SAHAGENT virus en sommeil

bonjour les amis (ies)

g windows xp pro sp1
avec ad _aware a jour :easy cleaner a jour :spy bot a jour et f- secure 2004 en antivirus
mais voila y a quelque temps g choper une saloperie impossible a viré g formater une bonne vingtaine de fois mais sans resultat
il ralentit ma connexion internet voir meme la paralise !!!!
le dernier anti trojan que g essayer c flow protector 2005 il me dit que c un virus en sommeil et il s appelle SAHAGENT NEUTRALISE PAR LE NAVIGATEUR WEB SECURISE ( generic malware )
je ne c plus quoi faire si vous avez l

3 réponses

  1. Salut...

    Cela pourrai peut etre t'aider

    Trouver sur le site FORUM ZEBULONFR

    Salut

    c'est un spyware qui se nomme Bundle.exe qui se créer dans les fichier temporaire
    c:\Documents and Settings\Ton compte\local settings\temp

    tu vas dans la base de registre, menu "demarrer =>executer : et tu tapes : regedit

    dans la fenetre de gauche, tu vas à la clé :
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    et dans la fenetre de droite tu supprimes la valeur:
    "SAHBundle"="%Temp%\bundle.exe"

    maintenant dans la fenetre de gauche , tu vas a la clé :
    HKEY_LOCAL_MACHINE\Software \VGroup
    et tu supprimes la clef

    apres
    tu passes un coup de
    Spybot
    http://www.safer-networking.org/index.php?...ng=fr&page=news
    un coup de HijackThis
    http://www.merijn.org/files/HijackThis.exe
    un coup de CWShredder
    http://www.merijn.org/files/CWShredder.exe
    un coup d'Anti-trojans
    http://clement.reinier.free.fr/modules.php...Anti_Trojan_5.5
    de A²
    http://www.emsisoft.net/fr/software/free/

    A verifier tout de meme

    Un bon Troyen est un Troyen M O R T
    0
    1. salut TEDDY BEAR

      MERCI pour ton aide mais ca ne marche pas il est toujour la
      ad awre me trouve
      SAHAGENT type LSP c:/windows/system 32/ISP.dll
      voila spy bot lui trouve :
      ELITUM ELITE BAR
      DYFUCA INTERNET.OPTIMIZER
      ISEARCHTECH.POWER SCAN
      ISEARCHTECH.SIDER FIND
      ISEARCHTECH.SLOTCH
      voila si quelqu un peux m aider !
      merci
      0
      1. re bonjour les z amies g toujour des soucis voila se que donne le scann de
        Logfile of HijackThis v1.99.0
        Scan saved at 21:37:07, on 15/01/2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\scguard.exe
        C:\WINDOWS\System32\trass.exe
        C:\WINDOWS\System32\ctfmon.exe
        C:\WINDOWS\System32\mpwe.exe
        C:\WINDOWS\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
        C:\Program Files\Wanadoo\EspaceWanadoo.exe
        C:\Program Files\Wanadoo\ComComp.exe
        C:\Program Files\Wanadoo\Watch.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\moi\Local Settings\Temporary Internet Files\Content.IE5\CD67CHY7\HijackThis[1].exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O4 - HKLM\..\Run: [Windows Media Player] mpwe.exe
        O4 - HKLM\..\Run: [MS Windows Update] scguard.exe
        O4 - HKLM\..\Run: [Admanager Controller] C:\Program Files\Admanager Controller\AdManCtl.exe
        O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
        O4 - HKLM\..\Run: [Microsoft Legacy Device] trass.exe
        O4 - HKLM\..\RunServices: [Windows Media Player] mpwe.exe aidez moi siouplait
        0