Virus "about.Brontok.A"

Bonjour,
j'ai le virus about.Brontok.A qui me soule !!!
voici les symptomes :
- lancement de vista a l'aide du "gestionnaire de tache", faut que je tape explorer.exe
- telechargement impossible, l'ordi redemarre seul
- dans le dossier msconfig, il y a : "Bron-Spizaetus", "Tok-cirhatus-2058", "empty" qui sont cocher pour le démarrage et qui revient a chaque fois meme en les décochant.
- dans mon dossier Image il y a le fameux "about.Brontok.A"

j'ai eu ce probleme a partir du moment ou j'ai mis une clef USB dans mon ordi. 1 jour apres ca a commencer les problemes.

C'est grave docteur ?

je suis entrain de faire un rapport BITdefender en ligne. est ce deja une bonne initiative ?
Configuration: Windows Vista
Internet Explorer 7.0

72 réponses

Résumé de la discussion

La discussion porte sur une infection par about.Brontok.A sur Windows Vista, avec des symptômes tels que redémarrage fréquent, impossibilité de télécharger et des entrées récurrentes Bron-Spizaetus et Tok-Cirrhatus-2058 dans le démarrage. Plusieurs solutions recommandent de déconnecter l'Internet et les accès physiques, d'utiliser des outils de désinfection comme CleanX-II de sUBs ou PCA Sécurité Evosla, puis d'analyser les rapports et relancer si nécessaire. Des étapes complémentaires recommandent de désactiver puis réactiver la restauration système, d’appliquer des correctifs sur les démarrages via les outils recommandés et de lire les rapports post-run afin de cibler les fichiers infectés. En cas d’échec prolongé, la consultation d’autres outils et la comparaison des rapports détaillés restent préconisées pour adapter la désinfection au contexte matériel et logiciel.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour à tous,

    j'ai l'impression que le premier outil anti brontok n'a pas suffit.

    Le meilleur outil que je connaisse est Clean XII de sUBs :

    Galomert, si la dernière manip de jlpjlp ne donne rien, essaye ça

    Télécharge CleanX-II de sUBs (merci mOe) ici :

    http://download.bleepingcomputer.com/sUBs/CleanX-II.exe

    Déconnecte tes accès internet. Coupe tous les accès physiques (débranchement du modem, ...).
    Ferme toutes les applications.
    Désactive puis réactive ta restauration système.
    Clic droit sur CleanX-II.exe et "exécuter en mode administrateur" pour démarrer la réparation (UAC désactivée).
    Clique OK lorsque tu reçois un message d'avertissement.
    A la fin du scan (qui peut prendre plusieurs minutes, patiente le temps qu'il finisse), il va produire un message d'erreur (parce que l'outil ne prend pas en compte la copie pour un Windows français). Pour contourner cette erreur, fais ceci :
    Démarrer, exécuter et tape %temp%\report.txt . Le bloc-note va ouvrir le rapport.

    Si ce rapport montre qu'il reste encore des fichiers infectés (en fin de rapport après "POST RUN ANALYSIS"), relance l'outil une nouvelle fois.
    Ouvre à nouveau le rapport avec la méthode ci-dessus et copie le dans ta réponse. S'il reste encore des fichiers infectés, inutile de relancer encore l'outil. Il faut examiner le rapport.

    Si le .exe échoue, j'ai encore un outil sous le coude. Mais il faudra que tu donnes le nom de toutes les sessions existantes sur l'ordi.
    2
    1. bonsoir

      oui cest deja bien revient sur le forum posté le résulat
      0
      1. Contributeur sécurité
        slt,

        scan avec ceci: specialement concu par bitdefender pour brontok A

        https://www.bitdefender.fr/premium-services/virus-and-spyware-removal.html
        ___________________

        puis par rapport a ta clé:

        1/ # Télécharge RavAntivirus d'Evosla :
        http://ww25.evosla.com/compteur.php?soft=rav_antivirus

        # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
        # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
        # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
        # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
        # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
        # Retire tes disques amovibles et redémarrez votre ordinateur.
        # Poste le rapport, si infection!

        2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe

        Double-clique sur l’icône.
        Les icônes vont disparaître. C’est normal.
        Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
        Redémarre ensuite le PC.

