Security-X

Forum Security-X => Désinfections => Discussion démarrée par: laura57 le décembre 09, 2012, 16:31:43

Titre: A l'aide : Virus ministère de l'intérieur [Résolu]
Posté par: laura57 le décembre 09, 2012, 16:31:43
Bonjour, je suis actuellement infectée par un virus, qui me présente une page du ministère de l'intérieur. Ma webcam se met automatiquement en route. On me demande de payer par Ukash 100euros sous 48h.

Que dois-je faire pour pouvoir désinfecter mon ordinateur ?

P.S : Je possède Windows 7.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 09, 2012, 17:49:49
J'ai déjà fait l'analyse avec OTL comme vous l'aviez déjà conseillé à d'autre utilisateur. J'ai donc eu 2 rapports. Que dois-je faire ensuite ?
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 09, 2012, 17:58:38
Bonsoir laura,

Bienvenu sur Security-X

Tu peux donc démarrer en mode sans échec ?

Poste les rapports obtenus de cette manière :

Une aide à l'utilisation ici (http://forum.security-x.fr/cours-et-tutoriels-322/(tutoriel)-impression-d%27ecran-et-hebergement-de-rapport/msg60884/#msg60884)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 09, 2012, 18:06:12
Voici les liens obtenus :

http://security-x.fr/up/file.php?h=R0ca1e188a228014fae5ffff62de17c20

http://security-x.fr/up/file.php?h=Rc7e24c2774ae747c6ae45d105daf9760
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 09, 2012, 18:31:13
Re,

Une raison pour que ce pc ne soit pas à jour avec le service pack 1 et Internet explorer 9 ?


Tu as été infecté car certains plugin et addon (adobe reader, flash, java ...) n'étaient pas à jour sur ce pc, on s'en occupera en fin de procédure.


1) Relance  OTL.exe

(Utilisateur de Vista/Windows 7 faites un clic droit -> "Exécuter en tant qu'administrateur")

/!\ Attention, utilisateur d'Avast! ou d'autres antivirus, ne lancez pas OTL en mode sandbox /!\



:OTL
[2012/12/03 19:40:07 | 000,001,078 | ---- | C] () -- C:\Users\Laura\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
[2012/12/03 19:40:06 | 095,023,320 | ---- | C] () -- C:\ProgramData\0tbpw.pad

:Commands
[emptytemp]



Note :  S'il n'apparait pas, il se trouve ici : C:\_OTL, sous la forme xxxxxxxx_xxxx.log où x sont la date et l'heure

/!\ Ce script est exclusivement réservé à l'utilisateur actuel du sujet, vous ne devez en aucun cas l'utiliser de votre propre chef sur un autre pc, sous risque d'endommager le système /!\


Tu devrais pouvoir redémarrer normalement à partir de maintenant, confirme-moi le (ou pas) et nous poursuivrons.

 :AAN
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 09, 2012, 19:03:02
J'ai suivi toutes les instructions et mon ordinateur a redémarré normalement mais j'ai un soucis de connexion internet (wifi). Je me suis donc remise en mode sans échec avec réseau pour pouvoir accéder à internet.

Le rapport de suppression est apparut lors de mon redémarrage normal, je ne le trouve plus en mode sans échec
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 09, 2012, 19:33:15
Re,

Il s'est enregistré ici :

C:\_OTL, sous la forme xxxxxxxx_xxxx.log où x sont la date et l'heure


Télécharge l'outil suivant ensuite en mode sans échec avec réseau ou sur un autre pc :
Puis effectue l'analyse en mode normal par contre.

Télécharge Farbar Service Scanner (http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/) (de Farbar) sur ton bureau.



(S'il n'apparait pas, tu le trouveras à l'emplacement du fichier FSS.exe, sous le nom FSS.txt )
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 09, 2012, 19:49:47
Voici le rapport :

All processes killed
========== OTL ==========
C:\Users\Laura\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk moved successfully.
C:\ProgramData\0tbpw.pad moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Laura
->Temp folder emptied: 2493172602 bytes
->Temporary Internet Files folder emptied: 821299338 bytes
->FireFox cache emptied: 84937302 bytes
->Flash cache emptied: 3136553 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 572617393 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50875 bytes
RecycleBin emptied: 1549212550 bytes
 
Total Files Cleaned = 5 269,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 12092012_184145

Files\Folders moved on Reboot...
C:\Users\Laura\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 09, 2012, 20:01:57
Et voici le rapport Fss.txt :

Farbar Service Scanner Version: 07-12-2012
Ran by Laura (administrator) on 09-12-2012 at 19:54:11
Running from "C:\Users\Laura\Downloads"
Windows 7 Home Premium  (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo IP returned error. Yahoo IP is offline
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.

