Virus Spyware - Page 2

  1. Contributeur sécurité
    est ce que tu me donné ce message d'erreur ?pour faire avancer les choses .
    0
    1. Bah un message d'erreur comment dire... Ca me dit: "Internet Explorer à cesser de fonctionner". Dans ce message j'ai deux solution: Soit je redémarre Internet Explorer, soit je cherche en ligne une solution.

      Je suis en train de faire l'analyse que tu m'as demandé de faire.
      0
      1. Contributeur sécurité
        On va essayer ca pour explorer :

        télécharge Iefix a cette adresse : IEFIX

        décompresse le et exécute le .
        0
        1. Ok j'utiliserais cette méthode quand j'aurais terminer avec Dr.Web.
          Sinon pour pas m'embêter, Mozilla Firefox est peut-être une bonne solution !
          0
          1. Merci beaucoup pour tes réponses c'est vraiment sympa.
            Je voudrais pouvoir mettre le rapport DrWeb.csv sur le forum, mais comment faire? Je l'ouvre avec un fichier .txt?
            0
            1. Contributeur sécurité
              Je l'ouvre avec un fichier .txt? oui pas de soucis .
              0
              1. D'accord voici le rapport:

                winauq32.rom;c:\windows\system32;Trojan.Mssmsgs.2;Supprimé.;
                psexec.cfexe;C:\327882R2FWJFW;Program.PsExec.171;Irréparable.Quarantaine.;
                kb65666[1];C:\Documents and Settings\nicolas\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\14D69ZP;Trojan.Starter.561;Supprimé.;
                rbadsvag.exe;C:\Windows\System32;Trojan.Starter.561;Supprimé.;
                0
                1. Contributeur sécurité
                  Drwebcureit a fait du bon boulot !

                  tu vas ajouter ceci :

                  Vide tes fichiers temporaires avec ceci:
                  ->Clean Up 40:
                  http://pageperso.aol.fr/balltrap34/CleanUp40.exe
                  ->aide en image:(merci a Balltrap34)
                  http://pageperso.aol.fr/balltrap34/democleanup.htm

                  click sur option et décoche la case devant : delete prefect files

                  vide le manuellement :

                  :: Le contenu du dossier prefetch ::

                  * C:\WINDOWS\Prefetch <= sauf le fichier layout.ini

                  * Ne pas oublier de vider la corbeille !
                  0
                  1. Voilà j'ai fais CleanUp, maintenant je vais supprimer les fichiers.

                    Est-ce que je dois supprimer le dossier: ReadyBoot aussi?
                    0
                    1. Contributeur sécurité
                      Est-ce que je dois supprimer le dossier: ReadyBoot aussi?

                      A toi de voir , Readyboost sert a "booster" ton pc avec un disque amovible (du style cle usb); il allege la memoire vive en greffant une partie sur une clé ou autre . tu peux le garder comme tu peux le virer ,a savoir si tu t'en servira ?

                      recolle moi un hijack pour finir ensuite .
                      0
                      1. Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 11:31:29, on 17/08/2008
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Windows\RtHDVCpl.exe
                        C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                        C:\Program Files\Softwin\BitDefender10\bdagent.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                        C:\Windows\FixCamera.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\tsnp2std.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Windows\vsnp2std.exe
                        C:\Program Files\PowerISO\PWRISOVM.EXE
                        C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Steam\Steam.exe
                        C:\Program Files\Ares\Ares.exe
                        C:\Windows\System32\mobsync.exe
                        C:\Program Files\DAEMON Tools Lite\daemon.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Windows\explorer.exe
                        C:\Users\nicolas\AppData\Local\Temp\Rar$EX00.194\TeamSpeak 3.exe
                        C:\Users\nicolas\AppData\Local\Temp\Rar$EX00.461\TeamSpeak 3.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\HiJackThis\HiJackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: D - {0BDA86A8-FFF1-3332-8473-748579FC625D} - C:\Windows\wxml46820.dll
                        O2 - BHO: (no name) - {42C613FF-E3E7-4733-AB08-04227896E440} - (no file)
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                        O2 - BHO: (no name) - {e10b3d67-90f8-207a-3363-3efaf17a96f2} - (no file)
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe
                        O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
                        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                        O4 - HKLM\..\Run: [FixCamera] C:\Windows\FixCamera.exe
                        O4 - HKLM\..\Run: [tsnp2std] C:\Windows\tsnp2std.exe
                        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
                        O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
                        O4 - HKLM\..\Run: [{62dd4334-c0ca-6610-794f-b2f11170595d}] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\mbftpemgpduqfg.dll" DllStart
                        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                        O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
                        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                        O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                        O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
                        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                        O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                        O4 - HKCU\..\Run: [Comrade.exe] C:\Program Files\GameSpy\Comrade\Comrade.exe
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                        O13 - Gopher Prefix:
                        O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                        O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                        O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                        O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                        O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                        O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                        O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                        O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
                        O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                        0
                        1. Contributeur sécurité
                          -> Relance HijackThis cliques sur « scanner seulement » ou (« do a scan only »),
                          coche les cases devant ces lignes :

                          O2 - BHO: (no name) - {42C613FF-E3E7-4733-AB08-04227896E440} - (no file)
                          O2 - BHO: (no name) - {e10b3d67-90f8-207a-3363-3efaf17a96f2} - (no file)


                          et ensuite ferme toutes les fenêtres actives autres que HijackThis!, navigateur inclus,
                          puis clique "Fix checked"( ou « fixer objet »). Ferme HijackThis!

                          tu as installé de nouveaux prog ?

                          Il va falloir analyser un ou des fichier(s) suspect(s) !

                          Il se peut qu'il se trouvent dans les " dossiers cachés " du systeme.
                          Il faut donc les rendre visibles pour le scan.

                          Pour afficher les dossiers et fichiers cachés:

                          Panneau de configuration > Options des dossiers > onglet Affichage.

                          Coche Afficher les fichiers et dossiers cachés,
                          Décoche Masquer les extensions de fichiers connus
                          Décoche Masquer les fichiers protégés du Système.
                          Un message de mise en garde va apparaitre. Clique sur OK pour confirmer ton choix.
                          Les fichiers et dossiers cachés du système apparaitront alors dans l'explorateur Windows en transparence.

                          Rends toi sur ce site :

                          https://www.virustotal.com/gui/

                          Clique sur parcourir et cherche ces fichiers : C:\Program Files\GameSpy\Comrade\Comrade.exe
                          C:\Windows\system32\mbftpemgpduqfg.dll


                          Clique sur Send File.

                          Un rapport va s'élaborer ligne à ligne.

                          Attends la fin. Il doit comprendre la taille du fichier envoyé.

                          Sauvegarde le rapport avec le bloc-note.
                          ---------------------------------------------------------------------------------------------------------------------------------------------------------------

                          Télécharge MSNFix.zip (de !aur3n7) sur ton bureau:
                          http://sosvirus.changelog.fr/MSNFix.zip

                          Décompresse-le (clic droit >> Extraire ici) et place les fichiers dans C:\MSNFix (très important).

                          Double cliquer sur le fichier MSNFix.bat.
                          - Exécutez l'option R.
                          -- Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage

                          Note :
                          Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal

                          - Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.txt

                          pour VISTA :

                          désactive l'UAC:https://forum.malekal.com/viewtopic.php?f=59&t=6517

                          Copie le dans ta réponse.
                          0
                          Précédent
                          • 1
                          • 2