Bugbot de hotmail

Bonjour,
Comment enlever de mes contacts et de ma boite mail, un robot qui envoie des mails à ma place???
Configuration: Windows XP
Firefox 2.0.0.11

52 réponses

Résumé de la discussion

Problème central : un logiciel malveillant se substitue à l’envoi d’emails, affectant les contacts et la boîte mail sur Windows XP avec Firefox 2.0.0.11 et la messagerie configurée. Des éléments détectés par Spybot - Search & Destroy montrent des clés et fichiers malveillants dans le registre, ainsi que des programmes indésirables et des paramètres de démarrage qui maintiennent le bot actif. Pour résoudre le problème, il est recommandé d’utiliser Spybot pour désinstaller les éléments identifiés, nettoyer le registre et vérifier les autoruns, puis de supprimer les dossiers associés et de redémarrer le système. Des mesures supplémentaires utiles incluent la mise à jour des composants Windows XP et du navigateur, l’installation d’un antivirus et l’examen des programmes installés ou des modules complémentaires responsables.

Bobot (l’IA à votre service)
  1. ca y est j'ai fait le truc pour la restauration système.
    Pour la défragmentation, quelques mois je pense..
    0
    1. Désactivez la restauration système :

      Clic droit sur Poste de Travail/Propriétés ou double clic sur Système dans Panneau de configuration Onglet Restauration du système/cocher la case 'Désactiver la restauration du système ...' / OK


      nb : purger la restauration du sytème efface, les virus et malwares planqués dans les fichiers de restauration, c'est pour cela qu'il est primordial de la désactivez !!!


      Ensuite décoches la même case, ainsi tu purges ton système de tout point de restauration...

      ok, à quand remontes ta dernière défragmentation ?
      0
      1. y a pas de problème, je te mettais pas la pression, je croyais juste que comme mon problème était résolu, tu avais abandonné.(merci de bien vouloir continuer à m'aider)

        je te donne le nombre de ram (je suis pas sure que ce soit ça que je te donne, mais bon..): Mémoire totale: 511MB DDR-SDRAM
        0
        1. il m'en faut plus.. J'ai une vie aussi, merci de comprendre...
          De combien disposes tu de RAM ?
          0
          1. j'ai dû te désespérer...:-)
            0
            1. pour le robot, je pense que c'est bon, mais je ne peux pas savoir si il va continuer à envoyer des msgs..et le reste c'est la lenteur de l'ordi, sa protection et ma messagerie hotmail qui est en chinois..
              0
              1. bon...
                heuu, tes soucis n°1 tu en es où ?
                0
                1. quelleslignes? le truc HP, c'est l'imprimante
                  0
                  1. Attends, merci de patienter ce n'est pas finis...
                    Ces lignes mentionnés m'intrigue...
                    0
                    1. C:\Program Files\HP\Smart Web Printing? Non ca ne me dit rien..
                      j'ai qqes petites questions si tu vx bien:
                      est ce que je dois enlever des logiciels pour que l'ordi aille plus vite?
                      est ce que l'ordi est bien protégé avec antirvir et zone alarm (ca suffit?)
                      et une dernière, est ce que je peux désinstaller puis reinstaller ma boite mail, sans perdre mon email? (parce sur ma messagerie hotmail, tout est écri en chinois et en pt d'interrogation..

                      Merci beaucoup beaucoup de ton aide !
                      0
                      1. ok, n'oublie pas de me dire si tu rencontres encore des problèmes concernant le robot/Mail
                        Ensuite : ceci te dit quelque chose =C:\Program Files\HP\Smart Web Printing?
                        Et concernant le fichier DLL tant que tu n'as plus les erreurs, c'est que c'est bon...
                        0
                        1. Salut;bon j'ai copié coller le fichier framedyn que j'ai téléchargé et je l'ai mis dans le dossier spybot..j'ai eu tort?