BITS Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============
Checking Start type of SharedAccess: ATTENTION!=====> Unable to retrieve start type of SharedAccess. The value does not exist.
Checking ImagePath of SharedAccess: ATTENTION!=====> Unable to retrieve ImagePath of SharedAccess. The value does not exist.
Checking ServiceDll of SharedAccess: ATTENTION!=====> Unable to retrieve ServiceDll of SharedAccess. The value does not exist.
Checking Start type of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.
Checking ImagePath of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.
Checking ServiceDll of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys
[2012-02-15 13:44] - [2011-12-28 04:59] - 0499200 ____A (Microsoft Corporation) DB9D6C6B2CD95A9CA414D045B627422E

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-05-12 18:55] - [2012-03-30 12:09] - 1895280 ____A (Microsoft Corporation) 624C5B3AA4C99B3184BB922D9ECE3FF0

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll
[2012-10-10 18:29] - [2012-06-02 06:25] - 0182272 ____A (Microsoft Corporation) BAF19B633933A9FB4883D27D66C39E9A

C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll
[2009-07-14 01:09] - [2009-07-14 02:41] - 0565760 ____A (Microsoft Corporation) F8E058D17363EC580E4B7232778B6CB5

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 09, 2012, 21:43:58
Re,

Tu as les symptômes des dommages causé normalement par le rootkit qui accompagne cette infection, alors que je n'ai pas vu les traces de ce rootkit sur les rapports ... (souci de services système et connexion réseau)

On va donc faire une vérification avant les réparations :

Télécharge TDSSKiller (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) de Kaspersky sur ton bureau.

C:\ TDSSKiller.x.x.x.x_date_heure_log.txt

Poste son contenu dans ta prochaine réponse.

Un aide à l'utilisation ici (http://forum.security-x.fr/tutoriels-317/tutoriel-tdsskiller-nouvelle-version/)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 09, 2012, 22:12:55
Dans la fenêtre de résultat apparaît : No threat found. Le rapport n'est donc pas nécessaire ?
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 09, 2012, 22:30:43
Re,

Oui, c'ets bon, ça ne m'étonne pas trop, comme j'ai dit je ne voyais pas les indications du rootkit dans les rapports ...

On passe aux réparations :

1) Télécharge Windows Repair (http://www.tweaking.com/files/setups/tweaking.com_windows_repair_aio_setup.exe) (de Tweaking.com) sur ton bureau.



(S'il n'apparait pas, tu le trouveras à l'emplacement du fichier FSS.exe, sous le nom FSS.txt )

 :AAN
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 09, 2012, 23:35:31
Désolé j'ai mis du temps ! 

Voici le rapport :

Farbar Service Scanner Version: 07-12-2012
Ran by Laura (administrator) on 09-12-2012 at 23:28:12
Running from "C:\Users\Laura\Downloads"
Windows 7 Home Premium  (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo IP returned error. Yahoo IP is offline
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============
MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.

bfe Service is not running. Checking service configuration:
The start type of bfe service is OK.
The ImagePath of bfe service is OK.
The ServiceDll of bfe service is OK.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============
wuauserv Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.

BITS Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============
Checking Start type of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.
Checking ImagePath of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.
Checking ServiceDll of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys
[2012-02-15 13:44] - [2011-12-28 04:59] - 0499200 ____A (Microsoft Corporation) DB9D6C6B2CD95A9CA414D045B627422E

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-05-12 18:55] - [2012-03-30 12:09] - 1895280 ____A (Microsoft Corporation) 624C5B3AA4C99B3184BB922D9ECE3FF0

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll
[2012-10-10 18:29] - [2012-06-02 06:25] - 0182272 ____A (Microsoft Corporation) BAF19B633933A9FB4883D27D66C39E9A

C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll
[2009-07-14 01:09] - [2009-07-14 02:41] - 0565760 ____A (Microsoft Corporation) F8E058D17363EC580E4B7232778B6CB5

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 10, 2012, 10:52:26
Re,

Tu as effectué toute la partie avec Windows Repair avant de refaire ce scan FSS ?

Tu peux me faire ceci aussi s'il te plait :

Télécharge RogueKiller (http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe) (de Tigzy) sur ton bureau.


(S'il ne s'ouvre pas, clique sur le bouton "Rapport", il est aussi enregistré sur le bureau : RKreport.txt)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 10, 2012, 11:42:27
Oui j'ai fais toute la partie avec windows repair en mode sans échec car ça ne marchait pas en mode normal. Je m'y suis sans doute mal prise ..
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 10, 2012, 11:44:12
Re,

Refais-le en mode normal, puis fais aussi le scan avec Roguekiller que je te propose.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 10, 2012, 11:49:14
Le soucis c'est qu'en mode normal l'outil windows repair ne se lance pas.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 10, 2012, 11:53:14
 :P Ben faut me le dire ...

