Spyware NTSB investigator...

Bonjour,
Voila, j'ai voulu telecharger un generaeur de clé pour Liberty Basic
sauf que qu'il se trouve que s'en etait pas un.
Un logiciel nommé NTSB investigator...... c'est ouvert et c'est installé trés vite sur ma becane.
Depuis, plus de wifi, plus de centre de securité actif, plus de logiciel entivirus, plus d'MSN (c'est un detaille je vous l'acorde), plus de fond d'ecran.
Alors voila, j'espere que vous pourrez m'aider, j'attend vos suggestions, vos commentaire, tout ce que vous voulez je suis un peu désesperé enfaite.
Configuration: Windows Vista Familial Premium SP1
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Suite à l’installation d’un prétendu générateur de clés pour Liberty Basic, la machine a été infectée par un logiciel nommé NTSB Investigator, entraînant la désactivation du Wi‑Fi, du pare-feu et de l’antivirus, et d’autres dysfonctionnements. Plusieurs conseils recommandent des outils de nettoyage et de suppression, notamment OTMoveIt3 pour déplacer des éléments problématiques et générer un rapport, puis CCleaner ou ToolsCleaner pour nettoyer les restes. D'autres évoquent la présence potentielle d'un rootkit et recommandent des mesures comme la désactivation temporaire de l'antivirus lors d’outils spécialisés et la réinstallation de programmes de sécurité. Des indications complémentaires indiquent que seule la connexion Ethernet subsistait, soulignant la nécessité d’un diagnostic approfondi et d’un rétablissement progressif de la configuration réseau actuelle.

Bobot (l’IA à votre service)
  1. lol

    t inKIete

    bonne soirée/semaine

    @+
    0
    1. Parcontre je ne suis pas inscrit alors si un modo pouvait mettre le sujet en resolue.
      Merci d'avance !!
      0
      1. Bon et bien merci beaucoup Chiquitine29
        Tu m'a etait d'une grande aide, et tu as etait trés performant.

        Je ferrais plus attention la prochaine fois lorsque je telechargeré un crack !
        (c'est la moral du sujet^^)
        0
        1. Je sais pas si c'est vrmeen necessaire, mais je copie le rapport tout de même.
          Mon Wifi remarche, je peu savoir ce que s'etait ?

          ----------------- FindyKill V4.706 ------------------

          * User : Evinrude - PC-DE-GUILLAUME
          * executed from : C:\Program Files\FindyKill
          * Update on 27/11/08 par Chiquitine29
          * Start at 21:00:58 the 01/12/2008
          * Windows Vista - Internet Explorer 7.0.6001.18000

          ((((((((((((((( *** deleting *** ))))))))))))))))))

          --------------- [ Active Processes ] ----------------

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\nvvsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\LogonUI.exe
          C:\Windows\system32\rundll32.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\System32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\lpksetup.exe
          C:\Windows\system32\agrsmsvc.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
          C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
          C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
          C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
          C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          C:\Windows\servicing\TrustedInstaller.exe
          C:\Windows\system32\DllHost.exe
          C:\Windows\system32\userinit.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
          C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
          C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
          C:\Windows\system32\DllHost.exe
          C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
          C:\Program Files\Samsung\Samsung Recovery Solution III\WCScheduler.exe
          C:\Windows\system32\runonce.exe
          C:\Windows\system32\conime.exe
          C:\Windows\system32\DllHost.exe

          --------------- [ Infected files / folders ] ----------------

          »»»» Supression files in C:

          »»»» Supression files in C:\Windows

          »»»» Supression files in C:\Windows\Prefetch

          Deleted ! - C:\Windows\prefetch\BW2PATCH1_1.EXE-7CDE0811.pf
          Deleted ! - C:\Windows\prefetch\BW2PATCH1_2.EXE-9033C296.pf
          Deleted ! - C:\Windows\prefetch\KEYGEN.EXE-24F125A4.pf

          »»»» Supression files in C:\Windows\system32

          »»»» Supression files in C:\Windows\system32\drivers

          »»»» Supression files in C:\Users\Evinrude\AppData\Roaming

          »»»» Supression files in C:\Users\Evinrude\AppData\Local\Temp

          »»»» Supression files in C:\Users\Evinrude\Local Settings\Temporary Internet Files\Content.IE5