        ____________________

        puis pour verifier:

        colle un rapport hijackthis

        http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

        manuel :
        http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
        https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

        Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

        ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

        Ensuite avec Explorer créer un dossier c:\hijackthis
        Décompresser Hijackthis dans ce dossier.
        C'est important pour les sauvegardes."
        0
        1. ok je scan avec votre lien merci de repondre si rapidement ! vous gerez ! je poste mon scan des que ca fini
          0
          1. jlpjlp, votre lien me ramene a un outil de suppression. lorsque je clik dessu ca me ramene a une page de telechargement du logiciel bitdeffender.
            0
            1. c'est normal que le test dure depuis 5 H maintenant et ets toujours pas fini ??? "
              0
              1. Contributeur sécurité
                si ton disque est plein cela peut etre normal
                sinon essaye de refaire le scan en mode sans echec (demarraer l'ordi en appuyant plusisuers fois sur F8 en général)

                puis

                puis par rapport a ta clé:

                1/ # Télécharge RavAntivirus d'Evosla :
                http://ww25.evosla.com/compteur.php?soft=rav_antivirus

                # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
                # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
                # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
                # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
                # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
                # Retire tes disques amovibles et redémarrez votre ordinateur.
                # Poste le rapport, si infection!

                2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfec­tor.exe

                Double-clique sur l’icône.
                Les icônes vont disparaître. C’est normal.
                Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
                Redémarre ensuite le PC.

                ____________________

                puis pour verifier:

                colle un rapport hijackthis

                http://www.trendsecure.com/portal/en-US/tools/security_tools­/hijackthis/download

                manuel :
                http://pagesperso-orange.fr/rginformatique/section%20virus/d­emohijack.htm
                http://leblogdeclaude.blogspot.com/2006/10/informatique-sect­ion-hijackthis.html

                Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

                ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

                Ensuite avec Explorer créer un dossier c:\hijackthis
                Décompresser Hijackthis dans ce dossier.
                C'est important pour les sauvegardes."
                0
                1. voici le rapport bitdefendert je doi faire quoi ?

                  BitDefender Online Scanner

                  Scan report generated at: Tue, Jul 22, 2008 - 04:59:31

                  Scan path: C:\;D:\;F:\;

                  Statistics

                  Time
                  01:24:16

                  Files
                  269432

                  Folders
                  17429

                  Boot Sectors
                  3

                  Archives
                  4288

                  Packed Files
                  22681

                  Results

                  Identified Viruses
                  2

                  Infected Files
                  16

                  Suspect Files
                  0

                  Warnings
                  0

                  Disinfected
                  0

                  Deleted Files
                  13

                  Engines Info

                  Virus Definitions
                  1382391

                  Engine build
                  AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

                  Scan plugins
                  16

                  Archive plugins
                  43

                  Unpack plugins
                  7

                  E-mail plugins
                  6

                  System plugins
                  5

                  Scan Settings

                  First Action
                  Disinfect

                  Second Action
                  Delete

                  Heuristics
                  Yes

                  Enable Warnings
                  Yes

                  Scanned Extensions
                  *;

                  Exclude Extensions

                  Scan Emails
                  Yes

                  Scan Archives
                  Yes

                  Scan Packed
                  Yes

                  Scan Files
                  Yes

                  Scan Boot
                  Yes

                  Scanned File
                  Status

                  C:\Users\Corrado\AppData\Local\br5139on.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\AppData\Local\br5139on.exe
                  Deleted

                  C:\Users\Corrado\AppData\Local\csrss.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\AppData\Local\csrss.exe
                  Deleted

                  C:\Users\Corrado\AppData\Local\inetinfo.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\AppData\Local\inetinfo.exe
                  Deleted

                  C:\Users\Corrado\AppData\Local\lsass.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\AppData\Local\lsass.exe
                  Disinfection failed

                  C:\Users\Corrado\AppData\Local\lsass.exe
                  Delete failed

                  C:\Users\Corrado\AppData\Local\services.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\AppData\Local\services.exe
                  Disinfection failed

                  C:\Users\Corrado\AppData\Local\services.exe
                  Delete failed

                  C:\Users\Corrado\AppData\Local\smss.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\AppData\Local\smss.exe
                  Deleted

                  C:\Users\Corrado\AppData\Local\svchost.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\AppData\Local\svchost.exe
                  Deleted

                  C:\Users\Corrado\AppData\Local\winlogon.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\AppData\Local\winlogon.exe
                  Disinfection failed

                  C:\Users\Corrado\AppData\Local\winlogon.exe
                  Delete failed

                  C:\Users\Corrado\Documents\Documents.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\Documents\Documents.exe
                  Deleted

                  C:\Users\Corrado\Documents\My Music\CDDB\CDDB.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\Documents\My Music\CDDB\CDDB.exe
                  Deleted

                  C:\Users\Corrado\Documents\My Music\CDDB\misc\misc.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\Documents\My Music\CDDB\misc\misc.exe
                  Deleted

                  C:\Users\Corrado\Documents\My Music\CDDB\Status\Status.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Users\Corrado\Documents\My Music\CDDB\Status\Status.exe
                  Deleted

                  C:\Users\Corrado\Pictures\about.Brontok.A.html
                  Infected with: Worm.Brontok.HTML.A