Vous êtes nos yeux devant le pc, si vous ne nous donnez pas le maximum de détails, difficile pour nous de savoir ce qu'il se passe ;)

Fait juste Roguekiller en mode normal pour le moment s'il te plait, s'il ne se lance pas, dis-le moi.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 10, 2012, 12:01:15
Oui désolé j'aurais du mieux le préciser  :)

Le rapport est :

RogueKiller V8.3.2 [Dec  7 2012] par Tigzy
mail : tigzyRK<at>gmail<dot>com
Remontees : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Site Web : http://www.sur-la-toile.com/RogueKiller/
Blog : http://tigzyrk.blogspot.com/

Systeme d'exploitation : Windows 7 (6.1.7600 ) 64 bits version
Demarrage : Mode normal
Utilisateur : Laura [Droits d'admin]
Mode : Recherche -- Date : 10/12/2012 11:55:35

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrees de registre : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
[ZeroAccess][FILE] n : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\n --> TROUVÉ
[ZeroAccess][FILE] n : C:\$recycle.bin\S-1-5-21-3269826459-1208102038-1188501346-1000\$1789fcce0045cd665ef04bbcb8c98c9b\n --> TROUVÉ
[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\@ --> TROUVÉ
[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-3269826459-1208102038-1188501346-1000\$1789fcce0045cd665ef04bbcb8c98c9b\@ --> TROUVÉ
[ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\U --> TROUVÉ
[ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-3269826459-1208102038-1188501346-1000\$1789fcce0045cd665ef04bbcb8c98c9b\U --> TROUVÉ
[ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\L --> TROUVÉ
[ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-3269826459-1208102038-1188501346-1000\$1789fcce0045cd665ef04bbcb8c98c9b\L --> TROUVÉ
[ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> TROUVÉ

¤¤¤ Driver : [NON CHARGE] ¤¤¤

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ Fichier HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts



¤¤¤ MBR Verif: ¤¤¤

+++++ PhysicalDrive0: TOSHIBA MK6465GSX +++++
--- User ---
[MBR] c08d23c5728c110961887f6080956dff
[BSP] 7e9c444929c8e4c7cbe094f6a91c74ad : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 400 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 821248 | Size: 305081 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 625627136 | Size: 304997 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: SD Card +++++
--- User ---
[MBR] f88b70e514c1edfae01ff8f50a59e496
[BSP] df4f83c1f72e36823a12b0dfc7617313 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT16 (0x06) [VISIBLE] Offset (sectors): 137 | Size: 1875 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Termine : << RKreport[1]_S_10122012_115535.txt >>
RKreport[1]_S_10122012_115535.txt
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 10, 2012, 14:05:18
Re,

Ah ben voilà, ça m'étonnais aussi de pas voir la cause des symptômes ...

à faire :

1) Relance RogueKiller :


(S'il ne s'ouvre pas, il est enregistré sur le bureau : RKreport.txt)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 10, 2012, 18:45:15
Voici le rapport :

RogueKiller V8.3.2 [Dec  7 2012] par Tigzy
mail : tigzyRK<at>gmail<dot>com
Remontees : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Site Web : http://www.sur-la-toile.com/RogueKiller/
Blog : http://tigzyrk.blogspot.com/

Systeme d'exploitation : Windows 7 (6.1.7600 ) 64 bits version
Demarrage : Mode normal
Utilisateur : Laura [Droits d'admin]
Mode : Suppression -- Date : 10/12/2012 18:37:36

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrees de registre : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REMPLACÉ (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REMPLACÉ (0)

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
[ZeroAccess][FILE] n : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\n --> SUPPRIMÉ
[ZeroAccess][FILE] n : C:\$recycle.bin\S-1-5-21-3269826459-1208102038-1188501346-1000\$1789fcce0045cd665ef04bbcb8c98c9b\n --> SUPPRIMÉ
[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\@ --> SUPPRIMÉ
[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-3269826459-1208102038-1188501346-1000\$1789fcce0045cd665ef04bbcb8c98c9b\@ --> SUPPRIMÉ
[Del.Parent][FILE] 00000004.@ : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\U\00000004.@ --> SUPPRIMÉ
[Del.Parent][FILE] 00000008.@ : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\U\00000008.@ --> SUPPRIMÉ
[Del.Parent][FILE] 000000cb.@ : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\U\000000cb.@ --> SUPPRIMÉ
[Del.Parent][FILE] 80000000.@ : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\U\80000000.@ --> SUPPRIMÉ
[Del.Parent][FILE] 80000032.@ : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\U\80000032.@ --> SUPPRIMÉ
[Del.Parent][FILE] 80000064.@ : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\U\80000064.@ --> SUPPRIMÉ
[ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\U --> SUPPRIMÉ
[ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-21-3269826459-1208102038-1188501346-1000\$1789fcce0045cd665ef04bbcb8c98c9b\U --> SUPPRIMÉ
[Del.Parent][FILE] 00000004.@ : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\L\00000004.@ --> SUPPRIMÉ
[Del.Parent][FILE] 201d3dde : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\L\201d3dde --> SUPPRIMÉ
[ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-18\$1789fcce0045cd665ef04bbcb8c98c9b\L --> SUPPRIMÉ
[ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-21-3269826459-1208102038-1188501346-1000\$1789fcce0045cd665ef04bbcb8c98c9b\L --> SUPPRIMÉ
[ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> SUPPRIMÉ

