[virus] infection trojan et ver - Page 2

Précédent
  • 1
  • 2
  1. Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 349
     
    Bonjour,

    Méthode à suivre dans l'ordre...
    ----------------------------------------------------------------------------
    ¤Télécharge ces logiciels si tu ne les as pas mais que tu n‘utilises pas tout de suite:

    1/

    Spybot S&D 1.4
    https://www.safer-networking.org/

    Démo d’utilisation (merci à Balltrap34 pour cette réalisation).
    http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

    2/

    Ad-Aware SE 1.06
    https://www.adaware.com/
    -Une aide:
    http://usa.lucretius-ada.com/zcvisitor/8782d344-4821-11ea-83ce-0a2cdf2c6be7?campaignid=0d1dff40-82d7-11e9-9533-0a157bfa6bfc
    - installe le patch français, tu pourras le trouver ici:
    http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
    et une petite vidéo d'utilisation ici:(merci à Moe31 pour cette réalisation).
    http://pageperso.aol.fr/balltrap34/adawrevid.asf

    3/ Ewido:

    http://perso.orange.fr/entraide-hijackthis/Ewido/

    Installation puis mises à jour.
    ----------------------------------------------------------------------------
    ¤Affiche tous les fichiers et dossiers :
    Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

    Coche « afficher les fichiers et dossiers cachés »

    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

    Décoche « masquer les extensions dont le type est connu »
    Puis fais «Ok» pour valider les changements.

    Et appliquer !
    ----------------------------------------------------------------------------
    ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

    O2 - BHO: (no name) - {849B9523-785F-4014-9CAF-079FB4A74C61} - (no file)

    O2 - BHO: (no name) - {A9BD3D21-6A56-47C3-874A-785A90D2E903} - C:\WINDOWS\system32\gebby.dll (file missing)

    O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - (no file)

    O20 - Winlogon Notify: winhuc32 - winhuc32.dll (file missing)

    ----------------------------------------------------------------------------
    ¤Démarre en mode sans échec :
    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
    (Si F8 ne marche pas utilise la touche F5).
    ----------------------------------------------------------------------------
    ¤ Lancer et exécuter Ewido pour un scan complet et copier/coller le rapport en forum.
    ----------------------------------------------------------------------------
    ¤ Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
    ----------------------------------------------------------------------------
    ¤ Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…
    --------------------------------------------------------------------------------------------------------------------------------------------------------
    ¤ Vide ta Corbeille.
    ----------------------------------------------------------------------------
    ¤ Redémarre en mode normal, relance Hijackthis et copie/colle un nouveau rapport sur le forum.

    Précise tes soucis s’il en reste....

    Tiens-moi au courant

    A+
    0
  2. supermezcal Messages postés 26 Statut Membre
     
    bon alors le rapport ewido :

    Created at: 00:47:49 12/10/2006

    + Scan result:

    C:\Program Files\Fichiers communs\{E89C368F-0958-1036-0819-030305130021}\services.dll -> Adware.Softomate : Cleaned.
    :mozilla.71:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
    :mozilla.72:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
    :mozilla.88:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.30:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.31:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.32:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.33:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.34:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.56:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.50:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.51:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.52:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.53:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.54:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.78:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.79:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.66:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
    :mozilla.70:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
    :mozilla.17:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.12:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.13:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.14:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.15:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.94:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.77:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
    :mozilla.48:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
    :mozilla.49:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
    :mozilla.18:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.19:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.20:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.21:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.26:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.27:C:\Documents and Settings\SpongeBob\Application Data\Mozilla\Firefox\Profiles\ox4juflt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.

    ::Report end

    et apres le hijackthis :

    Logfile of HijackThis v1.99.1
    Scan saved at 01:08:05, on 12/10/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\System32\WLTRAY.exe
    C:\Program Files\Microsoft Hardware\Mouse\point32.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\NavNT\vptray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\MSMSGS.EXE
    C:\Program Files\SuperCopier\SuperCopier.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\SpongeBob\Bureau\highjackthis\xxx.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
    O4 - HKLM\..\Run: [POINTER] point32.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [SuperCopier.exe] C:\Program Files\SuperCopier\SuperCopier.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    En tout cas j'ai l'impression de plus avoir de pb!!
    Alors un grand merci a tous ceux qui ont pris le temps de m'aider!

    Merci beaucoup c'est vraiment sympa.
    0
Précédent
  • 1
  • 2