          --------------- [ Registry / Infected keys ] ----------------

          Deleted ! - HKEY_USERS\S-1-5-21-876129911-1259334181-4154553057-1003\Software\Local AppWizard-Generated Applications\msnmsgr
          Deleted ! - HKEY_USERS\S-1-5-21-876129911-1259334181-4154553057-1003\Software\Local AppWizard-Generated Applications\winfilse

          --------------- [ States / Restarting of services ] ----------------

          +- Services : [ Auto=2 / Request=3 / Disable=4 ]

          Ndisuio - Type of startup = 3

          EapHost - Type of startup = 2

          Wlansvc - Type of startup = 2

          SharedAccess - Type of startup = 2

          wuauserv - Type of startup = 2

          wscsvc - Type of startup = 2

          WinDefend - Type of startup = 2

          --------------- [ Cleaning removable drives ] ----------------

          +- Informations :

          C: - Lecteur fixe
          D: - Lecteur fixe

          +- deleting files :

          --------------- [ Registry / Mountpoint2 ] ----------------

          -> Not found !

          --------------- [ Searching Cracks / Keygen ] ----------------

          ---------------- ! End of report ! ------------------
          0
          1. --> Fais clic droit sur le raccourci FindyKill sur ton bureau

            --> Choisi executer en tant qu administrateur

            --> Au menu principal,choisi l option 2 (Suppression)

            /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

            /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

            -------> ensuite post le rapport FindyKill.txt

            Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

            /!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides) /!\

            0
            1. ----------------- FindyKill V4.706 ------------------

              * User : Evinrude - PC-DE-GUILLAUME
              * Emplacement : C:\Program Files\FindyKill
              * Outils Mis a jours le 27/11/08 par Chiquitine29
              * Recherche effectuée à 20:53:32 le 01/12/2008
              * Windows Vista - Internet Explorer 7.0.6001.18000

              ((((((((((((((((( *** Recherche *** ))))))))))))))))))

              --------------- [ Processus actifs ] ----------------

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\nvvsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\rundll32.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\agrsmsvc.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Intel\WiFi\bin\EvtEng.exe
              C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
              C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
              C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
              C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
              C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
              C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
              C:\Program Files\Samsung\Samsung Recovery Solution III\WCScheduler.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Program Files\Internet Download Manager\IDMan.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Internet Download Manager\IEMonitor.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\program files\avira\antivir personaledition classic\avcenter.exe
              C:\Program Files\Windows Live\installer\WLSetupSvc.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Windows\system32\conime.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Windows\system32\WUDFHost.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe

              --------------- [ Fichiers/Dossiers infectieux ] ----------------

              »»»» Presence des fichiers dans C:

              »»»» Presence des fichiers dans C:\Windows

              »»»» Presence des fichiers dans C:\Windows\Prefetch

              Found ! - C:\Windows\Prefetch\KEYGEN.EXE-24F125A4.pf
              Found ! - C:\Windows\Prefetch\KEYGEN.EXE-24F125A4.pf
              Found ! - C:\Windows\Prefetch\BW2PATCH1_1.EXE-7CDE0811.pf
              Found ! - C:\Windows\Prefetch\BW2PATCH1_2.EXE-9033C296.pf

              »»»» Presence des fichiers dans C:\Windows\system32

              »»»» Presence des fichiers dans C:\Windows\system32\drivers

              »»»» Presence des fichiers dans C:\Users\Evinrude\AppData\Roaming

              »»»» Presence des fichiers dans C:\Users\Evinrude\AppData\Local\Temp

              »»»» Presence des fichiers dans C:\Users\Evinrude\Local Settings\Temporary Internet Files\Content.IE5

              --------------- [ Registre / Startup ] ----------------

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

              IDMan=C:\Program Files\Internet Download Manager\IDMan.exe /onboot
              Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

              SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
              <NO NAME>=
              HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
              Installed=1
              <NO NAME>=
              HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
              NoChange=1
              Installed=1
              <NO NAME>=
              HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
              Installed=1
              <NO NAME>=

              [HKEY_CURRENT_USER\software\local appwizard-generated applications\key_generator]
              [HKEY_CURRENT_USER\software\local appwizard-generated applications\msnmsgr]
              [HKEY_CURRENT_USER\software\local appwizard-generated applications\winfilse]

              --------------- [ Registre / Clés infectieuses ] ----------------

              Found ! - HKEY_USERS\S-1-5-21-876129911-1259334181-4154553057-1003\Software\Local AppWizard-Generated Applications\msnmsgr
              Found ! - HKEY_USERS\S-1-5-21-876129911-1259334181-4154553057-1003\Software\Local AppWizard-Generated Applications\winfilse
              Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr
              Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winfilse

