Cheval de troie (lollipop)

bat86 Messages postés 3 Statut Membre -  
kalimusic Messages postés 14619 Statut Contributeur sécurité -
Bonjour,

Voilà j'ai acheté un PC et je n'ai pas fait attention mon antivir de base n'était plus à jour : du coup bingo j'ai un cheval de Troie qui a infecté mon ordi : ralentissement du PC et pop-up envoyées en nombre malgré AdBlock.

J'ai fait un rapport d'analyse par Avira Antivir : je le poste ci-dessous

Quelqu'un peut il me conseiller sur la manière de s'en débarasser ? formater ? créer un point de restauration ? (sachant que mon ordi a un mois et que du coup je peux stocker mes données facilement sur un disque dur externe).

Merci d'avance pour votre aide.

Rapport :

Avira AntiVir Personal
Report file date: dimanche 30 septembre 2012 09:24

Scanning for 4286580 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - Free Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows 7 x64
Windows version : (Service Pack 1) [6.1.7601]
Boot mode : Normally booted
Username : Système
Computer name : BAPTISTE-PC

Version information:
BUILD.DAT : 10.2.0.707 36070 Bytes 25/01/2012 13:11:00
AVSCAN.EXE : 10.3.0.7 484008 Bytes 21/07/2011 10:12:28
AVSCAN.DLL : 10.0.5.0 47464 Bytes 21/07/2011 10:15:00
LUKE.DLL : 10.3.0.5 45416 Bytes 21/07/2011 10:13:59
LUKERES.DLL : 10.0.0.1 12648 Bytes 10/02/2010 22:40:49
AVSCPLR.DLL : 10.3.0.7 119656 Bytes 21/07/2011 10:12:28
AVREG.DLL : 10.3.0.9 90472 Bytes 21/07/2011 10:12:21
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 08:05:36
VBASE001.VDF : 7.11.0.0 13342208 Bytes 14/12/2010 05:53:55
VBASE002.VDF : 7.11.19.170 14374912 Bytes 20/12/2011 06:51:39
VBASE003.VDF : 7.11.21.238 4472832 Bytes 01/02/2012 06:52:16
VBASE004.VDF : 7.11.26.44 4329472 Bytes 28/03/2012 06:52:49
VBASE005.VDF : 7.11.34.116 4034048 Bytes 29/06/2012 06:53:18
VBASE006.VDF : 7.11.41.250 4902400 Bytes 06/09/2012 06:53:54
VBASE007.VDF : 7.11.41.251 2048 Bytes 06/09/2012 06:53:54
VBASE008.VDF : 7.11.41.252 2048 Bytes 06/09/2012 06:53:55
VBASE009.VDF : 7.11.41.253 2048 Bytes 06/09/2012 06:53:55
VBASE010.VDF : 7.11.41.254 2048 Bytes 06/09/2012 06:53:55
VBASE011.VDF : 7.11.41.255 2048 Bytes 06/09/2012 06:53:55
VBASE012.VDF : 7.11.42.0 2048 Bytes 06/09/2012 06:53:55
VBASE013.VDF : 7.11.42.1 2048 Bytes 06/09/2012 06:53:55
VBASE014.VDF : 7.11.42.65 203264 Bytes 09/09/2012 06:53:57
VBASE015.VDF : 7.11.42.125 156672 Bytes 11/09/2012 06:53:59
VBASE016.VDF : 7.11.42.171 187904 Bytes 12/09/2012 06:54:00