¤¤¤ Driver : [NON CHARGE] ¤¤¤

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ Fichier HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts



¤¤¤ MBR Verif: ¤¤¤

+++++ PhysicalDrive0: TOSHIBA MK6465GSX +++++
--- User ---
[MBR] c08d23c5728c110961887f6080956dff
[BSP] 7e9c444929c8e4c7cbe094f6a91c74ad : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 400 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 821248 | Size: 305081 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 625627136 | Size: 304997 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: SD Card +++++
--- User ---
[MBR] f88b70e514c1edfae01ff8f50a59e496
[BSP] df4f83c1f72e36823a12b0dfc7617313 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT16 (0x06) [VISIBLE] Offset (sectors): 137 | Size: 1875 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Termine : << RKreport[3]_D_10122012_183736.txt >>
RKreport[1]_S_10122012_115535.txt ; RKreport[2]_S_10122012_183700.txt ; RKreport[3]_D_10122012_183736.txt

Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 10, 2012, 18:54:37
Re,

à faire pour s'assurer que le rootkit n'est plus dans les corbeilles :
http://lenewbie.com/2011/10/04/reparer-la-corbeille-sous-windows-7/

Il suffit de faire la commande pour C: chez toi.

Ensuite, redémarre le pc en mode normal, puis refais cette manipulation : (ou dis-moi s'il ne peut se lancer comme la dernière fois)

Télécharge Windows Repair (http://www.tweaking.com/files/setups/tweaking.com_windows_repair_aio_setup.exe) (de Tweaking.com) sur ton bureau.

Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 10, 2012, 19:33:29
Alors dans " invite de commandes " apres avoir mis pour C: on me dit le répertoire est vide . Impossible de lancer windows repair en mode normal.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 10, 2012, 20:01:12
Re,

Attention, tu fais bien ce qui est marqué sur le lien hein, j'ai signalé C: pour pas que tu cherches d'autres répertoire, mais la commande à taper c'est :
Citer
rd /s /q C:\$Recycle.bin

Pour Windows repair, que se passe-t-il exactement ? il plante, il met une erreur, ou juste il se lance pas quand tu double-clique dessus ?
Tu as bien pensé à faire un clic-droit -> "exécuter en tant qu'administrateur" comme demandé ?
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 10, 2012, 20:16:09
Jusqu'à maintenant ça ne marchait pas quand j'entrée " le code " entier, et la je vois qu'il me dit : le répertoire n'est pas vide.     Pour windows repair ( en mode normal) je fais un double clic en éxécutant en tant qu'administrateur, un message " contrôle administrateur " s'affiche en me demandant si j'accepte que le programme suivant inconnu à apporter des modifications etc..    Je clique sur oui, puis rien ne se passe ensuite.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 10, 2012, 23:17:33
Re,

Bon, laisse tomber pour le vidage des corbeilles.

Fais la procédure Windows repair en mode sans échec, puis, à la suite, refais ceci :

Relance FSS :



(S'il n'apparait pas, tu le trouveras à l'emplacement du fichier FSS.exe, sous le nom FSS.txt )
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 00:10:01
Farbar Service Scanner Version: 07-12-2012
Ran by Laura (administrator) on 11-12-2012 at 00:03:16
Running from "C:\Users\Laura\Downloads"
Windows 7 Home Premium  (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo IP returned error. Yahoo IP is offline
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============
MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.

bfe Service is not running. Checking service configuration:
The start type of bfe service is OK.
The ImagePath of bfe service is OK.
The ServiceDll of bfe service is OK.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============
Checking Start type of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.
Checking ImagePath of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.
Checking ServiceDll of iphlpsvc: ATTENTION!=====> Unable to open iphlpsvc registry key. The service key does not exist.