                          je te poste un scan de hijackthis:

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 18:01:37, on 06/01/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                          C:\Program Files\a-squared Free\a2service.exe
                          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                          C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                          C:\WINDOWS\System32\gearsec.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\wscntfy.exe
                          C:\Program Files\Apoint2K\Apoint.exe
                          C:\WINDOWS\AGRSMMSG.exe
                          C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\Program Files\Apoint2K\Apntex.exe
                          C:\Program Files\Picasa2\PicasaMediaDetector.exe
                          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                          C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
                          O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                          O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                          O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                          O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                          O4 - Global Startup: BTTray.lnk = ?
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                          O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                          O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                          O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                          O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - https://www.f-secure.com/en/home/support
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                          O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
                          O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://jeuxenligne.orange.fr/GameShell/online/fr/Diner_Dash/DinerDash.1.0.0.4.cab
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{9B041F39-8361-474E-B06C-1232F0ECAB7C}: NameServer = 80.10.246.1,80.10.246.132
                          O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                          O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                          O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                          O23 - Service: Service de sécurité matérielle (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
                          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          0
                          1. bon ok
                            Tu vas surfe sur cette page (traduite de l'anglais)
                            $>http://translate.google.com/...

                            je te recommande de bien lire =>Nous vous recommandons également de lire le tutoriel comment décompresser et installer les fichiers., ceci te permettra d'installer ta DLL Manquante...

                            Et pour la télécharger tu cliqueras là =>Cliquez ici pour accéder au téléchargement de framedyn.dll

                            Donne moi l'état de ton pc aussi !
                            attention ne fais pas de restauration système, sinon tu risquerai de faire revenir les virus....
                            0
                            1. alors, me re voilà..! j'ai fait ce que tu as dit mais évidemment, comme pour te contredire et me faire passer en meme temps pour un boulet..(:-) il n'y a pas le fameux framedyn.dll (que je commence à connaitre tellement il est chiant..) il y a entre les deux: forcedos, framd, framdit et freecell..dc je ne peux pas cliquer dessus...
                              ne m abandonne pas!! :-)
                              0
                              1. 1. Cliques sur Démarrer, puis sur Exécuter.
                                2. Dans la zone Ouvrir, tapes ou copier coller ça = %systemroot%\system32\dllcache, puis cliquez sur OK.
                                3. Cliques avec le bouton droit sur framedyn.dll, puis cliquez sur Copier dans le menu contextuel qui apparaît.
                                4. Cliques sur Démarrer, puis sur Exécuter.
                                5. Dans la zone Ouvrir, tapes ou fais un copier/coller de ça = %systemroot%\system32\wbem, puis cliquez sur OK.
                                6. Dans le menu Edition, cliques sur Coller. Si le système t'invite à remplacer le fichier existant, cliquez sur Oui.
                                Redémarres ta machine et tiens moi au courant...

                                Retour au début
                                0
                                1. ok
                                  tu as ton cd original d'xp (attention pas le recovery) ?
                                  0
                                  1. Rapport de F-Secure:

                                    Scanning Report
                                    Saturday, January 05, 2008 15:39:43 - 17:23:30
                                    Computer name: FRANKLIN
                                    Scanning type: Scan system for viruses, rootkits, spyware
                                    Target: C:\

                                    Result: 1 malware found
                                    Tracking Cookie (spyware)
                                    · System (Disinfected)

                                    Statistics
                                    Scanned:
                                    · Files: 37186
                                    · System: 4726
                                    · Not scanned: 3
                                    Actions:
                                    · Disinfected: 1
                                    · Renamed: 0
                                    · Deleted: 0
                                    · None: 0
                                    · Submitted: 0
                                    Files not scanned:
                                    · C:\HIBERFIL.SYS
                                    · C:\PAGEFILE.SYS
                                    · C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT

                                    Options
                                    Scanning engines:
                                    · F-Secure Libra: 2.4.2, 2008-01-04
                                    · F-Secure AVP: 7.0.171, 2008-01-04
                                    · F-Secure Orion: 1.2.37, 2008-01-04
                                    · F-Secure Blacklight: 1.0.64
                                    · F-Secure Draco: 1.0.35, 0597-150-72
                                    · F-Secure Pegasus: 1.19.0, 2007-11-31
                                    Scanning options:
                                    · Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB BAT LNK ANI AVB CEO CMD LSP MAP MHT MIF PDF PHP POT WMF NWS TAR TGZ WSF ZL? {* ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQXSWF
                                    · Use Advanced heuristics

                                    Copyright © 1998-2006 Product support |Send virus sample to F-Secure
                                    F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
                                    0
                                    1. je suis en train de faire celui de f secure..jte l envoie dès que c'est fini (et qd jserai revenue de la piscine..:) a tt
                                      0
                                      • 1
                                      • 2
                                      • 3