INFECTE : Trojan-downloader, trojan-clicker

Résolu
Bonjour,

depuis quelques jour je suis iinfecté par des trojans.
A chaque fois que j'ouvre une page internet j'ai un message d'alerte de soit disant windows me renvoyant sur un site pour telecharger un antivirus.
Mais mes messages d'alertes ont des noms toujours differents, depuis j'ai téléchargé spy bot, malwarebytes, mon antivirus antivir ne le trouve pas et personne ne peut me l'enlever, si vous pourriez m'aider merci d'avance.
Configuration: Windows Vista
Internet Explorer 7.0

11 réponses

  1. Contributeur sécurité
    slt

    tu as les rapports antivir et malwarebyte? si oui mets les

    puis colle un rapport hijakhcits

    https://www.01net.com/404/­re/fiches/29061.html
    -1
    1. bonjour, non je n'ai pas les rapport antivir et malwarebytes.

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 14:22:23, on 20/10/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16757)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\BisonCam\BisonHK.exe
      C:\Windows\BisonCam\BsMnt.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\ProgramData\tgfqjghe\twnwdobq.exe
      C:\ProgramData\apiappinfo\kdenuzqp.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
      C:\Windows\system32\taskeng.exe
      D:\Programmes\totalcmd\TOTALCMD.EXE
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
      C:\Windows\system32\conime.exe
      C:\Users\Yassine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YTT0IWVP\HiJackThis[1].exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.5470\swg.dll
      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [BisonHK] C:\Windows\BisonCam\BisonHK.exe
      O4 - HKLM\..\Run: [BsMnt] C:\Windows\BisonCam\BsMnt.exe
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Skytel] Skytel.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programmes\Adobe\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [TrojanScanner] D:\Programmes\Trojan Remover\Trjscan.exe /boot
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [1abd03bBce] C:\ProgramData\tgfqjghe\twnwdobq.exe
      O4 - HKCU\..\Run: [apiappinfo] C:\ProgramData\apiappinfo\kdenuzqp.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
      O13 - Gopher Prefix:
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
      -1
      1. Contributeur sécurité
        slt,

        télécharge OTMoveIt
        http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
        double-clique sur OTMoveIt.exe pour le lancer.
        copie la liste qui se trouve en citation ci-dessous,
        et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

        Citation :

        C:\ProgramData\tgfqjghe\twnwdobq.exe
        C:\ProgramData\apiappinfo\kdenuzqp.exe

        clique sur MoveIt! pour lancer la suppression.
        le résultat apparaitra dans le cadre "Results".
        clique sur Exit pour fermer.
        poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

        il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

        _____________________

        a plus
        -1
        1. voici le rapport de OTMovelt

          C:\ProgramData\tgfqjghe\twnwdobq.exe moved successfully.
          C:\ProgramData\apiappinfo\kdenuzqp.exe moved successfully.

          OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10202008_143430
          -1
          1. Contributeur sécurité
            encore des alertes?

            antivir et malwarebyte on virés des infections?
            -1
            1. pour l'instant je n'ai plus d'alertes quand j'ouvre une page web, je suis en train d efaire un scan d'antivir et de malwarebytes.
              -1
              1. Contributeur sécurité
                ok colle moi les rapports
                -1
                1. pour l'instant j'ai que le rapport de antiivir, malmarebytes est en train de finir.

                  Avira AntiVir Personal
                  Report file date: lundi 20 octobre 2008 15:08

                  Scanning for 1692263 virus strains and unwanted programs.

                  Licensed to: Avira AntiVir PersonalEdition Classic
                  Serial number: 0000149996-ADJIE-0001
                  Platform: Windows Vista
                  Windows version: (plain) [6.0.6000]
                  Boot mode: Normally booted
                  Username: SYSTEM
                  Computer name: PC-DE-YASSINE

                  Version information:
                  BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                  AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                  AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                  LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                  LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                  ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                  ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
                  ANTIVIR2.VDF : 7.0.7.12 4066816 Bytes 08/10/2008 13:39:28
                  ANTIVIR3.VDF : 7.0.7.58 315904 Bytes 17/10/2008 13:39:30
                  Engineversion : 8.2.0.5
                  AEVDF.DLL : 8.1.0.6 102772 Bytes 19/10/2008 13:39:48
                  AESCRIPT.DLL : 8.1.1.9 319867 Bytes 19/10/2008 13:39:46
                  AESCN.DLL : 8.1.1.3 123252 Bytes 19/10/2008 13:39:45
                  AERDL.DLL : 8.1.1.2 438644 Bytes 19/10/2008 13:39:45
                  AEPACK.DLL : 8.1.2.4 369014 Bytes 19/10/2008 13:39:43
                  AEOFFICE.DLL : 8.1.0.28 196987 Bytes 19/10/2008 13:39:41
                  AEHEUR.DLL : 8.1.0.59 1438071 Bytes 19/10/2008 13:39:40
                  AEHELP.DLL : 8.1.1.2 115062 Bytes 19/10/2008 13:39:37
                  AEGEN.DLL : 8.1.0.41 319861 Bytes 19/10/2008 13:39:36
                  AEEMU.DLL : 8.1.0.9 393588 Bytes 19/10/2008 13:39:35
                  AECORE.DLL : 8.1.2.6 172406 Bytes 19/10/2008 13:39:34
                  AEBB.DLL : 8.1.0.3 53618 Bytes 19/10/2008 13:39:33
                  AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                  AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                  AVREP.DLL : 8.0.0.2 98344 Bytes 19/10/2008 13:39:31
                  AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                  AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                  AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                  SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                  SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                  NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                  RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                  RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                  Configuration settings for the scan:
                  Jobname..........................: Complete system scan
                  Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                  Logging..........................: low
                  Primary action...................: interactive
                  Secondary action.................: ignore
                  Scan master boot sector..........: on
                  Scan boot sector.................: on
                  Boot sectors.....................: C:, D:,
                  Process scan.....................: on
                  Scan registry....................: on
                  Search for rootkits..............: off
                  Scan all files...................: Intelligent file selection
                  Scan archives....................: on
                  Recursion depth..................: 20
                  Smart extensions.................: on
                  Macro heuristic..................: on
                  File heuristic...................: medium