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys
[2012-02-15 13:44] - [2011-12-28 04:59] - 0499200 ____A (Microsoft Corporation) DB9D6C6B2CD95A9CA414D045B627422E

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-05-12 18:55] - [2012-03-30 12:09] - 1895280 ____A (Microsoft Corporation) 624C5B3AA4C99B3184BB922D9ECE3FF0

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll
[2012-10-10 18:29] - [2012-06-02 06:25] - 0182272 ____A (Microsoft Corporation) BAF19B633933A9FB4883D27D66C39E9A

C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll
[2009-07-14 01:09] - [2009-07-14 02:41] - 0565760 ____A (Microsoft Corporation) F8E058D17363EC580E4B7232778B6CB5

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 11, 2012, 10:57:39
Re,

Ok, il manque encore des éléments qui n'ont pas été réparé :

à faire ne mode normal si possible, sinon en mode sans échec.

Télécharge Services Repair (http://kb.eset.com/library/ESET/KB%20Team%20Only/Malware/ServicesRepair.exe) (de Eset) sur ton bureau.



(S'il n'apparait pas, tu le trouveras à l'emplacement du fichier FSS.exe, sous le nom FSS.txt )
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 13:08:59
Voici le CC Support\Logs\SvcRepair.txt :

Log Opened: 2012-12-11 @ 12:37:56
12:37:56 - -----------------
12:37:56 - | Begin Logging |
12:37:56 - -----------------
12:37:56 - Fix started on a WIN_7 X64 computer
12:37:56 - Prep in progress.  Please Wait.
12:37:56 - Prep complete
12:37:56 - Repairing Services Now.  Please wait...
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BFE.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\SubLayer>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\Provider>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\Filter>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\BootTime\Filter>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\BootTime>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BITS.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Performance>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\iphlpsvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Teredo\{FA88062C-9A61-4C1E-AC45-7143F8F01AAD}>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Isatap\{8AD2FB26-F91E-44F1-9B24-3C0AE56C9CE0}>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Isatap>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\IPHTTPS>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Interfaces>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\config>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\MpsSvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\RPC-EPMap>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSOut>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSOut> failed with: Le fichier spécifié est introuvable.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSIn>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSIn> failed with: Le fichier spécifié est introuvable.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\DHCP>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\DHCP> failed with: Le fichier spécifié est introuvable.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\SharedAccess.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Static\System>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Static>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Configurable\System>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Configurable>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Epoch2>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Epoch>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\StandardProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\StandardProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\PublicProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\PublicProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\DomainProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\DomainProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\WinDefend.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\TriggerInfo\0>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\TriggerInfo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\wscsvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wscsvc\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wscsvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wscsvc>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\wuauserv.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wuauserv\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wuauserv\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wuauserv>

SetACL finished successfully.
12:37:57 - Services Repair Complete.
12:38:48 - Reboot Initiated
Log Opened: 2012-12-11 @ 12:43:59
12:43:59 - -----------------
12:43:59 - | Begin Logging |
12:43:59 - -----------------
12:43:59 - Fix started on a WIN_7 X64 computer
12:43:59 - Prep in progress.  Please Wait.
12:44:03 - Prep complete
12:44:03 - Repairing Services Now.  Please wait...
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BFE.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\SubLayer>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\Provider>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\Filter>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\BootTime\Filter>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\BootTime>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BITS.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Performance>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\iphlpsvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Teredo\{FA88062C-9A61-4C1E-AC45-7143F8F01AAD}>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Isatap\{8AD2FB26-F91E-44F1-9B24-3C0AE56C9CE0}>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Isatap>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\IPHTTPS>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Interfaces>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\config>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\MpsSvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\RPC-EPMap>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSOut>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSOut> failed with: Le fichier spécifié est introuvable.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSIn>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSIn> failed with: Le fichier spécifié est introuvable.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\DHCP>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\DHCP> failed with: Le fichier spécifié est introuvable.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc>

SetACL finished successfully.










et voici le rapport Fss.txt :

Farbar Service Scanner Version: 07-12-2012
Ran by Laura (administrator) on 11-12-2012 at 13:01:38
Running from "C:\Users\Laura\Downloads"
Windows 7 Home Premium  (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo IP returned error. Yahoo IP is offline
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys
[2012-02-15 13:44] - [2011-12-28 04:59] - 0499200 ____A (Microsoft Corporation) DB9D6C6B2CD95A9CA414D045B627422E

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-05-12 18:55] - [2012-03-30 12:09] - 1895280 ____A (Microsoft Corporation) 624C5B3AA4C99B3184BB922D9ECE3FF0

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll
[2012-10-10 18:29] - [2012-06-02 06:25] - 0182272 ____A (Microsoft Corporation) BAF19B633933A9FB4883D27D66C39E9A

C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll
[2009-07-14 01:09] - [2009-07-14 02:41] - 0565760 ____A (Microsoft Corporation) F8E058D17363EC580E4B7232778B6CB5

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 11, 2012, 14:34:03
Re,

Ok, c'est beaucoup mieux.

