Win32: vitro... Securtity tools VIRUS

Bonjour, j'ai un gros problème j'ai choppé un malware avant-hier intitulé Security tools et j'ai essayé de le retirer après avoir lu les différents sujets...

J'ai utilisé le msconfig pour le désactiver au démarage de l'ordi parce qu'il empêchait toutes les applications de s'executer et au bout de 10 sec le bureau disparaissait...

Sauf que maintenant, (il ne se lance plus au démarage) j'essaye de le supprimer et je ne le trouve nul part j'ai utilisé Hijackthis mais il ne le trouve pas (enfin je crois)...

J'ai donc fait un scan avec malwarebytes il m'a trouvé une vingtaines de fichiers infectés que j'ai mis en quarantaine...

Mais je me suis vite apperçu que cela n'avait servi à rien puisque mon ordinateur tourne au ralentit, quand je regarde dans les processus je m'apperçois que j'ai plein de fichiers svchost.exe qui tournent et me bouffent toute la ram...Même si c'est normal d'avoir quelque fichiers svchost là il y en a une 20 aines et certain bouffe complétement la RAM (Avant de choper le virus ça ne le faisait pas et je n'avais que 3-4 svchost.exe)

j'ai donc lancé avast mon antivirus et il m'a signalé que mon ordi avait un virus (nan sans blagues !) et qu'il voulait me faire un scan complet au redémarage...
J'ai fait le scan d'avast qui m'a pris 2 h et enfaite j'ai deux autres virus nommé Win32 vitro et JunkPoly qui ont infecté un bon nombre de fichiers...Je me suis renseigné et apparemment Win32 vitro est un nouveau virus détecté par la mise à jour d'avast et qui infecte les .exe... Bref je me trompe surement quelque part mais la j'ai vraiment besoin d'aide je ne sais plus quoi faire :/...

Merci à ceux qui pourront m'aider !

Je vous poste mon rapport HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:37:21, on 06/11/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18319)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://join.clonecashsystem.com/track/NjU1ODMuMjYuMzEuMzUuMC4wLjAuMC4w
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = search.net-studio.org
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = search.net-studio.org
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [wextract_cleanup1] rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Arnaud\AppData\Local\Temp\IXP001.TMP\"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ter8m] RUNDLL32.EXE C:\Windows\TEMP\msxm192z.dll,w
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [ter8m] RUNDLL32.EXE C:\Windows\TEMP\msxm192z.dll,w (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ter8m] RUNDLL32.EXE C:\Windows\TEMP\msxm192z.dll,w (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: fastnetsrv Service (fastnetsrv) - Netopsystems A - C:\Windows\system32\FastNetSrv.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: PremierOpinion - PremierOpinion - C:\Windows\system32\pmservice.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HD DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)

--
End of file - 7918 bytes

Merci d'avance à ceux qui voudront bien m'aider !
Configuration: Windows Vista
Firefox 3.0.15

45 réponses

Résumé de la discussion

Une infection par un malware baptisé Security Tools provoque des perturbations majeures sur Windows Vista, avec un blocage au démarrage et une forte ralentissement générale après que l'utilisateur ait tenté de le désactiver via msconfig. Le processus de suppression est compliqué: suppression via HijackThis et Malwarebytes n'élimine pas totalement les traces alors que Avast signale Win32 Vitro et JunkPoly et que des dizaines de svchost.exe consomment la RAM. Le rapport HijackThis partagé montre de nombreuses entrées de démarrage et des composants potentiellement malveillants, indiquant que la contamination est étendue et nécessiterait une assistance spécialisée.

Bobot (l’IA à votre service)

  1. /!\ ATTENTION SUIVRE SCRUPULEUSEMENT A LA LETTRE CES INDICATIONS/!\

    ▶ Surtout , pense à l'enregistrement à renommer Combofix en "ton prenom.exe"

    _______________________________________________________________
    >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
    >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
    ======================================================


    ▶ On va utiliser ComboFix.exe. Rends toi sur cette page web pour obtenir les liens de téléchargement, ainsi que des instructions pour exécuter l'outil:

    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

    Avant d'utiliser ComboFix :
    ______________________________________________________________________
    >> referme les fenêtres de tous les programmes en cours.
    >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
    >>la protection en temps réel de ton Antivirus et de tes Antispywares,
    >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


    ▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

    ▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    >> Reviens sur le forum, et

