Supprimer Spyware.SpyArsenalLog

Bonjour,
Je suis infecté par Spyware.SpyArsenalLog et je n'arrive pas à m'en débarrasser, auriez vous une solution?
En vous remerciant d'avance.

12 réponses

  1. Contributeur sécurité
    slt,

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. Bonsoir et merci de me repondre, voici les 2 rapports :

      log.txt :

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Sylvain&Gervaise at 2009-11-20 19:58:34
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 17 GB (44%) free of 38 GB
      Total RAM: 767 MB (38% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:58:41, on 20/11/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\DAEMON Tools Lite\daemon.exe
      C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Spyware Terminator\sp_rsser.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\wbem\wmiapsrv.exe
      C:\Program Files\Java\jre6\bin\jucheck.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Arovax AntiSpyware\arovaxantispyware.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
      C:\Documents and Settings\Sylvain&Gervaise\Bureau\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\Sylvain&Gervaise.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60341
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60341
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60341
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: iPhone OS 3 Toolbar - {74714D77-1695-4E73-A98E-25CB374F46B4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
      O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - (no file)
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - (no file)
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
      O3 - Toolbar: (no name) - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - (no file)
      O3 - Toolbar: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Service Google Update (gupdate1c9c9af77ab311c) (gupdate1c9c9af77ab311c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe
      O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
      0
      1. c'est arovax anti-spyware qui me trouve l'infection :

        Scan log. Started at 11.20.2009 20:41:32
        ------------------------------------------

        Start Processes scan
        Completed Processes scan
        Total items scanned: 46
        Items found: 0
        ------------------------------------------

        Start Registry scan
        Completed Registry scan
        Total items scanned: 25111
        Items found: 0
        ------------------------------------------

        Start Hosts file scan
        Completed Hosts file scan
        Total items scanned: 1
        Items found: 0
        ------------------------------------------

        Start Cookies scan
        Completed Cookies scan
        Total items scanned: 441
        Items found: 0
        ------------------------------------------

        Start File system scan
        Name: Spyware.SpyArsenalLog
        C:\WINDOWS\system32\CatRoot2\tmp.edb

        Completed File system scan
        Total items scanned: 5070
        Items found: 1
        ------------------------------------------

        Scanning Finished. 11.20.2009 20:54:44

        voici le rappport de malwarebyte :

        Malwarebytes' Anti-Malware 1.41
        Version de la base de données: 3181
        Windows 5.1.2600 Service Pack 3

        20/11/2009 21:04:18
        mbam-log-2009-11-20 (21-04-18).txt

        Type de recherche: Examen rapide
        Eléments examinés: 111738
        Temps écoulé: 16 minute(s), 22 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 0
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 0

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        (Aucun élément nuisible détecté)
        0
        1. il ne m'affiche pas de rapport, voilà ce que j'ai quand je fais analyser mon fichier :

          0 bytes size received / Se ha recibido un archivo vacio
          0
          1. Contributeur sécurité
            ok

            télécharge OTM
            http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/ (de Old_Timer) sur ton Bureau.

            double-clique sur OTM.exe pour le lancer.
            copie la liste qui se trouve en citation ci-dessous,
            et colle-la dans le cadre de gauche de OTM :Paste instruction for items to be moved.
            (attention bien mettre :files)

            :processes
            explorer.exe
            :files
            C:\WINDOWS\system32\CatRoot2\tmp.edb
            :commands
            [purity]
            [emptytemp]
            [start explorer]

            clique sur MoveIt! pour lancer la suppression.
            le résultat apparaitra dans le cadre "Results".
            clique sur Exit pour fermer.
            poste le rapport situé dans C:\_OTM\MovedFiles.

            il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
            0
            1. Bonjour, voici le rapport de OTM :

              All processes killed
              ========== PROCESSES ==========
              No active process named explorer.exe was found!
              ========== FILES ==========
              File move failed. C:\WINDOWS\system32\CatRoot2\tmp.edb scheduled to be moved on reboot.
              ========== COMMANDS ==========

              [EMPTYTEMP]

              User: Administrateur
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 32835 bytes

              User: Administrateur.MAISON
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 33170 bytes

              User: All Users

              User: Default User
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 67 bytes

              User: LocalService
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 33170 bytes

              User: NetworkService
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 67 bytes

              User: Sylvain&Gervaise
              ->Temp folder emptied: 381225 bytes
              ->Temporary Internet Files folder emptied: 181197499 bytes
              ->Java cache emptied: 13689500 bytes
              ->FireFox cache emptied: 9769216 bytes
              ->Apple Safari cache emptied: 108606 bytes

              %systemdrive% .tmp files removed: 0 bytes
              %systemroot% .tmp files removed: 1139202 bytes
              %systemroot%\System32 .tmp files removed: 29190874 bytes
              Windows Temp folder emptied: 2520 bytes
              %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
              %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 94404 bytes
              RecycleBin emptied: 0 bytes

              Total Files Cleaned = 224,75 mb

              OTM by OldTimer - Version 3.1.2.0 log created on 11232009_161558

              Files moved on Reboot...
              File move failed. C:\WINDOWS\system32\CatRoot2\tmp.edb scheduled to be moved on reboot.

              Registry entries deleted on Reboot...
              0
              1. Contributeur sécurité
                ok il est encore la?
                0
                1. Contributeur sécurité
                  télécharge combofix (par sUBs) ici :

                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                  et enregistre le sur le bureau.

                  déconnecte toi d'internet et ferme toutes tes applications.

                  désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                  double-clique sur combofix.exe et suis les instructions

                  à la fin, il va produire un rapport C:\ComboFix.txt

                  réactive ton parefeu, ton antivirus, la garde de ton antispyware

                  copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

                  Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                  Tu as un tutoriel complet ici :

                  https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                  0
                  1. Bonjour,
                    Je suis moi aussi infectée par Spyware.SpyArsenalLog mais sous XP , Avorax le trouve mais ne sais pas le supprimer définitivement, svp pouvez vous m'aider? Je vous en prie......
                    En vous remerciant d'avance.
                    0
                2. Contributeur sécurité
                  slt
                  colle un rapport avec RSIT pour voir
                  0