As-tu retrouvé la connexion en mode normal à présent ?
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 15:01:12
Non toujours pas de connexion en mode normal  :-\
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 11, 2012, 15:14:01
Re,

Comment te connectes-tu ? En wi-fi, en cable Ethernet, ou autrement ?

Avais-tu un antivirus ou un parefeu sur ce pc avant l'infection ou que tu aurais supprimé pendant la procédure ?
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 15:20:03
Je me connecte en wi-fi. J'avais et j'ai toujours l'antivirus Bitdefender.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 11, 2012, 16:05:28
Re,

Alors je peux te dire que ton antivirus est soit endommagé, soit mal installé. (peut-être à cause de l'infection)
Sur les rapports rien n'indique qu'il est actif, il n'y a que des restes ...

Il faudrait tester de la désinstaller, puis le réinstaller, je pense.

Si tu as des soucis pour le désinstalle,r je peux te fournir un outil spécifique pour cela (il semble ne pas apparaitre dans ta liste des programmes)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 16:43:18
J'ai pas fais les mises à jours depuis pas mal de temps, c'est sans doute ça. Pour le réinstaller, je vais donc devoir acheter de nouveau l'antivirus ?
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 17:17:28
En tout cas, merci beaucoup de ta patience et de m'avoir guidé jusque là déjà :)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 11, 2012, 18:46:52
Re,

Non, non aucun besoin de le racheter, ta licence est toujours fonctionnelle, il suffira de la remettre.
Tu peux aussi "réparer" l'installation si tu trouves le logiciel dans la liste des programmes (personnellement, je ne le vois pas ...)

Nous n'avons pas terminé ensuite, il faut mettre à jour plusieurs logiciels sur le pc, nettoyer les outils utilisé et je te donnerais des conseils aussi.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 19:36:05
J'ai trouvé le logiciel , j'ai essayé "réparer" . La réparation est en cours et la connexion internet fonctionne enfin
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 19:39:11
L'antivirus a bien été réparé.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 11, 2012, 19:51:17
Re,

Bien, j'avais visé juste donc, ça m'étonnais de voir aucun antivirus actif, et souvent quand ils sont endommagé et qu'ils gère un parefeu ou des protection web, il peuvent alors couper l'accès Internet.

Pour terminer donc :

1) Suppression des logiciels :

Supprime manuellement :
- FSS
- Windows repair
- Service repair

2) Relance  OTL.exe

Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 23:16:12
J'ai du mal à faire les manipulations, mon Pc tourne vraiment au ralentit ( ce qu'il ne faisait pas avant ). Il fonctionne normalement les premières minutes après le démarrage puis il se plante.                        Je vais commencer l'étape du téléchargement de Sxcu mais je doute d'y arriver
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 11, 2012, 23:25:52
Re,

Tu as supprimé les outils déjà ?

Attends avant de faire les mises à jour, on va refaire un scan pour voir :

Télécharge MalwareByte's Anti-Malware (http://www.inforumatique.fr/site/download/download-82+malwarebytes-anti-malware.php) :

Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 23:45:33
J'ai supprimé les outils oui
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 11, 2012, 23:55:04
Impossible de télécharger quoique se soit en mode normal, le pc se plante en plein téléchargement.
Je suis donc obligée de basculer en mode sans échec pour télécharger puis je lance le programme en mode normal.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 12, 2012, 11:58:25
Re,

Peux-tu s'il te plait désinstaller BitDefender, je pense qu'il est en cause pour tout ces désagrément.

Si tu as toujours la clé de licence, tu pourras le réinstaller complétement par la suite.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 12, 2012, 14:55:58
J'ai fini l'analyse et j'ai supprimé les éléments infectés.

 J'ai désinstallé BitDefender.

Voici le rapport :

Malwarebytes Anti-Malware (Essai) 1.65.1.1000
www.malwarebytes.org

Version de la base de données: v2012.12.11.12

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Laura :: LAURA-TOSH [administrateur]

Protection: Activé

12/12/2012 13:22:55
mbam-log-2012-12-12 (13-22-55).txt

Type d'examen: Examen complet (C:\|D:\|E:\|F:\|Q:\|)
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 389709
Temps écoulé: 53 minute(s), 21 seconde(s)

Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)

Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)

Fichier(s) détecté(s): 0
(Aucun élément nuisible détecté)

(fin)

Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 12, 2012, 15:05:47
Re,

Quels éléments infectés ? Il n'a rien trouvé justement ...
Il t'avait signalé quelque chose ?

