Aidez moi ...cheval de troie

Bonjour, g un problem ... chaque fois que j'essai d'acceder a mes documents ou a la poste de travail l'internet demarre automatiquement et google recherche s'ouvre et me donne les sites de win32 dowloader... qu'est ce que aca veutt dire et que dois je faire ????.. merci
Configuration: Windows XP

7 réponses

  1. Contributeur sécurité
    Bonjour,

    ▶ Télécharge hijackthis

    ▶ Tout est expliqué sur mon site web pour l'installer et l'utiliser correctement.

    ▶ Poste le rapport obtenu dans le bloc note dans ta prochaine réponse.

    Comment copier/coller le rapport :

    ▶ Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

    ▶ ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.
    0
    1. slt merci pour l'aide geoffrey5 ca m'a donne un autre resultat alors g fait analyse this .. mé g pas trouvé de solutions
      0
  2. bonjour,

    je pense que c'est des logiciels espions, avez vous un logiciel anti virus ou un logiciel anti spyware? le mieux c'est d'avoir un logiciel complet c'est à dire un logiciel que l'on paye, passe que les logiciels antivirus gratuit ne valent rien.
    0
    1. Contributeur sécurité
      tu dois poster le rapport comme expliqué dans mon tuto
      0
      1. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:06:56, on 17/02/2009
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.20627)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Opera\opera.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.0.1:8080
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: SysCli.Ctrl - {2D0733B6-0BAC-47C1-909A-D9DB0533FFAF} - C:\WINDOWS\system32\fejokt.dll
        O2 - BHO: WinSafe Class - {b6b571fb-b71d-449c-ad70-82e966328795} - C:\WINDOWS\iehost.dll
        O4 - HKLM\..\Run: [Vistadrv] C:\Program Files\VistaDriveStatus\vsdrv.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\kamsoft.exe
        O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        0
    2. Contributeur sécurité
      ▶ Télécharge malwarebyte's anti-malware

      ▶ Un tutoriel sera à ta disposition pour l'installer et l'utiliser correctement.

      ▶ Fais la mise à jour du logiciel (elle se fait normalement à l'installation)

      ▶ Lance une analyse complète en cliquant sur "Exécuter un examen complet"

      ▶ Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"

      ▶ L'analyse peut durer un bon moment.....

      ▶ Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"

      ▶ Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

      ▶ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

      * Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée

      Et ensuite refais un nouveau rapport hijackthis stp
      0
      1. salut geoffrey5 ... g fait ce que vous m'avez demandé et j'attends vos instructions.... merci
        0
      2. voila les nouveaux resultats de hijackthis :

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:38:15, on 18/02/2009
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.20627)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Opera\opera.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.0.1:8080
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O4 - HKLM\..\Run: [Vistadrv] C:\Program Files\VistaDriveStatus\vsdrv.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        0
    3. ca prends du temps pour telecharger malwarebytes ... je suis entrain de le faire
      0
      1. Malwarebytes' Anti-Malware 1.34
        Version de la base de données: 1773
        Windows 5.1.2600 Service Pack 2

        18/02/2009 11:07:53
        mbam-log-2009-02-18 (11-07-53).txt

        Type de recherche: Examen complet (C:\|D:\|)
        Eléments examinés: 71310
        Temps écoulé: 9 minute(s), 2 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 1
        Clé(s) du Registre infectée(s): 14
        Valeur(s) du Registre infectée(s): 2
        Elément(s) de données du Registre infecté(s): 5
        Dossier(s) infecté(s): 1
        Fichier(s) infecté(s): 19

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        C:\WINDOWS\system32\fejokt.dll (Rogue.FakeAlert) -> Delete on reboot.

        Clé(s) du Registre infectée(s):
        HKEY_CLASSES_ROOT\winapp.winsafe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\TypeLib\{16406580-14ce-4441-b904-ad56cc8064ca} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{967a494a-6aec-4555-9caf-fa6eb00acf91} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{9692be2f-eb8f-49d9-a11c-c24c1ef734d5} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b6b571fb-b71d-449c-ad70-82e966328795} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b6b571fb-b71d-449c-ad70-82e966328795} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\winapp.winsafe.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{2644a8e6-6ad2-4068-b902-5abc07441eed} (Rogue.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{a0960dbb-d8c8-4771-ad4a-f0493ccb1582} (Rogue.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{a8954909-1f0f-41a5-a7fa-3b376d69e226} (Rogue.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{2d0733b6-0bac-47c1-909a-d9db0533ffaf} (Rogue.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d0733b6-0bac-47c1-909a-d9db0533ffaf} (Rogue.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2d0733b6-0bac-47c1-909a-d9db0533ffaf} (Rogue.FakeAlert) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kamsoft (Trojan.Agent) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdoosoft (Trojan.Agent) -> Quarantined and deleted successfully.

        Elément(s) de données du Registre infecté(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

        Dossier(s) infecté(s):
        C:\Program Files\XPPoliceAntivirus (Rogue.XPPoliceAntivirus) -> Quarantined and deleted successfully.

        Fichier(s) infecté(s):
        C:\WINDOWS\iehost.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\fejokt.dll (Rogue.FakeAlert) -> Delete on reboot.
        C:\Program Files\XPPoliceAntivirus\setup.dat (Rogue.XPPoliceAntivirus) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\sf.ico (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\m3.ico (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\c.ico (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\m.ico (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\p.ico (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\s.ico (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\kamsoft.exe (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\m0vnonh.bat (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\olhrwef.exe (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\Documents and Settings\All Users\Application Data\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Administrateur\Favoris\SMS TRAP.url (Rogue.Link) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Administrateur\Menu Démarrer\SMS TRAP.url (Rogue.Link) -> Quarantined and deleted successfully.
        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\svchost.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Administrateur\Bureau\c-setup.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\WINDOWS\ios.dat (Malware.Trace) -> Quarantined and deleted successfully.
        0
        1. Contributeur sécurité
          Bonjour,

          vas supprimer tout ce qu'il y a dans la quarantaine de Malwarebytes et ensuite fais ceci stp :

          ▶ télécharge smitfraudfix et enregistre le sur le bureau

          ▶ Ensuite double clique sur smitfraudfix puis exécuter

          ▶ Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

          (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)

          ▶ copier/coller le rapport dans la réponse.

          Voici un tutoriel sonore et animé en cas de problème d'utilisation

          (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
          cet utilitaire pourrait arrêter des logiciels de sécurité.)
          0