    ▶ copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    1. Escan ne veut pas faire les mise à jours à chaque foi il y a marqué "failed"
      1. Voici le rapport

        Malwarebytes' Anti-Malware 1.41
        Version de la base de données: 3181
        Windows 6.0.6001 Service Pack 1

        17/11/2009 02:12:55
        mbam-log-2009-11-17 (02-12-55).txt

        Type de recherche: Examen complet (C:\|E:\|)
        Eléments examinés: 349341
        Temps écoulé: 1 hour(s), 38 minute(s), 39 second(s)

        Processus mémoire infecté(s): 1
        Module(s) mémoire infecté(s): 1
        Clé(s) du Registre infectée(s): 8
        Valeur(s) du Registre infectée(s): 10
        Elément(s) de données du Registre infecté(s): 2
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 32

        Processus mémoire infecté(s):
        C:\Windows\System32\FastNetSrv.exe (Backdoor.Bot) -> Unloaded process successfully.

        Module(s) mémoire infecté(s):
        c:\Windows\System32\BtwSrv.dll (Backdoor.Bot) -> Delete on reboot.

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\btwsrv (Backdoor.Bot) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\btwsrv (Backdoor.Bot) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwsrv (Backdoor.Bot) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fastnetsrv (Backdoor.Bot) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\fastnetsrv (Backdoor.Bot) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fastnetsrv (Backdoor.Bot) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.Exe (Trojan.Agent) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe (Security.Hijack) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mBt (Backdoor.Bot) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udfa (Backdoor.Bot) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mfa (Backdoor.Bot) -> Quarantined and deleted successfully.

        Elément(s) de données du Registre infecté(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.SearchPage) -> Bad: (http://join.clonecashsystem.com/track/NjU1ODMuMjYuMzEuMzUuMC4wLjAuMC4w) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.
        HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.SearchPage) -> Bad: (http://join.clonecashsystem.com/track/NjU1ODMuMjYuMzEuMzUuMC4wLjAuMC4w) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        c:\Windows\System32\BtwSrv.dll (Backdoor.Bot) -> Delete on reboot.
        C:\Windows\System32\FastNetSrv.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\opeia.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\t1p0_793505591980.b1k (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\Windows\System32\wmdtc.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\lsm32.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1DFWHP9N\w[1].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1DFWHP9N\w[2].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1DFWHP9N\w[3].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4Y02N1GE\w[1].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4Y02N1GE\w[2].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4Y02N1GE\w[3].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4Y02N1GE\w[4].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4Y02N1GE\w[6].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KR63KSQR\w[1].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KR63KSQR\w[2].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KR63KSQR\w[3].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KR63KSQR\w[6].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XQO33XCH\w[1].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XQO33XCH\w[2].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XQO33XCH\w[3].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XQO33XCH\w[4].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XQO33XCH\w[6].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\Temp\t4m0_126189473157.bk.old (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\Temp\tmp0_213444752952.bk.old (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\Temp\txpxr_39201534578.b1k (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Windows\Temp\txpxr_547833370707.b1k (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\Windows\Temp\txpxr_658309657641.b1k (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\Windows\Temp\txpxr_856923214016.b1k (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\Windows\Temp\txpxr_893289705339.b1k (Backdoor.Bot) -> Quarantined and deleted successfully.
        C:\Users\Arnaud\Favorites\Clone Cash System.url (Malware.Trace) -> Quarantined and deleted successfully.
        C:\Users\Arnaud\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
        1. hello

          Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

          ▶ Télécharge :

          Malwarebytes

          ou :

          Malwarebytes

          ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

          (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

          ▶ Potasses le Tuto pour te familiariser avec le prg :

          ( cela dit, il est très simple d'utilisation ).

          relance malwarebytes en suivant scrupuleusement ces consignes :

          ! Déconnecte toi et ferme toutes applications en cours !

          ▶ Lance Malwarebyte's .

          Fais un examen dit "Complet" .

          ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
          ▶ à la fin tu cliques sur "résultat" .
          ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

          ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

          ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

          1. Salut gen, mon ordinateur fonctionne correctement depuis que tu t'es absenté, il est cependant un peu plus lent qu'avant et j'ai toujours une grosse dizaine de svchost lancés dans les processus...

