[cheval de troie] Downloader.Generic4.VOL

bonsoir tout le monde j'ai un problème je suis infecté par un cheval de troie qui m'a été détecté par AVG 7.5 sous le nom de "Downloader.Generic4.VOL"
son chemin d'accés=>C:\winssh.exe ---fichier =>winssh.exe
chemin d'accès =>C:\Documents and Settings\Local Service\Local Settings\Tempory Internet Files\Content.IE5\U90POLWF\raser[1].htm
quand je veu me connecté a msn je n'est plus aucun controle
est-ce que quelqu'un pourrais m'aider SVP??
merci d'avance
Configuration: Windows XP
AOL 9.0

7 réponses

  1. Bonjour

    Fais ces deux choses

    ¤ Fais ce nettoyage: à faire réguliérement

    *Télécharge et installe CCleaner (n'installe pas la barre d'outil Yahoo)
    ---> http://www.infos-du-net.com/telecharger/CCleaner,0301-1039.html

    - Dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis clic en bas sur "chercher des erreurs" une fois terminé, clic sur "reparer les erreurs" et tu auras un message pour sauvegarder ta base de registre tu clic "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
    Les sauvegardes que tu aura faites, tu pourras les supprimer si ton ordinateur n'a plus de problémes.

    - Relance Ccleaner, vas dans l'onglet "nettoyeur" présent sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"

    Si tu as besoin d'aide avec Ccleaner, regarde ce tutoriel :
    http://redir.fr/gmll

    ¤ Télécharge ComboFix sur ton bureau
    ---> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    Ferme ton navigateur web avant d'exécuter ce programme
    Double-clic dessus et appuye sur "1" pour continuer
    Attends quelques minutes..
    Un rapport va s'ouvrir enregistre son contenu, puis copie et colle le ici .

    PS : il se peut qu'il y est un autre rapport colle son contenu ici aussi.
    0
    1. "HP_Propri‚taire" - 2007-07-05 11:01:36 - ComboFix 07-07-04.4 - Service Pack 2

      ((((((((((((((((((((((((( Files Created from 2007-06-05 to 2007-07-05 )))))))))))))))))))))))))))))))

      2007-07-05 11:01 51,200 --a------ C:\WINDOWS\nircmd.exe
      2007-07-05 10:40 <REP> d-------- C:\Program Files\CCleaner
      2007-07-05 02:48 209,533 --a------ C:\winsfr.exe
      2007-07-03 19:27 200 --a------ C:\winbbs.exe
      2007-06-10 21:48 <REP> d-------- C:\Program Files\Lavasoft
      2007-06-10 21:48 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\Lavasoft
      2007-06-06 22:01 <REP> d-------- C:\Program Files\SmartFTP Client
      2007-06-06 22:01 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\SmartFTP

      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

      2007-07-05 07:20:39 -------- d-----w C:\DOCUME~1\HP_PRO~1\APPLIC~1\DMCache
      2007-07-04 12:45:22 -------- d-----w C:\Program Files\eMule
      2007-06-28 20:33:03 -------- d-----w C:\Program Files\AOL 9.0
      2007-06-16 20:09:44 50,856 ----a-w C:\DOCUME~1\HP_PRO~1\APPLIC~1\GDIPFONTCACHEV1.DAT
      2007-05-20 21:21:06 -------- d-----w C:\DOCUME~1\HP_PRO~1\APPLIC~1\IDM
      2007-05-20 12:22:13 -------- d-----w C:\Program Files\VirtualDJ
      2007-05-20 09:18:48 -------- d-----w C:\Program Files\Internet Download Manager
      2007-05-16 15:13:53 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
      2007-04-25 14:22:35 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
      2007-04-21 09:17:25 9,216 ----a-w C:\WINDOWS\system32\avgwlntf.dll
      2007-04-21 09:17:25 110,592 ----a-w C:\WINDOWS\system32\avgfwafu.dll
      2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
      2007-04-17 14:58:05 2,404 ----a-w C:\DOCUME~1\HP_PRO~1\APPLIC~1\wklnhst.dat
      2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
      2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
      2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
      2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
      2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
      2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
      2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
      2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

