Infection

Résolu
bonjour,
au démarage de mon pc j'ai eu un écran bleu,un colègue ma conseiller de faire une analyse avec zhp.Dans le rapport il y a plein de lignes marqué pup,adware et autre, ne sachant pas comment supprimer ces infections je demande de l'aide au près de vous.D'avance merci.

15 réponses

  1. ok merci pour ton aide et bonne continuation.
    0
    1. Bonsoir,

      Pas de soucis je comprends ;)

      Désinfection terminé.

      Bonne continuation et bon surf ;)
      0
      1. bonsoir,
        désolé de ne pas avoir répondu,dure journée de boulot :)
        pour les soucis ça a l'air clean.
        0
        1. Bonjour ?

          Toujours des soucis ?
          0
          1. Copie les lignes en gras ci dessous :

            SysRestore

            [HKLM\Software\Trymedia Systems] =>Adware.Trymedia
            O64 - Services: CurCS - ??\??\???? - Pas de propriétaire (ewdmaudn) .(...) - LEGACY_EWDMAUDN
            [HKLM\Software\Trymedia Systems] =>Adware.Trymedia^

            O47 - AAKE:Key Export SP - "C:\Program Files\rFactor\rFactor Dedicated.exe" [Enabled] .(...) -- C:\Program Files\rFactor\rFactor Dedicated.exe (.not file.)
            O47 - AAKE:Key Export SP - "I:\Program Files\Microsoft Games\Combat Flight Simulator 3\cfs3.exe" [Disabled] .(...) -- I:\Program Files\Microsoft Games\Combat Flight Simulator 3\cfs3.exe (.not file.)
            O47 - AAKE:Key Export SP - "J:\Program Files\MyProg\F1_2011.exe" [Enabled] .(...) -- J:\Program Files\MyProg\F1_2011.exe (.not file.)
            O47 - AAKE:Key Export SP - "J:\GTR2\GTR2.exe" [Enabled] .(...) -- J:\GTR2\GTR2.exe (.not file.)
            O47 - AAKE:Key Export SP - "J:\Program Files\SimBin\RaceRoom The Game 2\RRG.exe" [Enabled] .(...) -- J:\Program Files\SimBin\RaceRoom The Game 2\RRG.exe (.not file.)
            O47 - AAKE:Key Export SP - "J:\Program Files\WRC 2 FIA World Rally Championship\WRC2.exe" [Enabled] .(...) -- J:\Program Files\WRC 2 FIA World Rally Championship\WRC2.exe (.not file.)
            O47 - AAKE:Key Export SP - "J:\Program Files\Infogrames\Grand Prix 4\GP4.exe" [Enabled] .(...) -- J:\Program Files\Infogrames\Grand Prix 4\GP4.exe (.not file.)
            O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\rundll32.exe" [Disabled] Clé orpheline
            O47 - AAKE:Key Export SP - "J:\Program Files\THQ\MotoGP2\motogp2.exe" [Enabled] .(...) -- J:\Program Files\THQ\MotoGP2\motogp2.exe (.not file.)
            O47 - AAKE:Key Export SP - "J:\Programme Files\Call of Duty Modern Warfare 2\iw4mp.dat" [Enabled] .(...) -- J:\Programme Files\Call of Duty Modern Warfare 2\iw4mp.dat (.not file.)
            O47 - AAKE:Key Export SP - "J:\Program Files\theHunter\game\theHunter.exe" [Enabled] .(...) -- J:\Program Files\theHunter\game\theHunter.exe (.not file.)
            O47 - AAKE:Key Export SP - "J:\Program Files\Cyanide\Cycling Manager\CyclingManager.exe" [Enabled] .(...) -- J:\Program Files\Cyanide\Cycling Manager\CyclingManager.exe (.not file.)
            O47 - AAKE:Key Export SP - "J:\GTR2\Plugins\CarSetup\GTR2CarSetupServerEx.exe" [Enabled] .(...) -- J:\GTR2\Plugins\CarSetup\GTR2CarSetupServerEx.exe (.not file.)
            O4 - HKUS\S-1-5-21-1004336348-436374069-1177238915-1006\..\Run: [AVG-Secure-Search-Update_JUNE2013_TB] C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe (.not file.) =>Toolbar.AVGSearch
            O23 - Service: (vToolbarUpdater15.5.0) . (...) - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe (.not file.) =>Toolbar.AVGSearch
            [MD5.00000000000000000000000000000000] [APT] [AVG-Secure-Search-Update_JUNE2013_TB_rmv] (...) -- C:\WINDOWS\TEMP\{D818812C-F4D6-4545-82E9-C47AF59D720D}.exe (.not file.) [0]
            O53 - SMSR:HKLM\...\startupreg\ROC_roc_dec12 [Key] . (...) -- C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe (.not file.) =>Toolbar.AVGSearch
            O53 - SMSR:HKLM\...\startupreg\vProt [Key] . (...) -- C:\Program Files\AVG Secure Search\vprot.exe (.not file.) =>Toolbar.AVGSearch
            SS - | Auto 00\00\0000 0 | (vToolbarUpdater15.5.0) . (...) - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe =>Toolbar.AVGSearch
            [HKLM\SYSTEM\CurrentControlSet\Services\vToolbarUpdater15.5.0] =>Toolbar.AVGSearch^
            [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\ROC_roc_dec12] =>Toolbar.AVGSearch^
            [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\vProt] =>Toolbar.AVGSearch^
            [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>Toolbar.Tarma
            [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>Toolbar.Tarma
            C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe =>Toolbar.AVGSearch^