                  C:\Users\Corrado\Pictures\about.Brontok.A.html
                  Disinfection failed

                  C:\Users\Corrado\Pictures\about.Brontok.A.html
                  Deleted

                  C:\Windows\KesenjanganSosial.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Windows\KesenjanganSosial.exe
                  Deleted

                  C:\Windows\ShellNew\RakyatKelaparan.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Windows\ShellNew\RakyatKelaparan.exe
                  Deleted

                  C:\Windows\System32\cmd-brontok.exe
                  Infected with: Backdoor.Hupigon.ADI

                  C:\Windows\System32\cmd-brontok.exe
                  Deleted
                  0
                  1. Contributeur sécurité
                    1/ # Télécharge RavAntivirus d'Evosla :
                    http://ww25.evosla.com/compteur.php?soft=rav_antivirus

                    # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
                    # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
                    # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
                    # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
                    # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
                    # Retire tes disques amovibles et redémarrez votre ordinateur.
                    # Poste le rapport, si infection!

                    2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfec­­tor.exe

                    Double-clique sur l’icône.
                    Les icônes vont disparaître. C’est normal.
                    Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
                    Redémarre ensuite le PC.

                    ____________________

                    puis pour verifier:

                    colle un rapport hijackthis

                    http://www.trendsecure.com/portal/en-US/tools/security_tools­­/hijackthis/download

                    manuel :
                    http://pagesperso-orange.fr/rginformatique/section%20virus/d­­emohijack.htm
                    http://leblogdeclaude.blogspot.com/2006/10/informatique-sect­­ion-hijackthis.html

                    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

                    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

                    Ensuite avec Explorer créer un dossier c:\hijackthis
                    Décompresser Hijackthis dans ce dossier.
                    C'est important pour les sauvegardes."
                    0
                    1. L'antivirus Esiolva m'a supprimer 4 virus (autorun principalement) et a la fin du test il ma marqué qu emon rdi est sain mais pas de log.

                      pour Flash_Disinfector, je le demarre, les icones partent et ensuite il y a une fenetre ou il y a marqué "Done!!!", pas de log non plus. par contre j'ai été obliger, pour réafficher mon bureau a le faire a partir du "gestionnaire"-"nouvelle tache"-"explorer.exe" est ce normal ?

                      je fais un hijactis ?
                      0
                      1. le moindre liens en rapport avec hijactis, mon ordi redemarre seul lorsque je clique. j'ai toujours le meme probleme de demarrag de mon pc (obliger de passer par le gestionnaire - nouvelle tache - explorer.exe.

                        je vais telecharger hijactis sur un autre pc, je fais un test et je le poste merci
                        0
                        1. je poste le rapport demain apres car je bosse demain matin
                          0
                          1. Contributeur sécurité
                            bonsoir vous deux ;

                            pour suivre .....
                            0
                            1. j'ai telecharger hijactis mais mon orid ne veut pas l'installer. il redemmare des que je veux cliker sur suivant. j'ai commencer un examen avec Malwarebytes'. je le poste des que c fini. j'ai deja 17 clef registre infecter ! a toute !!
                              0
                              1. Voici le rapport de Malwarebytes que dois je faire ensuite ? je ne peut pas installer hijactis ! mon ordi y veut pas ce con !

                                Malwarebytes' Anti-Malware 1.22
                                Version de la base de données: 982
                                Windows 6.0.6001 Service Pack 1

                                22:06:19 23/07/2008
                                mbam-log-7-23-2008 (22-06-09).txt

                                Type de recherche: Examen complet (C:\|D:\|)
                                Eléments examinés: 121121
                                Temps écoulé: 2 hour(s), 8 minute(s), 25 second(s)

                                Processus mémoire infecté(s): 0
                                Module(s) mémoire infecté(s): 0
                                Clé(s) du Registre infectée(s): 24
                                Valeur(s) du Registre infectée(s): 4
                                Elément(s) de données du Registre infecté(s): 1
                                Dossier(s) infecté(s): 1
                                Fichier(s) infecté(s): 69

                                Processus mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Module(s) mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Clé(s) du Registre infectée(s):
                                HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CLASSES_ROOT\Interface\{4e493e24-27f2-4749-8f73-5e775a238ee3} (Trojan.FakeAlert) -> No action taken.
                                HKEY_CLASSES_ROOT\Interface\{f4626dc1-0af5-433a-a016-9b9c35d5d405} (Trojan.FakeAlert) -> No action taken.
                                HKEY_CLASSES_ROOT\Typelib\{40ca3d09-9abb-4038-967e-7b2933168902} (Trojan.FakeAlert) -> No action taken.
                                HKEY_CLASSES_ROOT\Interface\{480b1a9b-6ac6-43d9-a6ef-4a9410f74426} (Trojan.FakeAlert) -> No action taken.
                                HKEY_CLASSES_ROOT\wxdbpfvo.btbv (Trojan.FakeAlert) -> No action taken.
                                HKEY_CLASSES_ROOT\wxdbpfvo.toolbar.1 (Trojan.FakeAlert) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\dpcproxy (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\uninstall (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\Classes\applications\accessdiver.exe (Trojan.FakeAlert) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\fwbd (Trojan.FakeAlert) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\HolLol (Trojan.FakeAlert) -> No action taken.
                                HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> No action taken.

