sdbot.ADN A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Trojan C://windows/ Trojan-Dropper.Win32.Agent.bot This Trojan is designed to install and launch other malicious programs on the victim machine without the knowledge or consent of the user.
Worm C://windows/temp/ Win32.Rbot.CBX A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Spyware autorun Win32.PerFiler Win32.PerFiler is designed to retrieve and install files when executed. Win32.PerFiler is configured to download from either a designated web or FTP site.
Worm hidden autorun Win32.Miewer.a A Trojan Downloader that masquerades as a legitimate system file. Associated processes connect to the Internet to download additional malicious files
Trojan C://windows/ Trojan-Downloader.VBS.Small.dc This Trojan downloads other files via the FTP protocol and launches them for execution on the victim machine without the user’s knowledge.
Worm autorun Win32.Peacomm.dam A Trojan Downloader that is spread as an attachment to emails with news headlines as the subject lines which downloads additional security threats.
Trojan C://windows/system/drivers/ Win32.Spamta.KG.worm A multi-component mass-mailing worm that downloads and executes files from the Internet.
Trojan C://windows/system/drivers/etc/ Trojan.IRCBot.d a worm that opens an IRC back door on the infected host. It spreads by exploiting the Windows Remote Buffer Overflow Vulnerability.
Trojan C://windows/system/mui/ Trojan.Dropper.MSWord.j A Microsoft Word macro virus that drops a trojan onto the infected host.
Trojan C://windows/system/mui/ Win32.Clagger.C This is small Trojan downloader that downloads files and lowers security settings. It is spreading as an email attachment.
Worm C://windows/system/ Worm.Bagle.CP This is a ""Bagle"" mass-mailer which demonstrates typical ""Bagle"" behavior.
Worm C://windows/ Win32.BlackMail.xx "This dangerous worm will destroy certain data files on an infected user's machine on February 3, 2008.
Trojan hidden autorun Trojan.Win32.Agent.ado Trojan downloader that is spread as an attachment to a spam email and tries to download a password stealer.
Trojan autorun Win32.Outsbot.u A backdoor Trojan that is remotely controlled via Internet Relay Chat (IRC). It exploits Sony Digital Rights Management (DRM) software to hide its presence.
Worm hidden autorun Win32.Sober.P This is a mass-mailing worm that uses its own SMTP engine to spread. It sends itself as an email attachment that mimics an image file.
Worm C://windows/temp/ Win32.Sdbot.ADN A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Trojan C://windows/ Trojan-Dropper.Win32.Agent.bot This Trojan is designed to install and launch other malicious programs on the victim machine without the knowledge or consent of the user.
Worm C://windows/temp/ Win32.Rbot.CBX A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Spyware autorun Win32.PerFiler Win32.PerFiler is designed to retrieve and install files when executed. Win32.PerFiler is configured to download from either a designated web or FTP site.
Worm hidden autorun Win32.Miewer.a A Trojan Downloader that masquerades as a legitimate system file.
Trojan C://windows/ Trojan-Downloader.VBS.Small.dc This Trojan downloads other files via the FTP protocol and launches them for execution on the victim machine without the user’s knowledge.
Worm autorun Win32.Peacomm.dam A Trojan Downloader that is spread as an attachment to emails with news headlines as the subject lines which downloads additional security threats.
Trojan C://windows/system/drivers/ Win32.Spamta.KG.worm A multi-component mass-mailing worm that downloads and executes files from the Internet.
Trojan C://windows/system/drivers/etc/ Trojan.IRCBot.d a worm that opens an IRC back door on the compromised host.