      *Note* empty entries & legit default entries are not shown

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
      2007-02-19 16:53 79544 --a------ C:\Program Files\Internet Download Manager\IDMIECC.dll

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
      2006-12-18 04:16 59032 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      2006-07-07 13:29 324416 --a------ C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
      2004-08-13 18:42 155648 --a------ C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
      2007-01-20 00:56 2436160 -ra------ c:\program files\google\googletoolbar3.dll

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      2007-06-18 21:45 325048 --a------ C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
      2006-01-17 17:04 282624 --a------ C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "RTHDCPL"="RTHDCPL.EXE" [2006-03-08 13:54 C:\WINDOWS\RTHDCPL.EXE]
      "nwiz"="nwiz.exe" [2006-01-25 04:15 C:\WINDOWS\system32\nwiz.exe]
      "HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 08:35]
      "PCMService"="C:\Program Files\CyberLink\PowerCinema\PCMService.exe" [2006-02-25 03:46]
      "HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 23:34]
      "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41]
      "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-01-03 03:15]
      "AOLSAV"="C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe" [2004-04-26 18:40]
      "AOLDialer"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe" [2006-11-17 13:41]
      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-11-06 19:00]
      "HostManager"="C:\Program Files\Fichiers communs\AOL\1168204254\ee\AOLSoftware.exe" [2006-11-17 15:16]
      "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-04-21 11:17]

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-07-29 20:34]
      "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 21:45]
      "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 12:48]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
      avgwlntf.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      Usnsvc usnsvc

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{983a3932-668c-11db-afb8-0016178841af}]
      AutoRun\command- K:\Autorun.exe

      **************************************************************************

      catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
      Rootkit scan 2007-07-05 11:03:24
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      AOLSAV = C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe?exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************

      Completion time: 2007-07-05 11:04:13

      --- E O F ---
      0
      1. voila g fais comme tu m'avais dis g telecharger Cclean et j'ai fais la procédure voila a la fin g eu se rapport
        je vais vérifier si j'ai encore quelque chose et je t'en fais par
        merci beaucoup pour ton aide
        0
        1. Rends toi sur se site
          http://www.virustotal.com/en/virustotalx.html

          En haut à droite clic sur "choisir"
          Tu vas dans C:, tu cherches le processus ci-dessous et tu clic sur "ouvrir"

          C:\winsfr.exe

          dès que c'est fait, clic sur "send"
          Tu attends un peu qu'il analyse ton fichier ça peut duré plusieurs minutes et colle le rapport ici une fois qu'il a terminé stp

          Fais la même chose avec celui-ci

          C:\winbbs.exe

          ET

          Fais ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
          Une fois qu'il a terminé colle le rapport ici stp

          https://www.bitdefender.com/toolbox/
          0
          1. Complete scanning result of "winsfr.exe", received in VirusTotal at 07.05.2007, 18:13:34 (CET).

            Antivirus Version Update Result
            AhnLab-V3 2007.7.5.0 07.05.2007 no virus found
            AntiVir 7.4.0.37 07.05.2007 no virus found
            Authentium 4.93.8 07.04.2007 no virus found
            Avast 4.7.997.0 07.04.2007 no virus found
            AVG 7.5.0.476 07.05.2007 no virus found
            BitDefender 7.2 07.05.2007 Trojan.Virtumod.IZ
            CAT-QuickHeal 9.00 07.05.2007 TrojanDownloader.AutoIt.g
            ClamAV devel-20070416 07.05.2007 no virus found
            DrWeb 4.33 07.05.2007 no virus found
            eSafe 7.0.15.0 07.05.2007 suspicious Trojan/Worm
            eTrust-Vet 30.8.3765 07.05.2007 no virus found
            Ewido 4.0 07.05.2007 no virus found
            FileAdvisor 1 07.05.2007 no virus found
            Fortinet 2.91.0.0 07.05.2007 no virus found
            F-Prot 4.3.2.48 07.04.2007 no virus found
            F-Secure 6.70.13260.0 07.05.2007 IM-Worm.Win32.Agent.d
            Ikarus T3.1.1.8 07.05.2007 Trojan-Downloader.Win32.Banload.ams
            Kaspersky 4.0.2.24 07.05.2007 IM-Worm.Win32.Agent.d
            McAfee 5068 07.05.2007 no virus found
            Microsoft 1.2701 07.05.2007 no virus found
            NOD32v2 2379 07.04.2007 no virus found
            Norman 5.80.02 07.05.2007 no virus found
            Panda 9.0.0.4 07.05.2007 no virus found
            Sophos 4.19.0 06.24.2007 no virus found
            Sunbelt 2.2.907.0 07.04.2007 no virus found
            Symantec 10 07.05.2007 no virus found
            TheHacker 6.1.6.142 07.04.2007 no virus found
            VBA32 3.12.0.2 07.05.2007 no virus found
            VirusBuster 4.3.23:9 07.05.2007 no virus found
            Webwasher-Gateway 6.0.1 07.05.2007 Worm.Win32.ModifiedUPX.gen!90 (suspicious)

