Suprimer malware defender 2009

Bonjour, je suis infecté par malware defender 2009 c'est infernal. j'ai telecharger hjackthis, voici le rapport:

ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:06:34, on 18/12/2009
Platform: Windows XP SP3, v.5512 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20861)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VistaDriveIcon\DrvIcon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\richtx64.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\clspackxq.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wscsvc32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [DrvIcon] C:\Program Files\VistaDriveIcon\DrvIcon.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [richtx64.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\richtx64.exe
O4 - HKCU\..\Run: [clspackxq.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\clspackxq.exe
O4 - HKCU\..\Run: [Malware Defense] "C:\Program Files\Malware Defense\mdefense.exe" -noscan
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {91D4B4D5-E368-40AB-8F53-A37FA634B471} (Installer9Ctrl Class) - http://www5.tellmemorecampus.com/bin/tol9inst.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

--
End of file - 4743 bytes

que doi-je faire merci d'avance!
Configuration: Windows XP Internet Explorer 7.0

5 réponses

  1. Contributeur
    Ok, vide la quarantaine de Malwarebytes --> onglet quarantaine et supprime tout.
    Important --> redémarre le pc.

    Ensuite,

    Telecharges RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

    - Fermes toutes les applications en cours et double clic sur RSIT.exe
    - Selectionnes " Continue " à l'ecran >> RSIT va analyser le pc et verifier si l'outil hijackthis ( version à jour) est present sur le pc, si ce n'est pas le cas, RSIT le telechargera >> acceptes la license
    - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent, log.txt à l'écran et info.txt dans la barre des taches
    - Postes le contenu des 2 rapports
    1
    1. Contributeur
      Salut,

      Télécharge et installe ccleaner : https://filehippo.com/download_ccleaner/
      - Durant l'installation, décoche la case proposant la barre d'outils yahoo et décoche la case " ajouter l'option des mises à jour"

      - Une fois installé, fermes toutes les applications en cours et lance ccleaner
      - clic >> option >> avancé et decoches " effacer les fichiers etc... plus vieux que 24h
      - Sélectionne " nettoyeur " >> clic sur Analyse puis nettoyage, puis referme le programme...

      -----------------------------
      - Télécharge Malwarebytes' Anti-Malware :
      http://www.malwarebytes.org/mbam/program/mbam-setup.exe

      - Installe le > double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour
      - Une fois installé, fermes toutes les applications en cours et lances Malwarebytes
      - Exécutes un examen rapide du pc ( tu n'auras pas accés à internet pendant l'analyse)
      - A la fin du scan clic sur " Afficher les résultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la sélection "
      - Si il a besoin de redémarrer le pc pour finir la désinfection, acceptes
      - Un rapport s'établira, postes son contenu.

      -----------------------------
      0
      1. Malwarebytes' Anti-Malware 1.42
        Version de la base de données: 3385
        Windows 5.1.2600 Service Pack 3, v.5512
        Internet Explorer 7.0.5730.13

        18/12/2009 17:40:25
        mbam-log-2009-12-18 (17-40-25).txt

        Type de recherche: Examen rapide
        Eléments examinés: 99120
        Temps écoulé: 6 minute(s), 9 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 1
        Valeur(s) du Registre infectée(s): 3
        Elément(s) de données du Registre infecté(s): 1
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 3

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\forceclassiccontrolpanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\richtx64.exe (Trojan.Agent) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\clspackxq.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

        Elément(s) de données du Registre infecté(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        C:\Documents and Settings\Administrateur\Local Settings\Temp\richtx64.exe (Rogue.Installer) -> Delete on reboot.
        C:\Documents and Settings\Administrateur\Local Settings\Temp\clspackxq.exe (Rogue.Installer) -> Delete on reboot.
        C:\Documents and Settings\Administrateur\Local Settings\Temp\wscsvc32.exe (Trojan.FakeAlert) -> Delete on reboot.
        0
        1. info.txt logfile of random's system information tool 1.06 2009-12-18 18:06:31

