Win32.Trojan-gen

Résolu
Boboléon -  
crapoulou Messages postés 42848 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour,Win32.Trojan-gen

Bonjour !
Ca fait une semaine que je passe mon temps à tenter de dévéroler ma bécane de nombreuses bestioles… dont la centrale me semble être Win32.Trojan-gen, qui porte plein de noms différents et draine tout un tas de malwares… en vrac, quelques exemples :
-SmitfraudC
- Virtumonde
- Trojan.Agent
- Hijack.wallpaper ; Hijack.homepage
- Fake.dropped.malware
- Rogue.System.Antivirus
- Malware.trace…

J’ai utilisé Avast 4.8, SmitfraudFix , Spybot ;
Ce dernier est utile pour empêcher les modifs de registre, mais il connait des difficultés d’analyse pour 3 “includes” : Trojans, TrojansC et Malware – voir ci-joint le fichier Include errors.log) ;
et sur les conseils de Boulepate62, Malwarebytes et Bitdefender.
Sans succès pour éradiquer la bestiole mère… toute aide est la bienvenue !
Je joints le rapport Hijackthis en fin de message…

J'ai de l'espoir en voyant que cette question trouve des solutions sur le forum !
Merci d’avance

INCLUDE ERRORS.LOG DE SPYBOT :

C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Malware.sbi | Win32.Agent.pz | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FakeUPSInvoice | <$SYSDIR>\userini.exe
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Malware.sbi | Win32.Agent.pz | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FakeUPSInvoice | <$SYSDIR>\userini.exe
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Malware.sbi | Win32.Agent.pz | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FakeUPSInvoice | <$SYSDIR>\userini.exe
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Malware.sbi | Win32.Agent.pz | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FakeUPSInvoice | <$SYSDIR>\userini.exe
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Malware.sbi | Win32.Agent.pz | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FakeUPSInvoice | <$SYSDIR>\userini.exe
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Malware.sbi | Win32.Agent.pz | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\MalwareC.sbi | Smitfraud-C.ul | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | FakeUPSInvoice | <$SYSDIR>\userini.exe
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Malware.sbi | Win32.Agent.pz | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\MalwareC.sbi | Smitfraud-C.ul | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | FakeUPSInvoice | <$SYSDIR>\userini.exe
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_DATA>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Haxdoor.hm | <$FILE_LIBRARY>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>

RAPPORT HIJACKTHIS.LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:04:46, on 07/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\NOTEPAD.EXE
c:\program files\fichiers communs\installshield\updateservice\isuspm.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\agent.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=5061108
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {D3166EE4-3E00-46CA-8F62-8E01D2314A7F} - http://www.cig.canon-europe.com/ph/fr_FR/st/download/ddup/CNIMGUP_01_210102F.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Droppix Service - Droppix - C:\Program Files\Fichiers communs\Droppix\DxService.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: MpService - Canon Inc. - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
A voir également:

25 réponses

crapoulou Messages postés 42848 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 017
 
Ces fichiers se trouvent dans la restauration du système : peux tu supprimer ces fichiers détectés par avast ?
Si oui, fais le.
Ensuite, Désactive et réactive ta restauration système.
Démarrer, clic droit</gras> sur Poste de travail, Propriétés, onglet Restauration du système, Désactiver la restauration du système, puis Appliquer et <gras>ok, ok<gras>.
(Manipulation inverse pour la réactiver).
0
Boboleon Messages postés 9 Statut Membre 3
 
C'est OK j'ai tout viré avec OTMoveIt... je reteste...
0
crapoulou Messages postés 42848 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 017
 
Pourquoi tu n'y parviens pas ?
Quand il a détecté quoi t'as fait quoi, mis en quarantaine ??
Fais quand même la manip'.
0
Boboléon
 
Après contrôles, il semble que la bécane soit clean ! Merci beaucoup pour le soutien !
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Boboléon
 
J'ai pas compris exactement l'utilité de la manip , mais je l'ai fait quand même et voici le rapport !

[ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\SDFIX: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\Jérôme\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SdFix.exe: trouvé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\KillBox.exe: trouvé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\OtMoveIt2.exe: trouvé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SmitFraudFix.exe: trouvé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SmitFraudfix: trouvé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SPybot\HijackThis: trouvé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SPybot\Hijackthis\HJTInstall.exe: trouvé !
C:\Documents and Settings\Jérôme\Recent\HijackThis.lnk: trouvé !
C:\Program Files\HijackThis: trouvé !
C:\Program Files\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\HijackThis\hijackthis.log: trouvé !
C:\Program Files\Mozilla Firefox\SmitFraudfix: trouvé !

Corbeille vidée!
Fichiers temporaires nettoyés !
---------------------------------
-->- Suppression:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\Jérôme\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SdFix.exe: supprimé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\KillBox.exe: supprimé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\OtMoveIt2.exe: supprimé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SmitFraudFix.exe: supprimé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SPybot\Hijackthis\HJTInstall.exe: supprimé !
C:\Program Files\HijackThis\HijackThis.exe: supprimé !
C:\Program Files\HijackThis\hijackthis.log: supprimé !
C:\SDFIX: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SmitFraudfix: supprimé !
C:\Documents and Settings\Jérôme\Mes documents\Utilitaires\Securite_info\SPybot\HijackThis: supprimé !
C:\Program Files\HijackThis: supprimé !
C:\Program Files\Mozilla Firefox\SmitFraudfix: supprimé !
0