Trojan C://windows/system/mui/ Trojan.Dropper.MSWord.j A Microsoft Word macro virus that drops a trojan onto the infected host.
Trojan C://windows/system/mui/ Win32.Clagger.C This is small Trojan downloader that downloads files and lowers security settings. It is spreading as an email attachment.
Worm C://windows/system/ Worm.Bagle.CP This is a ""Bagle"" mass-mailer which demonstrates typical ""Bagle"" behavior: it has a .ZIP file attachment.
Worm C://windows/ Win32.BlackMail.xx This dangerous worm will destroy certain data files on an infected user's machine on February 3, 2008.
Trojan hidden autorun Trojan.Win32.Agent.ado Trojan downloader that is spread as an attachment to a spam email and tries to download a password stealer.
Trojan hidden autorun Win32.Outsbot.u A backdoor Trojan that is remotely controlled via Internet Relay Chat (IRC).
Worm hidden autorun Win32.Sober.P This is a mass-mailing worm that uses its own SMTP engine to spread. It sends itself as an email attachment that mimics an image file.
Trojan C://windows/system32/ Trojan.BAT.Adduser.t This Trojan has a malicious payload. It is a BAT file. It is 1129 bytes in size.
Spyware C://windows/system32/ Spyware.007SpySoftware Program designed to monitor user activity. May be used with or without consent.
Trojan C://windows/hidden/ Trojan.Clicker.EC Trojan.Clicker.EC is an information stealing Trojan that masquerades as a legitimate system file so as to avoid detection and subsequent removal.
Dialer C://windows/hidden/ Dialer.Trafficjam.a Dialer.Trafficjam.a is a premium-rate phone dialer that automatically invokes paid access to various porn-related Web sites.
Trojan hidden autorun Trojan.Poison.J Trojan.Poison.J is a key-logging Trojan for the Windows platform.
Adware Registry Adware.eXact.BargainBuddy A browser helper object that monitors internet browsing sessions in an attempt to redirect search queries and distribute unsolicited advertisements.
Worm C://windows/system32/ Win32.Delbot.AI Win32.Delbot.AI is a worm and IRC backdoor that exploits system vulnerabilities in order to provide remote access to the host PC.
Worm C://windows/temp/ Win32.Sdbot.ADN A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Trojan C://windows/ Trojan-Dropper.Win32.Agent.bot This Trojan is designed to install and launch other malicious programs on the victim machine without the knowledge or consent of the user.
Worm C://windows/temp/ Win32.Rbot.CBX A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Spyware autorun Win32.PerFiler Win32.PerFiler is designed to retrieve and install files when executed. Win32.PerFiler is configured to download from either a designated web or FTP site.
Worm hidden autorun Win32.Miewer.a A Trojan Downloader that masquerades as a legitimate system file.
Trojan C://windows/ Trojan-Downloader.VBS.Small.dc This Trojan downloads other files via the FTP protocol and launches them for execution on the victim machine without the user’s knowledge.
Spyware C://windows/system32/ W97M/Spirocheta A dangerous generic spyware. It is designed to steal sensitive information from the victim machine.
Spyware C://windows/system32/ W97M/Smac.B A dangerous generic spyware. It is designed to steal sensitive information from the victim machine.
Spyware C://windows/system32/ W97M/Satan.A A dangerous generic spyware. It is designed to steal sensitive information from the victim machine.
Spyware C://windows/system32/ W97M/Sandula-B A dangerous generic spyware. It is designed to steal sensitive information from the victim machine.
Spyware C://windows/system32/ W97M/Renegade A dangerous generic spyware. It is designed to steal sensitive information from the victim machine.


