Scan Antivir : "TR/Crypt.XPACK.Gen Trojan&quo

anonime -  
nihat42 Messages postés 307 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour,
Je suis infecté, le scan de Antivir detecte "TR/Crypt.XPACK.Gen Trojan"
Et il y en a peut être d'autres...

S'il y a une âme charitable qui peut m'aider?

J'ai télécharger HiJackThis et voici le resultat:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:11:27, on 23/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\windows\Explorer.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\windows\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\windows\system32\PnkBstrB.exe
C:\windows\system32\slserv.exe
C:\windows\system32\svchost.exe
C:\windows\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\RamBooster\Rambooster.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\windows\System32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\paul\Bureau\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster\Rambooster.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\windows\system32\PnkBstrB.exe
O23 - Service: SmartLinkService (SLService) - - C:\windows\SYSTEM32\slserv.exe

--
End of file - 5045 bytes
Configuration: Windows XP
Internet Explorer 7.0

4 réponses

  1. nihat42 Messages postés 307 Date d'inscription   Statut Membre Dernière intervention   42
     
    Télécharge Malwarebytes' Anti-Malware (MBAM)
    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    * Double clique sur le fichier téléchargé pour lancer le processus d'installation.
    * Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour": si le pare-feu demande l'autorisation à MBAM de se connecter, accepte.
    * Une fois la mise à jour terminée, rends-toi dans l'onglet "Recherche".
    * Sélectionne "Exécuter un examen rapide"
    * Clique sur "Rechercher"
    * L'analyse démarre, le scan est relativement long, c'est normal.
    * A la fin de l'analyse, un message s'affiche :

    L'examen s'est terminé normalement. Clique sur 'Afficher les résultats' pour afficher tous les objets trouvés.

    Clique sur "Ok" pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
    * Ferme tes navigateurs.
    * Si des malwares ont été détectés, clique sur Afficher les résultats.
    Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    * MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport et poste-le dans ta prochaine réponse.
    0
    1. anonime
       
      Ah j'ai oublié de dire que je n'arrive plus à faire de mise à jour sur antivir et
      je n'arrive pas non plus pour mbam !
      Ce n'est pas le pare feu car je viens de faire les mises à jour sur mon 2eme ordinateur et
      ça fonctionnent.
      0
      1. anonime > anonime
         
        J'ai essayé de réinstaller mbam, rien n'y fait, impossible de faire la mise à jour!
        J'ai réinstallé aussi mozilla Firefox car je pense que c'est depuis que j'ai télécharger le plug in
        firebug que ça déconne.

        En attendant je te met le rapport de Antivir:



        Avira AntiVir Personal
        Report file date: lundi 23 février 2009 16:06

        Scanning for 1262312 virus strains and unwanted programs.

        Licensed to: Avira AntiVir PersonalEdition Classic
        Serial number: 0000149996-ADJIE-0001
        Platform: Windows XP
        Windows version: (Service Pack 2) [5.1.2600]
        Boot mode: Normally booted
        Username: SYSTEM
        Computer name: MAJESTY

        Version information:
        BUILD.DAT : 8.2.0.337 16934 Bytes 18/11/2008 13:05:00
        AVSCAN.EXE : 8.1.4.10 315649 Bytes 18/11/2008 08:21:26
        AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
        LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
        LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
        ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:29:38
        ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 19:32:40
        ANTIVIR2.VDF : 7.1.2.55 248832 Bytes 20/02/2009 16:08:46
        ANTIVIR3.VDF : 7.1.2.67 61440 Bytes 23/02/2009 13:09:18
        Engineversion : 8.2.0.87
        AEVDF.DLL : 8.1.1.0 106868 Bytes 30/01/2009 15:56:18
        AESCRIPT.DLL : 8.1.1.47 348539 Bytes 13/02/2009 11:49:24
        AESCN.DLL : 8.1.1.7 127347 Bytes 13/02/2009 11:49:24
        AERDL.DLL : 8.1.1.3 438645 Bytes 05/11/2008 07:43:26
        AEPACK.DLL : 8.1.3.8 397684 Bytes 04/02/2009 16:11:32
        AEOFFICE.DLL : 8.1.0.33 196987 Bytes 11/12/2008 14:54:10
        AEHEUR.DLL : 8.1.0.97 1610103 Bytes 20/02/2009 16:09:28
        AEHELP.DLL : 8.1.2.0 119159 Bytes 18/11/2008 16:06:00
        AEGEN.DLL : 8.1.1.20 336245 Bytes 20/02/2009 16:09:28
        AEEMU.DLL : 8.1.0.9 393588 Bytes 15/10/2008 10:49:36
        AECORE.DLL : 8.1.6.6 176501 Bytes 17/02/2009 16:00:12
        AEBB.DLL : 8.1.0.3 53618 Bytes 15/10/2008 10:49:34
        AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
        AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
        AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 12:02:15
        AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
        AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
        AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
        SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
        SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
        NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
        RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
        RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

