Virus msn et vista 64 bits

Windu -  
 coolmec -
Bonjour,

aujourd'hui j'ai reçu un message de l'un de mes contact avec un lien vers l'un des fameux virus msn. J'ai téléchargé le virus comme un boulet sans me poser de question et j'ai donc été infecté. J'ai vu qu'il existe de nombreux logiciel affin de supprimer les virus msn mais j'ai windows vista 64 bits et impossible de trouver un logiciel compatible avec vista 64 bits. Depuis que j'ai été infecté avast me trouve régulièrement des virus que je supprime au fur et a mesure. J'ai scané le PC avec a-squared et spybot mais sans succès.

J'espère avoir été assez clair dans mon explication.

Merci d'avance de vos réponses !
Configuration: Windows Vista
Firefox 3.0.4

4 réponses

  1. coolmec
     
    salut !!

    telecharges la version d'essai de kaspersky internet security, installe la, et fais une analyse, il va te desinfecter en un rien de temps !!

    http://linkbee.com/KASPERSKY-ESSAI

    ;) bon courage
    1
  2. Utilisateur anonyme
     
    Salut,

    1/
    Télécharger CCleaner (installe pas la barre de Yahoo ) :
    https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

    lance le, dans nettoyeur clique sur lancer le nettoyage puis dans Registre fait chercher et répare les erreurs autant de fois qu'il y en n'a.

    2/
    On enlève le plus gros :

    fait un scan en ligne avec internet explore, si tu as firefox fait:
    démarrer -> executer -> tape : iexplore (puis valide)

    BRANCHE TA OU TES CLE USB / LECTEUR EXTERNE ...

    (coche toutes les cases à chaque fois) :
    https://www.eset.com/

    à la fin colle le rapport : C:\Program Files\EsetOnlineScanner\log.txt

    si ta besoin d'aide tu as un tutoriel ici : http://bibou0007.com/tutos-et-lexique-f45/tutorial-nod32-online-scanner-t128.htm

    3/ Fait un scan avec malwarebyte :
    telechargement et aide ici :
    http://www.pcinfo-web.com/...
    une fois fini le rapport s'ouvre copie le et supprime toute la selection.

    4/
    Ensuite une fois fini fait un rapport hijackthis :
    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html

    tu le télécharges, tu le lances et tu cliquera sur le premier bouton en haut "Do a system scan and save a logfile"
    tu colleras le fichier texte ici ;).

    PS : Ne fermes pas le programme
    0
    1. Windu
       
      Merci beaucoup de ton aide !!


      1/ J'avais déjà passé Ccleaner mais sans succès (je l'ai quand même refait)


      2/ J'ai essayé de faire l'analyse sur le site mais impossible, après avoir accepté l'installation du control activeX j'arrive a cette page : http://img368.imageshack.us/img368/9981/antivirusrt3.jpg


      Pour le reste j'ai lancé le scan de malwarebyte cette nuit, je posteré le rapport demain matin ainsi que celui de hijackthis
      0
  3. Utilisateur anonyme
     
    tu as les droit administrateur ? / autorise active X ? / tu est sur IE normal et pas 64 bits ?
    0
    1. Windu
       
      Oui j'ai les droits d'admin sur le PC le control des comptes utilisateurs est désactivé. J'ai bien autorisé le control activeX. Pour ce qui est de la version de IE je n'y ai pas touché depuis que j'ai le PC car je n'utilise que firefox.

      3/ J'ai fait le scan avec Malwarebytes et il ma trouvé quelques fichiers infectés, voici le rapport :

      Malwarebytes' Anti-Malware 1.30
      Version de la base de données: 1443
      Windows 6.0.6001 Service Pack 1

      02/12/2008 11:07:12
      mbam-log-2008-12-02 (11-07-05).txt

      Type de recherche: Examen complet (C:\|D:\|)
      Eléments examinés: 141917
      Temps écoulé: 30 minute(s), 16 second(s)

      Processus mémoire infecté(s): 1
      Module(s) mémoire infecté(s): 1
      Clé(s) du Registre infectée(s): 2
      Valeur(s) du Registre infectée(s): 3
      Elément(s) de données du Registre infecté(s): 2
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 10

      Processus mémoire infecté(s):
      C:\Windows\fxstaller.exe (Backdoor.Bot) -> No action taken.

      Module(s) mémoire infecté(s):
      C:\Windows\System32\ddcYsPhG.dll (Trojan.Vundo) -> No action taken.

      Clé(s) du Registre infectée(s):
      HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> No action taken.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows UDP Control Center (Backdoor.Bot) -> No action taken.

