Bonjour damvdr,
Effectivement ton ordinateur est infecté.
Voici la correction à effectuer avec FRST. Tu peux t'aider de cette
note explicative avec des captures d'écran.
Ouvre le bloc-notes : Touche Windows + R,
Dans le champs "Exécuter", saisir notepad et OK.
Copie/Colle dedans ce qui suit :
Code : Tout sélectionner
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Run: [6lIGjAcyGU] => C:\Program Files\B2DAQ6232N\5HVII9SMX.exe [370688 2017-02-20] (HhhooooooooooooooooooooOO)
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Run: [4Vikk2mTm4] => C:\Program Files\5NUJCX9MTA\5NUJCX9MT.exe [370688 2017-02-20] (HhhooooooooooooooooooooOO)
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Run: [1heLRMfF0k] => C:\Program Files\0O6UVW4FOR\7RUGVZ0ZI.exe [370688 2017-02-20] (HhhooooooooooooooooooooOO)
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Run: [gdnH6sy5UB] => C:\Program Files\H3JA7VJT3C\BH0IZZ9BY.exe [370688 2017-02-20] (HhhooooooooooooooooooooOO)
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Run: [6BSTRyhBL8] => C:\Program Files\XAO9ZTH8A0\RP6GRX7R5.exe [370688 2017-02-20] (HhhooooooooooooooooooooOO)
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Run: [akkxpXUPW8] => C:\Program Files\HM764VIPVF\HM764VIPV.exe [370688 2017-02-20] (HhhooooooooooooooooooooOO)
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Run: [Waz1O9p37X] => C:\Program Files\YC8W6NDXGC\SQQ3YQ3GB.exe [370688 2017-02-20] (HhhooooooooooooooooooooOO)
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Run: [RcH37Rrcwf] => C:\Program Files\I43XEPFI9O\I43XEPFI9.exe [370688 2017-02-20] (HhhooooooooooooooooooooOO)
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer: [DisallowRun] 1
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [1] Generator3.0.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [2] Generator 3.0.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [3] Generator3.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [4] Generator 3.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [5] Generator2.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [6] Generator 2.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [7] Generator2.0.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [8] Generator 2.0.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [9] Generator1.0.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [10] Generator 1.0.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [11] Generator1.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [12] Generator 1.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [13] Generatorbb.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [14] Generator bb.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [15] Generator.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [16] Generador.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [17] Generador3.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [18] Generador3.0.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [19] Generador2.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [20] Gener.exe
HKU\S-1-5-21-687109208-295075809-1198124490-1001\...\Policies\Explorer\DisallowRun: [21] Genera.exe
HKLM\...\Providers\x9leisov: C:\Program Files (x86)\Sherset Community\local64spl.dll [308224 2017-02-20] ()
ShellExecuteHooks: Pas de nom - {EE208D6E-F444-11E6-AF06-64006A5CFC23} - C:\Program Files (x86)\Erniedkfack\Atodersqtation.dll [146432 2017-02-20] ()