        Configuration settings for the scan:
        Jobname..........................: Complete system scan
        Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
        Logging..........................: low
        Primary action...................: interactive
        Secondary action.................: ignore
        Scan master boot sector..........: on
        Scan boot sector.................: on
        Boot sectors.....................: C:, D:, E:,
        Process scan.....................: on
        Scan registry....................: on
        Search for rootkits..............: off
        Scan all files...................: Intelligent file selection
        Scan archives....................: on
        Recursion depth..................: 20
        Smart extensions.................: on
        Macro heuristic..................: on
        File heuristic...................: medium

        Start of the scan: lundi 23 février 2009 16:06

        The scan of running processes will be started
        Scan process 'avscan.exe' - '1' Module(s) have been scanned
        Scan process 'avguard.exe' - '1' Module(s) have been scanned
        Scan process 'avcenter.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
        Scan process 'Rambooster.exe' - '1' Module(s) have been scanned
        Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
        Scan process 'avgnt.exe' - '1' Module(s) have been scanned
        Scan process 'alg.exe' - '1' Module(s) have been scanned
        Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
        Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'slserv.exe' - '1' Module(s) have been scanned
        Scan process 'PnkBstrB.exe' - '1' Module(s) have been scanned
        Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
        Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
        Scan process 'jqs.exe' - '1' Module(s) have been scanned
        Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
        Scan process 'explorer.exe' - '1' Module(s) have been scanned
        Scan process 'wbload.exe' - '1' Module(s) have been scanned
        Scan process 'sched.exe' - '1' Module(s) have been scanned
        Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'lsass.exe' - '1' Module(s) have been scanned
        Scan process 'services.exe' - '1' Module(s) have been scanned
        Scan process 'winlogon.exe' - '1' Module(s) have been scanned
        Scan process 'csrss.exe' - '1' Module(s) have been scanned
        Scan process 'smss.exe' - '1' Module(s) have been scanned
        32 processes with 32 modules were scanned

        Starting master boot sector scan:
        Master boot sector HD0
        [INFO] No virus was found!
        Master boot sector HD1
        [INFO] No virus was found!
        Master boot sector HD2
        [INFO] No virus was found!
        [WARNING] System error [87]: Paramètre incorrect.

        Start scanning boot sectors:
        Boot sector 'C:\'
        [INFO] No virus was found!
        Boot sector 'D:\'
        [INFO] No virus was found!
        Boot sector 'E:\'
        [INFO] No virus was found!

        Starting to scan the registry.
        The registry was scanned ( '50' files ).


        Starting the file scan:

        Begin scan in 'C:\'
        C:\pagefile.sys
        [WARNING] The file could not be opened!
        C:\Program Files\Mozilla Firefox\components\iamfamous.dll
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
        [NOTE] The file was moved to '4a0fc71f.qua'!
        C:\WINDOWS\system32\drivers\atapi.sys
        [WARNING] The file could not be opened!
        Begin scan in 'D:\' <data>
        Begin scan in 'E:\'


        End of the scan: lundi 23 février 2009 17:13
        Used time: 1:06:35 Hour(s)

        The scan has been done completely.

        9003 Scanning directories
        256654 Files were scanned
        1 viruses and/or unwanted programs were found
        0 Files were classified as suspicious:
        0 files were deleted
        0 files were repaired
        1 files were moved to quarantine
        0 files were renamed
        2 Files cannot be scanned
        256651 Files not concerned
        1637 Archives were scanned
        3 Warnings
        1 Notes



        merci
        0
  2. anonime
     
    Je te laisse aussi le rapport mbam sans la mise à jour:

    Malwarebytes' Anti-Malware 1.34
    Version de la base de données: 1749
    Windows 5.1.2600 Service Pack 2

    23/02/2009 21:32:48
    mbam-log-2009-02-23 (21-32-48).txt

    Type de recherche: Examen rapide
    Eléments examinés: 58375
    Temps écoulé: 2 minute(s), 12 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 3
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c80b7ff6-ce60-4079-935e-520c045c30a6} (Adware.EGDAccess) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\coolplay (Trojan.DNSChanger) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
  3. anonime
     
    Plus la peine de pas m'aider, quelqu'un d'autre l'a fait!

    merci quand même
    0
  4. nihat42 Messages postés 307 Date d'inscription   Statut Membre Dernière intervention   42
     
    Supprime le dossier d'Hijackthis.
    0