Comment se comporte le pc sans Bitdefender ? Mieux ou pas ? La connexion est revenu ?
Les téléchargements fonctionnent ?
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 12, 2012, 15:32:21
Alors , il avait trouvé 21 éléments infectés. Le soucis c'est que le pc s'était planté juste après avoir supprimé la sélection. J'ai donc refait une analyse pour être sûre.

Le pc se comporte mieux sans l'antivirus, je n'ai plus de bugs, les téléchargements se font normalement et la connexion est revenue .
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 12, 2012, 18:27:50
Re,

Peux-tu me fournir le rapport initial de MBAM, tu dois le trouver dans l'onglet "Rapport/log"
Regarde la date et l'heure pour avoir le premier.

 :AAN
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 12, 2012, 19:07:47
Je ne trouve pas rapports/logs, je suis désolé mais je ne suis pas très doué !
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 12, 2012, 19:22:42
Re,

Pas de souci, nous sommes là quand c'est comme ça, faut pas hésiter à demander.

Tu ouvres Malwarebyte's, tu verras des onglets en haut, l'un se nomme "Rapport/logs" :
(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fwww.astucesinternet.com%2Fdata%2Fmalwarebytes%2Fmalwarebytes-onglets-007.png&hash=50097ee88c74857acc2929a809e296266e33aaad)

dedans tu auras une liste de rapport, trouve celui qui contient les détection, ouvre-le puis copie son contenu dans ta prochaine réponse.

 :AAN
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 12, 2012, 19:28:18
Ah merci !

Malwarebytes Anti-Malware (Essai) 1.65.1.1000
www.malwarebytes.org

Version de la base de données: v2012.12.11.12

Windows 7 x64 NTFS (Mode sans échec/Réseau)
Internet Explorer 8.0.7600.16385
Laura :: LAURA-TOSH [administrateur]

Protection: Désactivé

12/12/2012 11:40:44
mbam-log-2012-12-12 (11-40-44).txt

Type d'examen: Examen complet (C:\|D:\|)
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 387760
Temps écoulé: 54 minute(s), 34 seconde(s)

Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 16
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB38E21A-0133-419D-92AD-ECDFD5244D6D} (Adware.ShoppingReport2) -> Mis en quarantaine et supprimé avec succès.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB620C54-E229-4942-87CE-E717109FC8C6} (Adware.ShoppingReport2) -> Mis en quarantaine et supprimé avec succès.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Mis en quarantaine et supprimé avec succès.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport2 (Adware.HotBar.SS2) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.HbAx (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.HbAx.1 (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.HbInfoBand (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.HbInfoBand.1 (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.IEButton (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.IEButton.1 (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.IEButtonA (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.IEButtonA.1 (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.RprtCtrl (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCR\ShoppingReport2.RprtCtrl.1 (Adware.ShopperReports) -> Mis en quarantaine et supprimé avec succès.
HKCU\Software\ShoppingReport2 (Adware.ShoppingReport2) -> Mis en quarantaine et supprimé avec succès.
HKLM\SOFTWARE\ShoppingReport2 (Adware.ShoppingReport2) -> Mis en quarantaine et supprimé avec succès.

Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)

Dossier(s) détecté(s): 3
C:\Program Files (x86)\ShoppingReport2 (Adware.ShoppingReport2) -> Mis en quarantaine et supprimé avec succès.
C:\Program Files (x86)\ShoppingReport2\Bin (Adware.ShoppingReport2) -> Mis en quarantaine et supprimé avec succès.
C:\Program Files (x86)\ShoppingReport2\Bin\2.7.21 (Adware.ShoppingReport2) -> Mis en quarantaine et supprimé avec succès.

Fichier(s) détecté(s): 2
C:\Program Files\Common Files\Bitdefender\SetupInformation\{2AB9289D-6432-4CC0-8869-A195C3F0CFCC}\ThreatScanner.exe (Trojan.Downloader) -> Mis en quarantaine et supprimé avec succès.
C:\Program Files (x86)\ShoppingReport2\Uninst.exe (Adware.HotBar.SS2) -> Mis en quarantaine et supprimé avec succès.

(fin)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 12, 2012, 21:38:18
Re,

Ok, ce n'était que des restes de sponsor publicitaire.

Peux-tu me dire à présent où tu en étais des manipulation de ce message :
http://forum.security-x.fr/desinfections/a-l%27aide-virus-ministere-de-l%27interieur/msg84484/#msg84484

Quelles sont celles déjà faite ou pas ?
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 12, 2012, 21:55:10
Je suis à l'étape 3 , et je ne l'ai pas commencé
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 12, 2012, 22:04:44
Re,

Très bien, débute alors les mises à jour, commence par celle du système avec Windows update, le service pack 1 et IE9, c'est le plus long.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 13, 2012, 16:19:39
Pour le service pack 1 et IE9 les mises à jours ne se font pas, j'ai des échecs à chaque tentatives.