            Aditional Information
            File size: 209533 bytes
            MD5: 15945e3b68982f7c2687bd59aefbed5d
            SHA1: 65a2a046d8391f1a92e168070e048232b0e31a6c
            packers: UPX
            packers: UPX
            packers: UPX
            0
            1. Complete scanning result of "winbbs.exe", received in VirusTotal at 07.05.2007, 18:25:41 (CET).

              Antivirus Version Update Result
              AhnLab-V3 2007.7.5.0 07.05.2007 no virus found
              AntiVir 7.4.0.39 07.05.2007 no virus found
              Authentium 4.93.8 07.04.2007 no virus found
              Avast 4.7.997.0 07.04.2007 no virus found
              AVG 7.5.0.476 07.05.2007 no virus found
              BitDefender 7.2 07.05.2007 no virus found
              CAT-QuickHeal 9.00 07.05.2007 no virus found
              ClamAV devel-20070416 07.05.2007 no virus found
              DrWeb 4.33 07.05.2007 no virus found
              eSafe 7.0.15.0 07.05.2007 no virus found
              eTrust-Vet 30.8.3765 07.05.2007 no virus found
              Ewido 4.0 07.05.2007 no virus found
              FileAdvisor 1 07.05.2007 no virus found
              Fortinet 2.91.0.0 07.05.2007 no virus found
              F-Prot 4.3.2.48 07.04.2007 no virus found
              F-Secure 6.70.13260.0 07.05.2007 no virus found
              Ikarus T3.1.1.8 07.05.2007 no virus found
              Kaspersky 4.0.2.24 07.05.2007 no virus found
              McAfee 5068 07.05.2007 no virus found
              Microsoft 1.2701 07.05.2007 no virus found
              NOD32v2 2379 07.04.2007 no virus found
              Norman 5.80.02 07.05.2007 no virus found
              Panda 9.0.0.4 07.05.2007 no virus found
              Sophos 4.19.0 06.24.2007 no virus found
              Sunbelt 2.2.907.0 07.04.2007 no virus found
              Symantec 10 07.05.2007 no virus found
              TheHacker 6.1.6.142 07.04.2007 no virus found
              VBA32 3.12.0.2 07.05.2007 no virus found
              VirusBuster 4.3.23:9 07.05.2007 no virus found
              Webwasher-Gateway 6.0.1 07.05.2007 no virus found

              Aditional Information
              File size: 200 bytes
              MD5: 2f0359358fa3fdc500c8e59b3f46f695
              SHA1: e5ad3f6a3f76e392778245624128613c4310782d
              0
              1. Supprime celui-ci :

                C:\winsfr.exe

                **Si un fichier/dossier persiste lors de la suppression fait ceci:
                - Redémarre ton PC. Dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaître choisis "mode sans echec" attends un peu..
                Puis va supprimer les fichiers/dossiers, vide ta corbeille et redémarre ton PC normalement.

                ¤ Fais ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
                Une fois qu'il a terminé colle le rapport ici stp

                https://www.bitdefender.com/toolbox/
                0