          ======Uninstall list======

          Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Reader 9.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
          Age of Mythology - The Titans Expansion-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTXP.EXE" /runtemp /addremove
          Age of Mythology-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTAL.EXE" /runtemp /addremove
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
          Camera RAW Plug-In for EPSON Creativity Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}\SETUP.EXE" -l0x40c UNINST
          CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
          CX4300_5500_DX4400 Manuel-->C:\Program Files\EPSON\TPMANUAL\CX4300_5500_DX4400\FRA\USE_G\DOCUNINS.EXE
          EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
          EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
          EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}\SETUP.EXE" -l0x40c UNINST
          EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}\Setup.exe" -l0x40c UNINST
          EPSON Logiciel imprimante-->C:\WINDOWS\system32\spool\DRIVERS\W32X86\EPUPDATE.EXE /r
          EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
          EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
          EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
          Ext2Ifs-->"C:\WINDOWS\System32\UnIfs.exe"
          FastStone-->"C:\Program Files\FastStone Capture\Désinstaller.exe"
          GeekBox-->"C:\Program Files\GeekBox\Désinstaller.exe"
          HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
          Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
          Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
          Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
          Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
          SpyHunter-->"C:\Program Files\Enigma Software Group\SpyHunter\Uninstall.exe" "C:\Program Files\Enigma Software Group\SpyHunter\install.log" -u
          Unlocker 1.8.7-->C:\Program Files\Unlocker\uninst.exe
          VistaDriveIcon-->"C:\Program Files\VistaDriveIcon\Désinstaller.exe"
          WiFi Station-->C:\Program Files\InstallShield Installation Information\{DECE22F4-EEDD-4615-BC56-2F4827FAD64B}\setup.exe -runfromtemp -l0x040c -removeonly
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
          Windows Trust Installer-->"C:\Program Files\WTInstaller\Désinstaller.exe"
          WinRAR-->"C:\Program Files\WinRAR\uninstall.exe"

          ======Hosts File======

          127.0.0.1 localhost
          127.0.0.1 mpa.one.microsoft.com

          Securitycenter WMI appears to be broken

          ======System event log======

          Computer Name: 7830F82812F0484
          Event Code: 7036
          Message: Le service Connexions réseau est entré dans l'état : en cours d'exécution.

          Record Number: 3252
          Source Name: Service Control Manager
          Time Written: 20091018101942.000000+120
          Event Type: Informations
          User:

          Computer Name: 7830F82812F0484
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service aswRdr.

          Record Number: 3251
          Source Name: Service Control Manager
          Time Written: 20091018101942.000000+120
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: 7830F82812F0484
          Event Code: 7036
          Message: Le service avast! Mail Scanner est entré dans l'état : en cours d'exécution.

          Record Number: 3250
          Source Name: Service Control Manager
          Time Written: 20091018101942.000000+120
          Event Type: Informations
          User:

          Computer Name: 7830F82812F0484
          Event Code: 7036
          Message: Le service avast! Web Scanner est entré dans l'état : en cours d'exécution.

          Record Number: 3249
          Source Name: Service Control Manager
          Time Written: 20091018101942.000000+120
          Event Type: Informations
          User:

          Computer Name: 7830F82812F0484
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service Connexions réseau.

          Record Number: 3248
          Source Name: Service Control Manager
          Time Written: 20091018101942.000000+120
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          =====Application event log=====

          Computer Name: 7830F82812F0484
          Event Code: 1000
          Message: Les compteurs de performances pour le service MSDTC (MSDTC) ont été chargés.
          Les données d'enregistrement contiennent les nouvelles valeurs d'index
          assignées à ce service.

          Record Number: 5
          Source Name: LoadPerf
          Time Written: 20090821153230.000000+120
          Event Type: Informations
          User:

          Computer Name: 7830F82812F0484
          Event Code: 1000
          Message: Les compteurs de performances pour le service TermService (Services Terminal Server) ont été chargés.
          Les données d'enregistrement contiennent les nouvelles valeurs d'index
          assignées à ce service.

          Record Number: 4
          Source Name: LoadPerf
          Time Written: 20090821153222.000000+120
          Event Type: Informations
          User:

          Computer Name: 7830F82812F0484
          Event Code: 1000
          Message: Les compteurs de performances pour le service RemoteAccess (Routage et accès distant) ont été chargés.
          Les données d'enregistrement contiennent les nouvelles valeurs d'index
          assignées à ce service.

          Record Number: 3
          Source Name: LoadPerf
          Time Written: 20090821152926.000000+120
          Event Type: Informations
          User:

          Computer Name: 7830F82812F0484
          Event Code: 1000
          Message: Les compteurs de performances pour le service PSched (PSched) ont été chargés.
          Les données d'enregistrement contiennent les nouvelles valeurs d'index
          assignées à ce service.

          Record Number: 2
          Source Name: LoadPerf
          Time Written: 20090821152859.000000+120
          Event Type: Informations
          User:

          Computer Name: 7830F82812F0484
          Event Code: 1000
          Message: Les compteurs de performances pour le service RSVP (QoS RSVP) ont été chargés.
          Les données d'enregistrement contiennent les nouvelles valeurs d'index
          assignées à ce service.

          Record Number: 1
          Source Name: LoadPerf
          Time Written: 20090821152845.000000+120
          Event Type: Informations
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 3 Stepping 1, AuthenticAMD
          "PROCESSOR_REVISION"=0301
          "NUMBER_OF_PROCESSORS"=1
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP

          -----------------EOF-----------------
          0
          1. Contributeur
            Re,

            Windows Trust Installer , il s'agit dune version piratée de windows, ces versions sont pour la plupart du temps infectée dès l'installation...

            Un peu de lecture :
            https://www.commentcamarche.net/faq/2981-j-utilise-une-version-piratee-de-windows

            https://www.commentcamarche.net/faq/4550-windows-legaliser-windows

            -------------------
            0