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.2.220\WsAppService.exe [441344 2017-01-05] (Wondershare) [Fichier non signé]
C:\Program Files (x86)\Wondershare
2017-02-20 11:42 - 2017-02-20 11:42 - 07680000 _____ C:\Program Files (x86)\GUT6848.tmp
2017-02-20 11:42 - 2017-02-20 11:42 - 00016816 _____ C:\WINDOWS\System32\Tasks\856I4I50L7301-dll
2017-02-20 11:42 - 2017-02-20 11:42 - 00000000 ____D C:\Program Files (x86)\GUM6847.tmp
2017-02-20 11:32 - 2017-02-20 11:32 - 04015056 _____ C:\Users\Damien\Desktop\adwcleaner_6.043.exe
2017-02-20 09:58 - 2017-02-20 09:58 - 00000000 ____D C:\Users\Damien\AppData\Roaming\Reazowardlaqule
2017-02-20 09:54 - 2017-02-20 09:54 - 00000000 ___HD C:\OneDriveTemp
2017-02-20 09:49 - 2017-02-20 09:58 - 00000000 ____D C:\Program Files (x86)\BeCleaner
2017-02-20 09:49 - 2017-02-20 09:51 - 00000000 ____D C:\Users\Damien\AppData\Local\Anibeent
2017-02-20 09:49 - 2017-02-20 09:49 - 00016808 _____ C:\WINDOWS\System32\Tasks\856I4I50L7301
2017-02-20 09:49 - 2017-02-20 09:49 - 00006070 _____ C:\WINDOWS\System32\Tasks\Sherset Community
2017-02-20 09:49 - 2017-02-20 09:49 - 00005106 _____ C:\WINDOWS\System32\Tasks\Anuvtain
2017-02-20 09:49 - 2017-02-20 09:49 - 00000000 ___HD C:\ProgramData\856I4I50L7301
2017-02-20 09:49 - 2017-02-20 09:49 - 00000000 ____D C:\Program Files\YC8W6NDXGC
2017-02-20 09:49 - 2017-02-20 09:49 - 00000000 ____D C:\Program Files\XAO9ZTH8A0
2017-02-20 09:49 - 2017-02-20 09:49 - 00000000 ____D C:\Program Files\I43XEPFI9O
2017-02-20 09:49 - 2017-02-20 09:49 - 00000000 ____D C:\Program Files\HM764VIPVF
2017-02-20 09:49 - 2017-02-20 09:49 - 00000000 ____D C:\Program Files\H3JA7VJT3C
2017-02-20 09:49 - 2017-02-20 09:49 - 00000000 ____D C:\Program Files (x86)\Sherset Community
2017-02-20 09:49 - 2017-02-20 09:49 - 00000000 ____D C:\Program Files (x86)\Erniedkfack
2017-02-20 09:48 - 2017-02-20 09:49 - 00000000 ____D C:\Program Files\0O6UVW4FOR
2017-02-20 09:48 - 2017-02-20 09:48 - 00000000 ____D C:\Program Files\B2DAQ6232N
2017-02-20 09:48 - 2017-02-20 09:48 - 00000000 ____D C:\Program Files\5NUJCX9MTA
Task: {2B9F4C3C-5C66-49CE-9D7C-A3F9BF0340A0} - System32\Tasks\856I4I50L7301 => Rundll32.exe "C:\ProgramData\856I4I50L7301\856I4I50L7301.dll",IILUsWWZ <==== ATTENTION
Task: {629722A3-39E7-43C0-90BF-B2C02F3BA624} - System32\Tasks\Sherset Community => C:\Program Files (x86)\Erniedkfack\grikery.exe [2017-02-20] (Glarysoft Ltd)
Task: {E6A89822-0C62-4C3F-8033-1E8D927C99C5} - System32\Tasks\Anuvtain => "msiexec" /i hxxp://d2buh1bf1g584w.cloudfront.net/msi/rel.php?u=STM3500418AS_9VM0L8V3XXXX9VM0L8V3&v=2017220 /q
Task: {F913F2E4-4423-4A15-8E04-64D867AA11D4} - System32\Tasks\856I4I50L7301-dll => Rundll32.exe "C:\ProgramData\856I4I50L7301\856I4I50L7301.dll",IILUsWWZ
2017-02-20 11:42 - 2017-02-20 11:42 - 7680000 _____ () C:\Program Files (x86)\GUT6848.tmp
Hosts:
EmptyTemp:
RemoveProxy:
Une fois, le texte collé dans le Bloc-notes,
Menu "Fichier" puis "Enregistrer sous",
A gauche, place toi sur le Bureau,
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clique sur "Enregistrer", cela va créer fixlist.txt sur le Bureau.
Relance FRST et clique sur le bouton "Corriger / Fix"
Un redémarrage sera peut-être nécessaire (
pas obligatoire )
Un fichier texte apparait, copie/colle le contenu ici dans un nouveau message.
Redémarre l'ordinateur.
Enfin, pense à réinitialiser tes navigateurs:
==================================
Réinitialise/Répare les navigateurs WEB :
*
réparer Mozilla Firefox (premier paragraphe)
*
réparer Google Chrome (premier paragraphe)
*
Réinitialiser et réparer Internet Explorer