                  Start of the scan: lundi 20 octobre 2008 15:08

                  The scan of running processes will be started
                  Scan process 'avscan.exe' - '1' Module(s) have been scanned
                  Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                  Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
                  Scan process 'msiexec.exe' - '1' Module(s) have been scanned
                  Scan process 'FlashUtil10a.exe' - '1' Module(s) have been scanned
                  Scan process 'conime.exe' - '1' Module(s) have been scanned
                  Scan process 'GoogleToolbarUser.exe' - '1' Module(s) have been scanned
                  Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                  Scan process 'ieuser.exe' - '1' Module(s) have been scanned
                  Scan process 'TOTALCMD.EXE' - '1' Module(s) have been scanned
                  Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
                  Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                  Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                  Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'o2flash.exe' - '1' Module(s) have been scanned
                  Scan process 'avguard.exe' - '1' Module(s) have been scanned
                  Scan process 'agrsmsvc.exe' - '1' Module(s) have been scanned
                  Scan process 'CCC.exe' - '1' Module(s) have been scanned
                  Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                  Scan process 'MOM.exe' - '1' Module(s) have been scanned
                  Scan process 'kdenuzqp.exe' - '1' Module(s) have been scanned
                  Scan process 'twnwdobq.exe' - '1' Module(s) have been scanned
                  Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                  Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                  Scan process 'jusched.exe' - '1' Module(s) have been scanned
                  Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                  Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
                  Scan process 'BsMnt.exe' - '1' Module(s) have been scanned
                  Scan process 'BisonHK.exe' - '1' Module(s) have been scanned
                  Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
                  Scan process 'explorer.exe' - '1' Module(s) have been scanned
                  Scan process 'dwm.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'sched.exe' - '1' Module(s) have been scanned
                  Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                  Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                  Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                  Scan process 'lsm.exe' - '1' Module(s) have been scanned
                  Scan process 'lsass.exe' - '1' Module(s) have been scanned
                  Scan process 'services.exe' - '1' Module(s) have been scanned
                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                  Scan process 'wininit.exe' - '1' Module(s) have been scanned
                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                  Scan process 'smss.exe' - '1' Module(s) have been scanned
                  59 processes with 59 modules were scanned

                  Starting master boot sector scan:
                  Master boot sector HD0
                  [INFO] No virus was found!

                  Start scanning boot sectors:
                  Boot sector 'C:\'
                  [INFO] No virus was found!
                  Boot sector 'D:\'
                  [INFO] No virus was found!

                  Starting to scan the registry.
                  The registry was scanned ( '40' files ).

                  Starting the file scan:

                  Begin scan in 'C:\' <OS_Install>
                  C:\hiberfil.sys
                  [WARNING] The file could not be opened!
                  C:\pagefile.sys
                  [WARNING] The file could not be opened!
                  Begin scan in 'D:\' <Data>

                  End of the scan: lundi 20 octobre 2008 15:47
                  Used time: 38:34 Minute(s)

                  The scan has been done completely.

                  12678 Scanning directories
                  231002 Files were scanned
                  0 viruses and/or unwanted programs were found
                  0 Files were classified as suspicious:
                  0 files were deleted
                  0 files were repaired
                  0 files were moved to quarantine
                  0 files were renamed
                  2 Files cannot be scanned
                  231000 Files not concerned
                  1434 Archives were scanned
                  2 Warnings
                  0 Notes
                  -1
                  1. voilà l'autre rapport

                    Malwarebytes' Anti-Malware 1.29
                    Version de la base de données: 1295
                    Windows 6.0.6000

                    20/10/2008 16:16:34
                    mbam-log-2008-10-20 (16-16-34).txt

                    Type de recherche: Examen complet (C:\|D:\|)
                    Eléments examinés: 100307
                    Temps écoulé: 1 hour(s), 6 minute(s), 34 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 2
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 0

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    HKEY_CURRENT_USER\SOFTWARE\wkey (Malware.Trace) -> Quarantined and deleted successfully.
                    HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.

                    Valeur(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    (Aucun élément nuisible détecté)
                    -1
                    1. ok merci beaucoup pour ton aide
                      -1