VBASE017.VDF : 7.11.42.235 141312 Bytes 13/09/2012 06:54:01
VBASE018.VDF : 7.11.43.35 133632 Bytes 15/09/2012 06:54:03
VBASE019.VDF : 7.11.43.89 129024 Bytes 18/09/2012 06:54:04
VBASE020.VDF : 7.11.43.141 130560 Bytes 19/09/2012 06:58:37
VBASE021.VDF : 7.11.43.187 121856 Bytes 21/09/2012 06:58:39
VBASE022.VDF : 7.11.43.251 147456 Bytes 24/09/2012 12:38:06
VBASE023.VDF : 7.11.44.43 152064 Bytes 25/09/2012 12:38:08
VBASE024.VDF : 7.11.44.103 165888 Bytes 27/09/2012 15:45:03
VBASE025.VDF : 7.11.44.104 2048 Bytes 27/09/2012 15:45:03
VBASE026.VDF : 7.11.44.105 2048 Bytes 27/09/2012 15:45:03
VBASE027.VDF : 7.11.44.106 2048 Bytes 27/09/2012 15:45:03
VBASE028.VDF : 7.11.44.107 2048 Bytes 27/09/2012 15:45:03
VBASE029.VDF : 7.11.44.108 2048 Bytes 27/09/2012 15:45:03
VBASE030.VDF : 7.11.44.109 2048 Bytes 27/09/2012 15:45:03
VBASE031.VDF : 7.11.44.160 150016 Bytes 29/09/2012 07:08:59
Engineversion : 8.2.10.178
AEVDF.DLL : 8.1.2.10 102772 Bytes 19/09/2012 06:54:40
AESCRIPT.DLL : 8.1.4.58 463226 Bytes 30/09/2012 07:10:15
AESCN.DLL : 8.1.9.2 131444 Bytes 27/09/2012 15:45:09
AESBX.DLL : 8.2.5.12 606578 Bytes 19/09/2012 06:54:42
AERDL.DLL : 8.1.9.15 639348 Bytes 19/09/2012 06:54:38
AEPACK.DLL : 8.3.0.38 811382 Bytes 30/09/2012 07:10:13
AEOFFICE.DLL : 8.1.2.48 201082 Bytes 26/09/2012 12:38:35
AEHEUR.DLL : 8.1.4.108 5329272 Bytes 30/09/2012 07:10:02
AEHELP.DLL : 8.1.24.0 258423 Bytes 27/09/2012 15:45:08
AEGEN.DLL : 8.1.5.38 434548 Bytes 27/09/2012 15:45:07
AEEXP.DLL : 8.2.0.2 115060 Bytes 27/09/2012 15:45:10
AEEMU.DLL : 8.1.3.2 393587 Bytes 19/09/2012 06:54:10
AECORE.DLL : 8.1.28.2 201079 Bytes 27/09/2012 15:45:04
AEBB.DLL : 8.1.1.0 53618 Bytes 21/04/2011 05:53:14
AVWINLL.DLL : 10.0.0.0 19304 Bytes 21/04/2011 05:53:36
AVPREF.DLL : 10.0.3.2 44904 Bytes 21/07/2011 10:12:20
AVREP.DLL : 10.0.0.10 174120 Bytes 21/07/2011 10:12:22
AVARKT.DLL : 10.0.26.1 255336 Bytes 21/07/2011 10:12:00
AVEVTLOG.DLL : 10.0.0.9 203112 Bytes 21/07/2011 10:12:10
SQLITE3.DLL : 3.6.19.0 355688 Bytes 21/07/2011 13:12:31
AVSMTP.DLL : 10.0.0.17 63848 Bytes 21/04/2011 05:53:36
NETNT.DLL : 10.0.0.0 11624 Bytes 21/04/2011 05:53:46
RCIMAGE.DLL : 10.0.0.35 2589544 Bytes 21/07/2011 10:15:09
RCTEXT.DLL : 10.0.64.0 97640 Bytes 21/07/2011 10:15:09

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: C:\program files (x86)\avira\antivir desktop\sysscan.avp
Logging.............................: Default
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:, Q:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: Advanced