            FirewallRaz
            PROXYFix
            EmptyFlash
            Emptytemp

            Puis suis ceci :
            ~ http://sosvirus.net/viewtopic.php?f=281&t=579

            J'attends donc 1 rapport :
            ¤ ZHPFixReport.txt

            ==========================================

            Si tu n'as plus de soucis, on finalise :
            ~ http://www.sosvirus.net/canned-speech/canned-speech-delfix-t547-20.html

            ++ ;)
            0
            1. Bonsoir,

              Ok refais moi un rapport ZHPDiag stp, je te fais un script et on finalise après ;)
              0
              1. Malwarebytes Anti-Malware 1.75.0.1300
                www.malwarebytes.org

                Database version: v2013.08.28.04

                Windows XP Service Pack 3 x86 NTFS
                Internet Explorer 8.0.6001.18702
                Thierry :: MERCKWIL-1926A1 [administrator]

                29/08/2013 20:51:34
                mbam-log-2013-08-29 (20-51-34).txt

                Scan type: Full scan (C:\|)
                Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
                Scan options disabled: P2P
                Objects scanned: 381932
                Time elapsed: 1 hour(s), 25 minute(s), 20 second(s)

                Memory Processes Detected: 0
                (No malicious items detected)

                Memory Modules Detected: 0
                (No malicious items detected)

                Registry Keys Detected: 1
                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.

                Registry Values Detected: 0
                (No malicious items detected)

                Registry Data Items Detected: 0
                (No malicious items detected)

                Folders Detected: 0
                (No malicious items detected)

                Files Detected: 13
                C:\Documents and Settings\Thierry\Mes documents\Downloads\01net_AVG_Antivirus_Free_Edition.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{DC5FBB9D-4A74-453A-99F5-DB015F9EF8FE}\RP578\A0205251.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{DC5FBB9D-4A74-453A-99F5-DB015F9EF8FE}\RP578\A0205253.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{DC5FBB9D-4A74-453A-99F5-DB015F9EF8FE}\RP578\A0205256.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{DC5FBB9D-4A74-453A-99F5-DB015F9EF8FE}\RP578\A0205258.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{DC5FBB9D-4A74-453A-99F5-DB015F9EF8FE}\RP578\A0205261.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{DC5FBB9D-4A74-453A-99F5-DB015F9EF8FE}\RP578\A0205263.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\ZHP\Quarantine\installmate.DIR\{55D596A2-1BF8-4319-A1F2-53DA8E36B454}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\ZHP\Quarantine\installmate.DIR\{55D596A2-1BF8-4319-A1F2-53DA8E36B454}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\ZHP\Quarantine\installmate.DIR\{A34052F1-68F4-412A-A3C1-20D678A37007}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\ZHP\Quarantine\installmate.DIR\{A34052F1-68F4-412A-A3C1-20D678A37007}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\ZHP\Quarantine\installmate.DIR\{C401D8CB-77D0-48AD-AA46-3FF21FE2FA3D}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
                C:\ZHP\Quarantine\installmate.DIR\{C401D8CB-77D0-48AD-AA46-3FF21FE2FA3D}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.

                (end)
                0
                1. Désolé, je me suis trompé, il n'y en avait qu'un ;)

                  Désinfecté c'est bien, mais si tu ne sais pas comment tu t'es infecté alors ça va recommencer ! La réponse ci dessous, elle n'est pas longue du tout, c'est 30 secondes de lectures et un surf plus intelligent par la suite ;)

                  Voici un sujet pour savoir comment tes ennuies on commencés :
                  ~ http://www.sosvirus.net/forum-virus-securite/les-toolbars-cauchemar-t1170.html

                  ============================================

                  Ceci stp :
                  ~ http://sosvirus.net/viewtopic.php?f=281&t=594

                  J'attends 1 rapport :
                  ¤ mbam.txt
                  0
                  1. http://upload.sosvirus.net/log/SosUpload.63e8ea24375d75e8c125c875d2da4b43.txt

                    j'ai eu un rapport au redémarrage du pc mais quel et le deuxième rapport ?
                    0
                    1. Au vu de ton rapport :)
                      Bonjour,

                      Fais ceci :
                      ~ http://sosvirus.net/viewtopic.php?f=281&t=546

                      J'attends donc 2 rapports :
                      ~ Adwcleaner.txt ( sur http://upload.sosvirus.net/ )
                      0
                      1. salut
                        si tu ne l'a pas eu a cet endroit
                        Télécharge ZHPDiag (de Nicolas Coolman). https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
                        * Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
                        * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)

                        puis

                        Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette

                        ? Rends toi sur pjjoint.malekal.com
                        ? Clique sur le bouton Parcourir
                        ? Sélectionne le fichier que tu veux héberger et clique sur Ouvrir
                        ? Clique sur le bouton Envoyer
                        ? Un message de confirmation s'affiche (L'upload a réussi ! - Le lien à transmettre à vos correspondant pour visualiser le fichier est : https://pjjoint.malekal.com/files.php?id=df5ea299241015

                        ? Copie le lien dans ta prochaine réponse.

                        Quand les bornes sont franchies, il n'y a plus de limite
                        Ce que j'ai écrit, je l'ai écrit
                        0
                        1. Bonsoir,

                          Doublon
                          0
                        2. je vois , mais un rapport zhpDiag prend trop de place , il suffit pas de lui dire poste le
                          0