      Elément(s) de données du Registre infecté(s):
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\\windows\\system32\\xxywomds -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\Windows\fxstaller.exe (Backdoor.Bot) -> No action taken.
      C:\Windows\SysWOW64\ddcYsPhG.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\System32\geBsrsPI.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\System32\nnNhFULC.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\System32\xxyWoMDs.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\SysWOW64\geBsrsPI.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\SysWOW64\nnNhFULC.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\SysWOW64\xxyWoMDs.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\System32\ddcYsPhG.dll (Trojan.Agent) -> No action taken.
      C:\Windows\System32\urqqolKa.dll (Trojan.Vundo) -> No action taken.


      4/ voici le rapport de hijackthis :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:15:18, on 02/12/2008
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Program Files (x86)\Windows Sidebar\sidebar.exe
      C:\Program Files (x86)\Electronic Arts\EADM\Core.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
      C:\Windows\SysWOW64\rundll32.exe
      C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      C:\Windows\SysWOW64\NOTEPAD.EXE
      C:\Users\Windu\Desktop\HiJackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files (x86)\Xi\NetXfer\NXIEHelper.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files (x86)\Xi\NetXfer\NXToolBar.dll
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
      O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\vtUmJYol.dll,#1
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe
      O4 - HKCU\..\Run: [EPSON Stylus Photo R220 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIAIE.EXE /FU "C:\Users\Windu\AppData\Local\Temp\E_S53AB.tmp" /EF "HKCU"
      O4 - HKCU\..\Run: [EA Core] C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O8 - Extra context menu item: Tout télécharger avec NetXfer - C:\Program Files (x86)\Xi\NetXfer\NXAddList.html
      O8 - Extra context menu item: Télécharger avec NetXfer - C:\Program Files (x86)\Xi\NetXfer\NXAddLink.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
      O13 - Gopher Prefix:
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
      O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
      O23 - Service: FAH@C:+Users+Windu+Desktop+crack+FAH.exe - Unknown owner - C:\Users\Windu\Desktop\crack\FAH.exe (file missing)
      O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
      O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
      O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
      O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
      O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
      O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
      O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
      O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
      O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
      O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
      O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
      O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
      O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
      O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
      O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
      0
  4. Utilisateur anonyme
     
    Pour malwarebyte supprime la selection !
    et refai hijackthis apres
    0
    1. Windu
       
      Oui c'est exactement ce que j'ai fait !
      0
    2. Windu
       
      Je viens d'installer IE8 beta pour réaliser l'analyse en ligne mais j'ai toujours exactement le même problème ! J'ai aussi remarqué un autre soucis avec firefox : lorsque je veut télécharger un fichier je fait enrgistrer sur le disque et la fenêtre qui apparait (pour choisir où enregistré) est toute blanche et je ne peut rien faire !

      Je viens de refaire un scan rapide avec Malwarebytes et il a retrouvé 6 éléments, voici le nouveau rapport :

      Malwarebytes' Anti-Malware 1.30
      Version de la base de données: 1443
      Windows 6.0.6001 Service Pack 1

      02/12/2008 11:54:30
      mbam-log-2008-12-02 (11-54-26).txt

      Type de recherche: Examen rapide
      Eléments examinés: 38899
      Temps écoulé: 2 minute(s), 1 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 1
      Clé(s) du Registre infectée(s): 1
      Valeur(s) du Registre infectée(s): 2
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 2

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      C:\Windows\System32\ljJASliH.dll (Trojan.Vundo) -> No action taken.

      Clé(s) du Registre infectée(s):
      HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> No action taken.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\Windows\SysWOW64\ljJASliH.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\System32\ljJASliH.dll (Trojan.Agent) -> No action taken.
      0
    3. Windu > Windu
       
      Après avoir supprimé les 6 objets infectés de Malwarebytes le problème de téléchargement avec firefox disparait mais lorsque je redémare le PC le problème revient ! J'ai vraiment du mal a comprendre...
      0
    4. Windu > Windu
       
      Voici le dernier virus trouvé par avast :

      http://img185.imageshack.us/img185/7770/virusze8.jpg

      Je viens de lancer un scan du système avec avast.
      0
    5. Windu > Windu
       
      L'analyse avast est terminée. Il a trouvé 3 fichiers infectés comme celui la dans le même répertoire :

      http://img154.imageshack.us/img154/5772/nouvoiw9.jpg

      Je les ai donc supprimé !

      Que dois-je faire maintenant ?
      0