Start of the scan: dimanche 30 septembre 2012 09:24

Starting search for hidden objects.
Error in ARK library

The scan of running processes will be started
Scan process 'avscan.exe' - '74' Module(s) have been scanned
Scan process 'avscan.exe' - '37' Module(s) have been scanned
Scan process 'chrome.exe' - '47' Module(s) have been scanned
Scan process 'chrome.exe' - '47' Module(s) have been scanned
Scan process 'chrome.exe' - '47' Module(s) have been scanned
Scan process 'avcenter.exe' - '85' Module(s) have been scanned
Scan process 'UNS.exe' - '64' Module(s) have been scanned
Scan process 'daemonu.exe' - '79' Module(s) have been scanned
Scan process 'LMS.exe' - '37' Module(s) have been scanned
Scan process 'chrome.exe' - '44' Module(s) have been scanned
Scan process 'chrome.exe' - '47' Module(s) have been scanned
Scan process 'SyncServer.exe' - '66' Module(s) have been scanned
Scan process 'ATH.exe' - '76' Module(s) have been scanned
Scan process 'chrome.exe' - '47' Module(s) have been scanned
Scan process 'chrome.exe' - '47' Module(s) have been scanned
Scan process 'chrome.exe' - '70' Module(s) have been scanned
Scan process 'distnoted.exe' - '41' Module(s) have been scanned
Scan process 'chrome.exe' - '111' Module(s) have been scanned
Scan process 'AppleMobileDeviceHelper.exe' - '78' Module(s) have been scanned
Scan process 'hpqgpc01.exe' - '56' Module(s) have been scanned
Scan process 'iTunes.exe' - '161' Module(s) have been scanned
Scan process 'hpqbam08.exe' - '41' Module(s) have been scanned
Scan process 'hpqSTE08.exe' - '70' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '79' Module(s) have been scanned
Scan process 'avgnt.exe' - '79' Module(s) have been scanned
Scan process 'HControlUser.exe' - '30' Module(s) have been scanned
Scan process 'DMedia.exe' - '36' Module(s) have been scanned
Scan process 'hpwuschd2.exe' - '30' Module(s) have been scanned
Scan process 'SweetPacksUpdateManager.exe' - '56' Module(s) have been scanned
Scan process 'SweetIM.exe' - '69' Module(s) have been scanned
Scan process 'ACEngSvr.exe' - '43' Module(s) have been scanned
Scan process 'CLMLSvc.exe' - '44' Module(s) have been scanned
Scan process 'AsScrPro.exe' - '38' Module(s) have been scanned
Scan process 'wcourier.exe' - '64' Module(s) have been scanned
Scan process 'ACMON.exe' - '53' Module(s) have been scanned
Scan process 'iusb3mon.exe' - '40' Module(s) have been scanned
Scan process 'hpqtra08.exe' - '81' Module(s) have been scanned
Scan process 'BTPlayerCtrl.exe' - '41' Module(s) have been scanned
Scan process 'lkonsro.exe' - '109' Module(s) have been scanned
Scan process 'MusicManager.exe' - '71' Module(s) have been scanned
Scan process 'mediasrv.exe' - '44' Module(s) have been scanned
Scan process 'WDC.exe' - '35' Module(s) have been scanned
Scan process 'ATKOSD2.exe' - '44' Module(s) have been scanned
Scan process 'TabTip32.exe' - '27' Module(s) have been scanned
Scan process 'sensorsrv.exe' - '35' Module(s) have been scanned
Scan process 'KBFiltr.exe' - '28' Module(s) have been scanned
Scan process 'ATKOSD.exe' - '28' Module(s) have been scanned
Scan process 'USBChargerPlus.exe' - '42' Module(s) have been scanned
Scan process 'QuickGesture.exe' - '35' Module(s) have been scanned
Scan process 'browsemngr.exe' - '33' Module(s) have been scanned
Scan process 'InsOnWMI.exe' - '50' Module(s) have been scanned
Scan process 'HControl.exe' - '44' Module(s) have been scanned
Scan process 'CVHSVC.EXE' - '81' Module(s) have been scanned
Scan process 'sftlist.exe' - '67' Module(s) have been scanned
Scan process 'obexsrv.exe' - '43' Module(s) have been scanned
Scan process 'sftvsa.exe' - '34' Module(s) have been scanned
Scan process 'jhi_service.exe' - '46' Module(s) have been scanned
Scan process 'IntelMeFWService.exe' - '32' Module(s) have been scanned
Scan process 'svchost.exe' - '52' Module(s) have been scanned
Scan process 'browsemngr.exe' - '32' Module(s) have been scanned
Scan process 'devmonsrv.exe' - '42' Module(s) have been scanned
Scan process 'InsOnSrv.exe' - '40' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '74' Module(s) have been scanned
Scan process 'avguard.exe' - '75' Module(s) have been scanned
Scan process 'armsvc.exe' - '30' Module(s) have been scanned
Scan process 'sched.exe' - '55' Module(s) have been scanned
Scan process 'GFNEXSrv.exe' - '10' Module(s) have been scanned
Scan process 'ASLDRSrv.exe' - '15' Module(s) have been scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'Q:\'
[INFO] No virus was found!
[INFO] Please restart the search with Administrator rights

