Virus anti Antivirus

Fermé
TomSmash - 7 sept. 2009 à 23:19
XaTon Messages postés 2041 Date d'inscription lundi 6 juillet 2009 Statut Membre Dernière intervention 22 janvier 2015 - 7 sept. 2009 à 23:21
Bonjour,

Après avoir lu la majorité des discussions sur le forum traitant des problèmes de virus bloquant l'accès aux sites des antivirus, je poste ce message car je ne suis pas arrivé à régler mon problème.
J'ai testé en mode sans échec ToolBarSD+GenProc et SDFix ainsi que ComboFix (pas mode sans échec) + CCleaner systématiquement, qui n'ont pas résolu mon problème (la page urlseek s'affichait dès que je voulais atteindre les sites des antivirus...et maintenant ne s'affiche plus que la page Serveur Introuvable)
J'écris ce message pour essayer de résoudre mon problème personnelle.
J'ai les rapports Hijackthis, ComboFix et SDFix.
Merci pour l'aide que vous pourrez m'apporter (sKe69...je suis sûr que tu peux bien m'aider!)

TomSmash


Voici le rapport de ComboFix:

ComboFix 09-09-06.06 - Administrateur 07/09/2009 22:40.1.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.759.273 [GMT 2:00]
Running from: c:\documents and settings\Administrateur\Bureau\Logiciels\Setup\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
c:\program files\SuperCopier2\SC2Hook.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\pdfforge Toolbar\SearchSettings.dll
c:\windows\system32\msconfig.exe
c:\windows\system32\oem4.inf

.
((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.

2009-09-07 20:13 . 2009-09-07 20:13 -------- d-----w- c:\windows\system32\wbem\snmp
2009-09-07 20:13 . 2009-09-07 20:13 -------- d-----w- c:\windows\srchasst
2009-09-07 20:13 . 2009-09-07 20:13 -------- d-----w- c:\windows\system32\xircom
2009-09-07 20:13 . 2009-09-07 20:13 -------- d-----w- c:\program files\microsoft frontpage
2009-09-07 20:11 . 2009-09-07 20:11 579584 ----a-w- c:\windows\system32\dllcache\user32.dll
2009-09-07 20:09 . 2009-09-07 20:09 -------- d-----w- c:\windows\ERUNT
2009-09-07 20:04 . 2009-09-07 20:16 -------- d-----w- C:\SDFix
2009-09-07 19:23 . 2009-09-07 19:23 -------- d-----w- C:\GenProc
2009-09-07 19:23 . 2009-09-07 19:37 -------- d-----w- C:\ToolBar SD
2009-08-28 15:21 . 2009-08-28 15:21 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\PCHealth
2009-08-11 09:49 . 2009-08-11 09:49 -------- d-----w- c:\documents and settings\Administrateur\Application Data\FireShot
2009-08-09 09:21 . 2009-08-09 09:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Skyline
2009-08-09 09:21 . 2009-08-09 09:21 -------- d-----w- c:\program files\Skyline