              --------------- [ Etat / Services ] ----------------

              +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

              /!\ Ndisuio - Type de démarrage = 4

              EapHost - Type de démarrage = 3

              Wlansvc - Type de démarrage = 2

              SharedAccess - Type de démarrage = 2

              wuauserv - Type de démarrage = 2

              wscsvc - Type de démarrage = 2

              WinDefend - Type de démarrage = 2

              --------------- [ Recherche dans supports amovibles] ----------------

              +- Informations :

              C: - Lecteur fixe
              D: - Lecteur fixe
              G: - Lecteur amovible

              +- presence des fichiers :

              --------------- [ Registre / Mountpoint2 ] ----------------

              -> Not found !

              ------------------- ! Fin du rapport ! --------------------
              0
              1. oui c normal

                le mieux est de désactiver antivir le temps de son utilisation
                0
                1. Heu, ton Findykill, est bloquer par Antivir.

                  "Contains recognition pattern of the DR/Tool.PsKill.K.37 dropper.

                  Je fait quoi ? J'ignore ?
                  0
                  1. ( pour le parfeu, j'ai reussi à le reactivé "manuellement" )
                    0
                    1. ok

                      pour msn c est normal car ton infection (bagle) l a infecté

                      pour le reste :

                      Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                      - Vas dans "Démarrer" puis Panneau de configuration.
                      - Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
                      - Clique sur Continuer.
                      - Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
                      - Valide par OK et redémarre.

                      Telecharge maintenant FindyKill sur ton bureau :

                      --> Lance l installation avec les parametres par default

                      --> Fais un clic droit sur le raccourci FindyKill sur ton bureau

                      --> Choisi executer en tant qu administrateur

                      --> Au menu principal,choisi l option 1 (Recherche)

                      --> Post le rapport FindyKill.txt
                      0
                      1. News :

                        *Mon Wifi n'est plus dispo (j'arrive pas à le reactivé même avec le centre reseau et partage)
                        *Le Centre de sécurité n'a pas pu activer le Pare-feu Windows
                        *Pour réutilisé MSN, j'ai du le désinstallé et le réinstallé.
                        0
                        1. Bien, çà a l'air de fonctionné, encor merci,
                          parcontre subsiste le probleme de connection wifi.
                          Seul l'Ethernet fonctionne.
                          0
                          1. TOUT SIMPLEMENT car il est plus performant

                            http://forum.malekal.com/ftopic3528.php
                            0
                            1. Je redemare et je vous dit.

                              ps : deja merci d'avance...., et j'aimerai savoir pourquoi m'avoir fait telecharger Antivir plutot qu'Avast svp.
                              0
                              1. [ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

                                -->- Recherche:

                                C:\Combofix.txt: trouvé !
                                C:\Qoobox: trouvé !
                                C:\_OtMoveIt: trouvé !
                                C:\Program Files\Trend Micro\HijackThis: trouvé !
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                                C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
                                C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
                                C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
                                C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
                                C:\Users\Evinrude\Desktop\HijackThis.lnk: trouvé !
                                C:\Users\Evinrude\Desktop\ComboFix.exe: trouvé !
                                C:\Users\Evinrude\Desktop\HJTInstall.exe: trouvé !
                                C:\Users\Evinrude\Desktop\OTMoveIt3.exe: trouvé !

                                ---------------------------------
                                -->- Suppression:

                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
                                C:\Users\Evinrude\Desktop\HijackThis.lnk: supprimé !
                                C:\Users\Evinrude\Desktop\ComboFix.exe: supprimé !
                                C:\Users\Evinrude\Desktop\HJTInstall.exe: supprimé !
                                C:\Combofix.txt: supprimé !
                                C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
                                C:\Users\Evinrude\Desktop\OTMoveIt3.exe: supprimé !
                                C:\Qoobox: supprimé !
                                C:\_OtMoveIt: supprimé !
                                C:\Program Files\Trend Micro\HijackThis: supprimé !
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
                                0
                                1. Heu, Mccaffe, et une version d'essai de 60 jours.
                                  Je n'ai pas le CD d'installation.
                                  Je peu le desinstallé et en installé un autre peut étre ? (avast par exemple)
                                  0
                                  • 1
                                  • 2