                                Valeur(s) du Registre infectée(s):
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{0656a137-b161-cadd-9777-e37a75727e78} (Fake.Dropped.Malware) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> No action taken.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{e1b2b64b-e123-4a7a-98d7-c51065df3249} (Trojan.FakeAlert) -> No action taken.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> No action taken.

                                Elément(s) de données du Registre infecté(s):
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> No action taken.

                                Dossier(s) infecté(s):
                                C:\Windows\System32\smp (Fake.Dropped.Malware) -> No action taken.

                                Fichier(s) infecté(s):
                                C:\Windows\gndarmblaor.dll (Trojan.FakeAlert) -> No action taken.
                                C:\Program Files\Sony\Sony.ACID.Pro.v6.0.Incl.Keygen-SSG\keygen.exe (Trojan.Downloader) -> No action taken.
                                C:\Windows\xbaqktfv.exe (Trojan.FakeAlert) -> No action taken.
                                C:\Windows\System32\kjshsvsr.exe (Trojan.FakeAlert) -> No action taken.
                                C:\Windows\System32\smp\msrc.exe (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\a.bat (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\base64.tmp (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\FVProtect.exe (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\userconfig9x.dll (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\winsystem.exe (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\zip1.tmp (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\zip2.tmp (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\zip3.tmp (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\zipped.tmp (Fake.Dropped.Malware) -> No action taken.
                                C:\Windows\bdn.com (Trojan.Agent) -> No action taken.
                                C:\Windows\iTunesMusic.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\mssecu.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\akttzn.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\anticipator.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\awtoolb.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\bdn.com (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\bsva-egihsg52.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\dpcproxy.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\hoproxy.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\hxiwlgpm.dat (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\hxiwlgpm.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\msgp.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\msnbho.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\mssecu.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\msvchost.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\mtr2.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\mwin32.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\netode.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\newsd32.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\ps1.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\psof1.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\psoft1.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\regc64.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\regm64.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\Rundl1.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\sncntr.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\ssurf022.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\ssvchost.com (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\ssvchost.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\sysreq.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\taack.dat (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\taack.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\temp#01.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\thun.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\thun32.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\VBIEWER.OCX (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\vcatchpi.dll (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\winlogonpc.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\winsystem.exe (Trojan.Agent) -> No action taken.
                                C:\Windows\System32\WINWGPX.EXE (Trojan.Agent) -> No action taken.
                                C:\Windows\rs.txt (Malware.Trace) -> No action taken.
                                C:\Windows\System32\vbsys2.dll (Trojan.Clicker) -> No action taken.
                                C:\Users\Corrado\Local Settings\csrss.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\Application Data\csrss.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\lsass.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\Application Data\lsass.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\services.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\Application Data\services.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\smss.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\Application Data\smss.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\svchost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\Application Data\svchost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                C:\Users\Corrado\Local Settings\Application Data\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
                                0
                                1. Contributeur sécurité
                                  Télécharge MSNFix de Laurent
                                  http://sosvirus.changelog.fr/MSNFix.zip

                                  Décompresse-le et double clic sur le fichier MSNFix.bat.
                                  - Exécute l'option R.
                                  --Si l'infection est détectée, exécute l'option N
                                  - Sauvegarde ce rapport puis fais un copier/coller de ce rapport sur le forum.

                                  Note :
                                  Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
                                  Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.

                                  envoyer le fichier [b] C:\DOCUME~1\florian\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr pour faire evoluer msnfix

                                  _________________

                                  télécharge combofix (par sUBs) ici :

                                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                  et enregistre le sur le bureau.

                                  déconnecte toi d'internet et ferme toutes tes applications.

                                  désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                                  double-clique sur combofix.exe et suis les instructions

                                  à la fin, il va produire un rapport C:\ComboFix.txt

                                  réactive ton parefeu, ton antivirus, la garde de ton antispyware

                                  copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

                                  Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                                  Tu as un tutoriel complet ici :

                                  https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                                  0
                                  1. je n epeut pas telecharger combofix (par sUBs). l'ordi redemarre des que le downlaod commence (comme avec hiactis) je vais esseyé de le telecharger sur un autre PC.
                                    0
                                    • 1
                                    • 2
                                    • 3
                                    • 4