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-07 20:42 . 2009-07-16 08:21 -------- d-----w- c:\program files\pdfforge Toolbar
2009-09-07 20:39 . 2009-07-09 20:55 -------- d-----w- c:\program files\SuperCopier2
2009-09-07 20:17 . 2009-07-07 16:14 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Dropbox
2009-09-07 19:44 . 2001-08-28 18:00 80246 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-07 19:44 . 2001-08-28 18:00 478066 ----a-w- c:\windows\system32\perfh00C.dat
2009-09-07 19:15 . 2009-07-24 12:13 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-09-07 16:07 . 2009-07-23 20:58 -------- d-----w- c:\program files\Mozilla Sunbird
2009-09-03 17:31 . 2009-07-16 12:41 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Skype
2009-09-03 14:00 . 2009-07-16 13:09 -------- d-----w- c:\documents and settings\Administrateur\Application Data\skypePM
2009-09-01 07:52 . 2009-07-19 12:16 -------- d-----w- c:\documents and settings\Administrateur\Application Data\vlc
2009-08-10 06:30 . 2009-07-07 19:28 72640 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-08 13:03 . 2009-08-07 20:13 -------- d-----w- c:\program files\OpenOffice.org 3
2009-08-07 20:20 . 2009-08-07 20:20 -------- d-----w- c:\documents and settings\Administrateur\Application Data\OpenOffice.org
2009-08-07 20:15 . 2009-08-07 20:15 -------- d-----w- c:\program files\JRE
2009-08-07 20:12 . 2009-08-07 20:13 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-08-07 20:12 . 2009-08-07 20:12 -------- d-----w- c:\program files\Java
2009-08-04 20:23 . 2009-07-09 19:38 -------- d-----w- c:\documents and settings\Administrateur\Application Data\VoipBuster
2009-08-04 16:46 . 2009-08-04 16:46 -------- d-----w- c:\documents and settings\Tom\Application Data\pdfforge
2009-08-04 08:48 . 2009-08-04 08:48 -------- d-----w- c:\documents and settings\All Users\Application Data\ThumbnailCache4R
2009-08-04 08:12 . 2009-08-04 08:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Lexmark 3600-4600 Series
2009-08-03 19:52 . 2009-08-03 19:52 -------- d-----w- c:\program files\Fichiers communs\Vbox
2009-08-03 19:52 . 2009-07-16 08:21 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-08-03 19:51 . 2009-07-07 15:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-28 10:21 . 2009-07-07 16:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-24 12:14 . 2009-07-24 12:14 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Thunderbird
2009-07-23 21:00 . 2009-07-23 21:00 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Talkback
2009-07-20 16:10 . 2009-07-20 16:09 -------- d-----w- c:\program files\Google
2009-07-19 18:15 . 2009-07-08 00:32 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Apple Computer
2009-07-19 18:07 . 2009-07-19 18:06 -------- d-----w- c:\program files\iTunes
2009-07-19 18:07 . 2009-07-19 18:06 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-19 18:06 . 2009-07-19 18:06 -------- d-----w- c:\program files\iPod
2009-07-19 18:06 . 2009-07-19 18:05 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-07-19 18:06 . 2009-07-08 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-19 18:06 . 2009-07-19 18:06 -------- d-----w- c:\program files\Bonjour
2009-07-19 14:30 . 2009-07-19 14:29 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Media Player Classic
2009-07-19 12:17 . 2009-07-19 12:17 -------- d-----w- c:\documents and settings\Administrateur\Application Data\dvdcss
2009-07-19 12:13 . 2009-07-19 12:13 -------- d-----w- c:\program files\VideoLAN
2009-07-18 13:02 . 2009-07-18 13:02 0 ----a-w- c:\windows\nsreg.dat
2009-07-18 11:27 . 2009-07-18 11:03 -------- d-----w- c:\program files\UsbFix
2009-07-18 10:52 . 2009-07-18 10:52 -------- d-----w- c:\program files\CCleaner
2009-07-16 13:09 . 2009-07-16 13:09 48 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-07-16 12:38 . 2009-07-16 12:38 -------- d-----r- c:\program files\Skype
2009-07-16 12:38 . 2009-07-16 12:38 -------- d-----w- c:\program files\Fichiers communs\Skype
2009-07-16 12:38 . 2009-07-16 12:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-16 10:35 . 2009-07-16 10:35 -------- d-----w- c:\program files\USB Driver-Express
2009-07-16 08:58 . 2009-07-16 08:58 -------- d-----w- c:\documents and settings\Administrateur\Application Data\pdfforge
2009-07-16 08:21 . 2009-07-16 08:19 -------- d-----w- c:\program files\PDFCreator
2009-07-16 08:20 . 2009-07-16 08:20 137 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\fusioncache.dat
2009-07-09 20:57 . 2009-07-09 20:51 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Winamp
2009-07-09 20:52 . 2009-07-09 20:51 -------- d-----w- c:\program files\Winamp
2009-07-09 10:16 . 2009-07-19 18:06 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-07-09 10:16 . 2009-07-19 18:06 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-07-07 15:32 . 2009-07-07 15:32 87328 ----a-w- c:\windows\system32\bcmwlcoi.dll
2009-07-07 15:32 . 2009-07-07 15:32 1123328 ----a-w- c:\windows\system32\drivers\BCMWL5.SYS
2009-07-07 14:23 . 2009-07-07 14:23 21892 ----a-w- c:\windows\system32\emptyregdb.dat
2008-04-13 23:33 . 2008-04-13 23:33 168032 --sha-r- c:\windows\system32\xfcrht.dll
.