S'il vous plait, aidez moi !!

Merci d'avance
Galou
A voir également:

4 réponses

rglf91 Messages postés 148 Date d'inscription lundi 24 mars 2008 Statut Membre Dernière intervention 23 décembre 2012 6
12 juin 2008 à 23:43
xpantivirus c'est un virus !!

telecharge malwares byte antimalware scan ton pc; et vires les

https://www.01net.com/telecharger/windows/Securite/anti-spam/fiches/44096.html
2
Merci, c'est fait voila le rapport:

Malwarebytes' Anti-Malware 1.17
Version de la base de données: 851

00:03:36 13/06/2008
mbam-log-6-13-2008 (00-03-36).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 69024
Temps écoulé: 9 minute(s), 13 second(s)

Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 6

Processus mémoire infecté(s):
C:\Program Files\XP Antivirus\xpa.exe (Rogue.XPAntivirus) -> Unloaded process successfully.

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\winsrc.dll (Adware.Search Toolbar) -> Unloaded module successfully.

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Adware.Search Toolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Adware.Search Toolbar) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\26374471106970058217238142778179 (Rogue.XPAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run\IEUpdate (Trojan.Agent) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\XP Antivirus (Rogue.XPAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrateur\Menu Démarrer\XP Antivirus 2008 (Rogue.XPAntivirus) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\WINDOWS\system32\winsrc.dll (Adware.Search Toolbar) -> Quarantined and deleted successfully.
C:\Program Files\XP Antivirus\xpa.exe (Rogue.XPAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrateur\Menu Démarrer\XP Antivirus 2008\XP Antivirus 2008.lnk (Rogue.XPAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrateur\Menu Démarrer\XP Antivirus 2008\Uninstall XP Antivirus 2008.lnk (Rogue.XPAntivirus) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ieupdates.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrateur\Application Data\Microsoft\Internet Explorer\Quick Launch\XP Antivirus 2008.lnk (Rogue.XPAntivirus) -> Quarantined and deleted successfully.

Et après ?
J'y connais pas grand chose moi en PC
Galou
0
Merci encore, ça a l'air d'être fini et sur ce, je vais aller faire dodo...

Merci mille fois

Galou
0
rglf91 Messages postés 148 Date d'inscription lundi 24 mars 2008 Statut Membre Dernière intervention 23 décembre 2012 6 > galou35
13 juin 2008 à 00:37
galoux coche la case résolu pour ton, problème!
heureux d'avoir pu t'aider!
0
galou35 > rglf91 Messages postés 148 Date d'inscription lundi 24 mars 2008 Statut Membre Dernière intervention 23 décembre 2012
13 juin 2008 à 23:10
Moi veut bien mais un po bête... c'est où ?

Merci encore

Galou
0
jax008 Messages postés 83 Date d'inscription samedi 11 août 2007 Statut Membre Dernière intervention 2 juin 2017 11 > galou35
16 juin 2008 à 00:20
tu le trouvera entre "POSER VOTRE QUESTION" et ta premiere intervention tt en noubliant pas de te connecter sur ton compte avant.tu choisi "PROBLEME RESOLU"
0
jax008 Messages postés 83 Date d'inscription samedi 11 août 2007 Statut Membre Dernière intervention 2 juin 2017 11
12 juin 2008 à 23:54
ok moi je te propose de telecharger un bon antivirus et un bon antispyware....
ANTIVIRUS: AVAST.KASPERSKY. pour moi c les meilleur.
pour AVAST c ici https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/25899.html
pour KASPERSKY c ici https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/1449.html
D'abord installe avast et programme un scan au demmarage de windows(avant que le virus ne s'active).apres desinstalle le et installe KASPERSKY et scan .apres garde l'un des deux installer dans mon cas c AVAST.
apres avoir installer un antivirus digne de se nom installe SPYBOT ici https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html
et SCAN (tu peux garder spybot et avast car spybot n'est pas un antivirus alors cela ne risque pas de ralentir ton pc ).
et je te propose d'installer zone allarm(FIREWALL) .tu trouvera ici http://www.01net.com/windows/Internet/internet_utlitaire/fiches/10024.html juste que c une demonstration tu devra l'acheter.
sinon le firewall de windows fera l'affaire.(comme pour moi. zone alarm ralenti un peu ton pc au demmarage).
et A SQUARED pour finir ici https://www.01net.com/telecharger/
ps:n'oubli pas avant de scanner de faire ttes les mises a jour necessaire.
0
jax008 Messages postés 83 Date d'inscription samedi 11 août 2007 Statut Membre Dernière intervention 2 juin 2017 11
12 juin 2008 à 23:58
ah g oublier XP ANTIVIRUS c de la dobe vire le et desactive les mise a jour automatique.
0
rglf91 Messages postés 148 Date d'inscription lundi 24 mars 2008 Statut Membre Dernière intervention 23 décembre 2012 6
13 juin 2008 à 00:35
ok galou ton rapport malware byte est bon !

hey les gars : XPANTIVIRUS C'EST UN ROGUE!!!c'est pas un antivirus
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 295
16 juin 2008 à 00:29
Salut,

XP Antivirus est un rogue, faux logiciel de sécurité.

- Télécharge HijackThis V 2.02 (HijackThis Installer) :
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

- Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

- Clique sur Install ensuite sur I Accept

- Clique sur Do a scan system and save log file

- Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
0