SAHAGENT virus en sommeil

tete doeuf -  
 tete d oeuf -
bonjour les amis (ies)

g windows xp pro sp1
avec ad _aware a jour :easy cleaner a jour :spy bot a jour et f- secure 2004 en antivirus
mais voila y a quelque temps g choper une saloperie impossible a viré g formater une bonne vingtaine de fois mais sans resultat
il ralentit ma connexion internet voir meme la paralise !!!!
le dernier anti trojan que g essayer c flow protector 2005 il me dit que c un virus en sommeil et il s appelle SAHAGENT NEUTRALISE PAR LE NAVIGATEUR WEB SECURISE ( generic malware )
je ne c plus quoi faire si vous avez l

3 réponses

  1. Teddy-Bear Messages postés 759 Statut Membre 91
     
    Salut...

    Cela pourrai peut etre t'aider

    Trouver sur le site FORUM ZEBULONFR

    Salut

    c'est un spyware qui se nomme Bundle.exe qui se créer dans les fichier temporaire
    c:\Documents and Settings\Ton compte\local settings\temp

    tu vas dans la base de registre, menu "demarrer =>executer : et tu tapes : regedit

    dans la fenetre de gauche, tu vas à la clé :
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    et dans la fenetre de droite tu supprimes la valeur:
    "SAHBundle"="%Temp%\bundle.exe"

    maintenant dans la fenetre de gauche , tu vas a la clé :
    HKEY_LOCAL_MACHINE\Software \VGroup
    et tu supprimes la clef

    apres
    tu passes un coup de
    Spybot
    http://www.safer-networking.org/index.php?...ng=fr&page=news
    un coup de HijackThis
    http://www.merijn.org/files/HijackThis.exe
    un coup de CWShredder
    http://www.merijn.org/files/CWShredder.exe
    un coup d'Anti-trojans
    http://clement.reinier.free.fr/modules.php...Anti_Trojan_5.5
    de A²
    http://www.emsisoft.net/fr/software/free/

    A verifier tout de meme

    Un bon Troyen est un Troyen M O R T
    0
  2. tete doeuf
     
    salut TEDDY BEAR

    MERCI pour ton aide mais ca ne marche pas il est toujour la
    ad awre me trouve
    SAHAGENT type LSP c:/windows/system 32/ISP.dll
    voila spy bot lui trouve :
    ELITUM ELITE BAR
    DYFUCA INTERNET.OPTIMIZER
    ISEARCHTECH.POWER SCAN
    ISEARCHTECH.SIDER FIND
    ISEARCHTECH.SLOTCH
    voila si quelqu un peux m aider !
    merci
    0
  3. tete d oeuf
     
    re bonjour les z amies g toujour des soucis voila se que donne le scann de
    Logfile of HijackThis v1.99.0
    Scan saved at 21:37:07, on 15/01/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\scguard.exe
    C:\WINDOWS\System32\trass.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\WINDOWS\System32\mpwe.exe
    C:\WINDOWS\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    C:\Program Files\Wanadoo\EspaceWanadoo.exe
    C:\Program Files\Wanadoo\ComComp.exe
    C:\Program Files\Wanadoo\Watch.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\moi\Local Settings\Temporary Internet Files\Content.IE5\CD67CHY7\HijackThis[1].exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [Windows Media Player] mpwe.exe
    O4 - HKLM\..\Run: [MS Windows Update] scguard.exe
    O4 - HKLM\..\Run: [Admanager Controller] C:\Program Files\Admanager Controller\AdManCtl.exe
    O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
    O4 - HKLM\..\Run: [Microsoft Legacy Device] trass.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] mpwe.exe aidez moi siouplait
    0