Starting to scan executable files (registry).
The registry was scanned ( '227' files ).

Starting the file scan:

Begin scan in 'C:\' <OS>
C:\Users\Baptiste\AppData\Local\Temp\LollipopInstaller.exe
[DETECTION] Is the TR/Rogue.KD.722183 Trojan
Begin scan in 'D:\' <DATA>
Begin scan in 'Q:\'
Search path Q:\ could not be opened!
System error [5]: Accès refusé.

Beginning disinfection:
C:\Users\Baptiste\AppData\Local\Temp\LollipopInstaller.exe
[DETECTION] Is the TR/Rogue.KD.722183 Trojan
[NOTE] The file was moved to the quarantine directory under the name '56e9b0aa.qua'.

End of the scan: dimanche 30 septembre 2012 11:34
Used time: 45:57 Minute(s)

The scan has been done completely.

30577 Scanned directories
620731 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
620730 Files not concerned
4769 Archives were scanned
0 Warnings
1 Notes
145 Objects were scanned with rootkit scan
0 Hidden objects were found

4 réponses

kalimusic Messages postés 14619 Statut Contributeur sécurité 3 027
 
Bonjour,

C'est juste l'installateur d'un adware, tu l'as installé ?

A +
0
sawpas Messages postés 841 Date d'inscription   Statut Membre Dernière intervention   416
 
Selon le rapport, Avira a apparement resolu le problème...

The scan has been done completely.

30577 Scanned directories
620731 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
620730 Files not concerned
4769 Archives were scanned
0 Warnings
0
bat86 Messages postés 3 Statut Membre
 
Malgré cela, le virus persiste...
J'ai aussi lancé "spybot research and destroy" et toujours infecté...

que faire d'autre ?
0
kalimusic Messages postés 14619 Statut Contributeur sécurité 3 027
 
bat86,

C'est normal Avira a seulement mis l'installeur de l'adware en quarantaine.
D'où ma question ;)

1. Désinstalle Spybot S&D, logiciel obsolète et qui risque de gêner la désinfection :

Désactive le module Tea Timer
● Dé-vaccine
● Désinstalle

2. Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.
● Lance AdwCleaner
- Sous XP double-clic sur l'icône pour lancer l'outil.
- Sous Vista/Seven clic-droit sur l'icône et choisir "Exécuter en tant qu'administrateur" dans le menu contextuel.
▸ Si tu souhaite conserver la barre d'outil Avira search free toolbar
▸ Clique sur le point d'interrogation ? et coche la case /DisableAskDetection
Ferme impérativement le navigateur ainsi que les applications en cours.
● Clique sur Suppression
● Patiente le temps du scan, accepte de redémarrer si l'outil le demande
● Le rapport doit s'ouvrir spontanément.

Le rapport est sauvegardé à la racine du disque C:\AdwCleaner[S1].txt

Poste le rapport, A +
0