            Voilà tout
            1. bonjour j ai du m absenter

              quels soucis te reste-t-il precisement ?
              1. En mode normal je n'ai pas désactivé avast (d'ailleurs je ne sais pas comment faire), mais en mode sans echec il n'y a plus l'antivirus, non?
                1. j'ai essayé de lancer List Killem mais toujours un message d'erreur que ce soit en mode normal ou sans echec

                  "An unknown error occured. The program will be terminated"
                  1. Excuse moi je n'ai pas bien compris, ce que tu appeles le post1 c'est quoi? :/

                    Tu veux parler de eScan Antivirus Toolkit?
                    1. retente le post1 stp

                      supprime , retelecharge et lance-le "executer en tant ........" avec le clic droit
                      1. Voici le rapport :-) :

                        All processes killed
                        ========== PROCESSES ==========
                        No active process named explorer.exe was found!
                        No active process named iexplore.exe was found!
                        No active process named firefox.exe was found!
                        No active process named msnmsgr.exe was found!
                        No active process named Teatimer.exe was found!
                        ========== FILES ==========
                        C:\Windows\System32\lsprst7.dll moved successfully.
                        C:\Windows\System32\lsprst7.tgz moved successfully.
                        C:\Windows\System32\ssprs.dll moved successfully.
                        C:\Windows\System32\ssprs.tgz moved successfully.
                        C:\Windows\System32\3936,731.exe moved successfully.
                        C:\Windows\System32\9097,102.exe moved successfully.
                        C:\Windows\System32\9854,548.exe moved successfully.
                        C:\Windows\System32\161710.BAT moved successfully.
                        ========== COMMANDS ==========

                        [EMPTYTEMP]

                        User: All Users

                        User: Arnaud
                        ->Temp folder emptied: 37426079 bytes
                        ->Temporary Internet Files folder emptied: 146012 bytes
                        ->Java cache emptied: 16954781 bytes
                        ->FireFox cache emptied: 60897067 bytes

                        User: Default
                        ->Temp folder emptied: 0 bytes
                        ->Temporary Internet Files folder emptied: 33170 bytes

                        User: Default User
                        ->Temp folder emptied: 0 bytes
                        ->Temporary Internet Files folder emptied: 0 bytes

                        User: Public

                        %systemdrive% .tmp files removed: 0 bytes
                        %systemroot% .tmp files removed: 0 bytes
                        %systemroot%\System32 .tmp files removed: 0 bytes
                        Windows Temp folder emptied: 7294878 bytes
                        RecycleBin emptied: 0 bytes

                        Total Files Cleaned = 117,07 mb

                        OTL by OldTimer - Version 3.1.4.0 log created on 11102009_143900

                        Files\Folders moved on Reboot...
                        File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                        C:\Windows\temp\mta13187.dll moved successfully.

                        Registry entries deleted on Reboot...
                        1. Télécharge OTL de OLDTimer

                          ▶ enregistre le sur ton Bureau.

                          ▶ clic droit "executer en tant qu'administrateur " sur OTL.exe pour le lancer.

                          ▶Copie la liste qui se trouve en gras ci-dessous,

                          ▶ colle-la dans la zone sous Customs Scans/Fixes :

                          :processes
                          explorer.exe
                          iexplore.exe
                          firefox.exe
                          msnmsgr.exe
                          Teatimer.exe

                          :files
                          C:\Windows\System32\lsprst7.dll
                          C:\Windows\System32\lsprst7.tgz
                          C:\Windows\System32\ssprs.dll
                          C:\Windows\System32\ssprs.tgz
                          C:\Windows\System32\????,???.exe
                          C:\Windows\System32\161710.Bat

                          :commands
                          [emptytemp]
                          [start explorer]
                          [reboot]


                          ▶ Clique sur RunFix pour lancer la suppression.

                          ▶ Poste le rapport.
                          1. Voilà j'ai fait une analyse détaillée mais il y a eu un message d'erreur juste à la fin de cette analyse "Violation d'accès à l'adresse 00403006 dans le module "ZHPDag.exe" lecture de l'adresse 00001850"...

                            http://www.cijoint.fr/cjlink.php?file=cj200911/cijgaLJROs.txt

                            Si le rapport n'est pas complet j'essayerai par l'autre ZHPag car j'ai fait avec celui de Nicolas (je sais plus son nom)
                            1. Voici le rapport comme prévu:

                              http://www.cijoint.fr/cjlink.php?file=cj200911/cij6mFNmVs.txt
                              • 1
                              • 2
                              • 3