[trojan spm/lx]

Résolu
tristan_no Messages postés 10 Statut Membre -  
 mehditop -
Bonjour, depuis quelques jours je suis embêté par un trojan spm/lx.
Mon antivirus avast ne trouve aucune trace de ce trojan.
Que puis-faire?
Merci d'avance pour votre conseil!

24 réponses

aoshi Messages postés 73 Statut Membre
 
salut moi ossi j'ai les meme probleme .
Mon fond d'ecrant et tou bleu avec marquer :
WARNING
YOU'RE IN DANGER
YOU'R CONPUTER IS INFECTED WITH SPYWARE

qu'est se que je peux faire jai telechager spybot et ad-adware mais ils ne le detecte pas.
0
ben91
 
------- LOGFILE OF AD-REMOVER 1.1.4.2 | ONLY XP/VISTA -------

Updated By C_XX On 28/05/2009 At 18:40
Contact: AdRemover.contact@gmail.com
WebSite: http://pagesperso-orange.fr/NosTools/ad_remover.html

Started At: 2:43:46, 22/05/2009 | Normal boot
Executed From: C:\Program Files\Ad-remover\
Operating System: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Computer Name: VANG
Current User: Ben - Administrator

.
============== ELEMENTS REMOVED ==============
.
.
HKCR\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKCR\EoRezoBHO.EoBho
HKCR\EoRezoBHO.EoBho.1
HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKCU\Software\EoRezo
HKCU\Software\Grand Virtual
HKCU\Software\ItsLabel
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Dealio
HKLM\Software\ItsLabel
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
.
C:\Documents and Settings\Ben\Application Data\Dealio\dinstallhelper.F71D3323251C46F38151047DBA492AA0.dll
C:\Documents and Settings\Ben\Application Data\Dealio
C:\Documents and Settings\Ben\Application Data\EoRezo\cache
C:\Documents and Settings\Ben\Application Data\EoRezo\cmhost.cyp
C:\Documents and Settings\Ben\Application Data\EoRezo\ConfMedia.cyp
C:\Documents and Settings\Ben\Application Data\EoRezo\db
C:\Documents and Settings\Ben\Application Data\EoRezo\eoDesktop
C:\Documents and Settings\Ben\Application Data\EoRezo\eoStats
C:\Documents and Settings\Ben\Application Data\EoRezo\host.cyp
C:\Documents and Settings\Ben\Application Data\EoRezo\user.cyp
C:\Documents and Settings\Ben\Application Data\EoRezo\db\cat.cyp
C:\Documents and Settings\Ben\Application Data\EoRezo\eoDesktop\config.xml
C:\Documents and Settings\Ben\Application Data\EoRezo\eoDesktop\eoDesktop.html
C:\Documents and Settings\Ben\Application Data\EoRezo\eoDesktop\userConfig.xml
C:\Documents and Settings\Ben\Application Data\EoRezo\eoStats\eoStats.txt
C:\Documents and Settings\Ben\Application Data\EoRezo
C:\Documents and Settings\Ben\Application Data\ItsLabel\ItsTV
C:\Documents and Settings\Ben\Application Data\ItsLabel\ItsTV\itsTV.xml
C:\Documents and Settings\Ben\Application Data\ItsLabel

(!) -- Temp files deleted.

.
+-----------------| Added Scan:
.

---- Mozilla FireFox Version 3.0.10 ----

ProfilePath: 2a43xcqi.default (Ben)
.
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.lo.st");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.1");
(Invalidprefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Invalidprefs.js) user_pref("browser.startup.homepage", "hxxp://www.lo.st");
(Invalidprefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.1");
.
.

---- Internet Explorer Version 6.0.2900.5512 ----

[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://search.live.com
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/

[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp://ieframe.dll/tabswelcome.htm

=========== Suspect (Cracks, Serials ... ) ==========

.

+---------------------------------------------------------------------------+


19 File(s) - C:\Program Files\Ad-remover\BACKUP
12 File(s) - C:\Program Files\Ad-remover\QUARANTINE

End at: 2:51:10 | 22/05/2009
.
+-----------------| E.O.F
.
0
Destrio5 Messages postés 99820 Statut Modérateur 10 304
 
0
mehditop
 
ben je vous conseil Spyware doctor c'est efficace et sans toute ces étapes, il suffit juste un petit scan et réparation
Salut
0