Sinon j'ai réussi le reste des mises à jours.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 13, 2012, 18:43:42
Re,

Peux-tu me donner le code d'erreur d'installation du service pack 1 ou IE 9 ?
(sous la forme 0x00000000, on le trouve sous Widnows update -> historique des mises à jour)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 13, 2012, 18:47:01
Service Pack 1 : x64 (KB976932)

Détails de l'erreur : Code 8007045D
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 13, 2012, 19:05:44
Re,

Tu as pu faire d'autres mises à jour via Windows update en dehors de ces deux là ou non ?

Refais ceci aussi s'il te plait :
Télécharge Farbar Service Scanner (http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/) (de Farbar) sur ton bureau.



(S'il n'apparait pas, tu le trouveras à l'emplacement du fichier FSS.exe, sous le nom FSS.txt )
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 13, 2012, 20:47:58
Farbar Service Scanner Version: 10-12-2012
Ran by Laura (administrator) on 13-12-2012 at 19:32:12
Running from "C:\Users\Laura\Downloads"
Windows 7 Home Premium  (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 13, 2012, 21:15:38
Ok,

Dis-moi si tu peux télécharger et installer le service pack 1 avec ce lien :
http://download.microsoft.com/download/0/A/F/0AFB5316-3062-494A-AB78-7FB0D4461357/windows6.1-KB976932-X64.exe

(attention, c'est lourd, plus de 900Mo !)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 13, 2012, 23:02:20
L'installation n'a pas réussi.

ERROR_IO_DEVICE(0x8007045d)
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 14, 2012, 10:29:17
Re,

Peux-tu faire ceci s'il te plait :

http://windows.microsoft.com/fr-FR/windows-vista/Check-your-hard-disk-for-errors

Coche les deux option et valide.
Le pc va demander à redémarrer, accepte.

Au redémarrage, tu vas avoir un scan sur un écran bleu ou noir qui va durer assez longtemps, laisse-le se dérouler.
Le pc démarrera seul ensuite.

Quand cela sera fait, retente l'installation des mises à jour, d'abord via Windows update :
Démarrer -> Tous les programmes -> Windows Update

Si tu obtiens la même erreur, vient me le dire.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 15, 2012, 02:14:08
L'installation de Windows Update a réussi !
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 15, 2012, 10:06:52
Re,

Voilà une bonne nouvelle ;)

Relance Windows Update et installe Internet Explorer 9 à présent et toute les autres mises à jour proposées en prioritaire :
Démarrer -> Tous les programmes -> Windows Update
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 15, 2012, 14:17:59
Je pense que Internet explorer est déjà installé car je ne le trouve plus dans les mises à jours. J'ai vérifié dans historiques des mises à jours et je le retrouve lorsqu'il y avait eu un échec de mise à jours ces jours derniers.
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 15, 2012, 18:35:21
Re,

Ok, on va vérifier si on est bon pour les mises à jour alors ;)


Télécharge SX Check&Update (http://tools.security-x.fr/download.php?f=SXCU.exe) (de Igor51 ) sur ton bureau.



Ferme le programme via "Quit"
Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 15, 2012, 19:14:47
SX Check&Update
Lien vers le tutoriel : http://forum.security-x.fr/tutoriels-317/tutoriel-sx-checkupdate/
---
Windows Version : Windows 7 64bits
Service Pack : 1
UserName : Laura
15/12/2012
19:13:47
version = v0.3.0 
---
Windows Update Information :
AUOptions : 4
Automatically, no notification
---

---
Name : FlashPlayer ActiveX 
Version : 11.5.502.135
Flash Player ActiveX  est à jour

Name : FlashPlayer Plugin FF
Version : 11.5.502.135
Flash Player Plugin FF est à jour

Name : FlashPlayer Plugin
Version : 11.5.502.135
Flash Player Plugin est à jour

Nom : Mozilla Firefox 16.0.2 (x86 fr)
   Version : 16.0.2

Java Information :
   Nom : Java 7 Update 9
   Version : 7.0.90
Java 7 Update 9 n'est pas à jour! (7.0.100)

Nom : Adobe Reader XI - Français
Version : 11.0.00
Adobe Reader est à jour

Nom : Internet Explorer
   Version : 9.0.8112.16421

Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: hyunkel30 le décembre 15, 2012, 22:01:46
Re,

Ok, on va mettre Java a jour, la nouvelle version vient de sortir.



Relance SX Check&Update :

Titre: Re : A l'aide : Virus ministère de l'intérieur
Posté par: laura57 le décembre 15, 2012, 23:10:23
Et bien merci beaucoup pour ton aide !  Au revoir ;D