------- Sigcheck -------

[-] 030DC4D48CC2B894FEE2F390D8E66AD5 [5.1.2600.5512 (xpsp.080413-0852)] c:\windows\system32\drivers\tcpip.sys

[-] 6A5F236CD5A33FAA882592834056DCA0 [5.1.2600.5512 (xpsp.080413-2111)] c:\windows\system32\ntkrnlpa.exe

[-] 3EBD4417CA19355C7E095E915EF7C432 [5.1.2600.5512 (xpsp.080413-2111)] c:\windows\system32\ntoskrnl.exe

[-] D1EA0A366973ECA3E03F1ACBEFDA8F43 [6.00.2900.5512 (xpsp.080413-2105)] c:\windows\explorer.exe

[-] 478B314098276163EDD8FCD47CC15BE5 [5.4.3790.5512 (xpsp.080413-0852)] c:\windows\system32\wuauclt.exe

[-] 1697B0EFD4E0FF0181F70CB73F04A518 [5.1.2600.5512 (xpsp.080413-2111)] c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
2009-06-25 13:06 688640 ----a-w- c:\program files\pdfforge Toolbar\pdfforgeToolbarIE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B922D405-6D13-4A2B-AE89-08A030DA4402}"= "c:\program files\pdfforge Toolbar\pdfforgeToolbarIE.dll" [2009-06-25 688640]

[HKEY_CLASSES_ROOT\clsid\{b922d405-6d13-4a2b-ae89-08a030da4402}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\Administrateur\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\Administrateur\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\Administrateur\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\windows\LSD\LClock\lclock.exe" [2004-09-19 65536]
"VoipBuster"="c:\program files\VoipBuster.com\VoipBuster\VoipBuster.exe" [2009-07-19 9075504]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-20 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-20 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-20 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1028096]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"lxdxmon.exe"="c:\program files\Lexmark 3600-4600 Series\lxdxmon.exe" [2008-03-20 668328]
"lxdxamon"="c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe" [2008-03-20 16040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-20 177472]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-07 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"WinLSD_SP3"="c:\windows\LSD\end.cmd" [2008-06-17 9944]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-23 124928]

c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Administrateur\Application Data\Dropbox\bin\Dropbox.exe [2009-8-31 26784939]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2009-8-3 110592]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\lxdxcoms.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\lxdxmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxtime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxjswx.exe"=
"c:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\Diagnostics\\LXDXdiag.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\frun.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5079:TCP"= 5079:TCP:drynisoe

R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service --> c:\windows\system32\lxdxcoms.exe -service [?]
S2 gupdate1ca095490cc3d8c;Google Update Service (gupdate1ca095490cc3d8c);c:\program files\Google\Update\GoogleUpdate.exe [20/07/2009 18:10 133104]
S2 lxdxCATSCustConnectService;lxdxCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdxserv.exe [09/07/2009 09:21 98984]
S2 sryinkss;Windows System;c:\windows\system32\svchost.exe -k netsvcs [14/04/2008 01:34 14336]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
sryinkss
.
Contents of the 'Scheduled Tasks' folder

2009-07-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2009-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-20 16:09]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-RunOnce-tscuninstall - c:\windows\system32\tscupgrd.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\jmzgulko.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.http - 157.159.10.14
FF - prefs.js: network.proxy.http_port - 81
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\jmzgulko.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}\components\pdfforgeToolbarFF.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-07 22:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\mc26.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(896)
c:\windows\system32\scecli.dll
.
Completion time: 2009-09-07 22:44
ComboFix-quarantined-files.txt 2009-09-07 20:43

Pre-Run: 3 737 628 672 octets libres
Post-Run: 3 716 038 656 octets libres

226
A voir également:

1 réponse

XaTon Messages postés 2041 Date d'inscription lundi 6 juillet 2009 Statut Membre Dernière intervention 22 janvier 2015 208
7 sept. 2009 à 23:21
Bonsoir ,

Dit moi ce que tu vois sur ce lien

> http://www.confickerworkinggroup.org/infection_test/cfeyechart.html

~~~~~~~~~~~~~~~> Hijack This <~~~~~~~~~~~~~~~~~~~

Telecharger Hijack

http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

Une fois Hijack installer, exécuter le :
• Cliquer sur "Do a system scan and save a logfile"

• Un fichier texte s'ouvre, si ce n'est pas le cas celui-ci se trouve dans le même dossier que hijackthis.exe .
• Faire édition / sélectionner tout
• Clic droit / copier

• Poste moi le rapport entier

[Edit]

Tu veut que sKe69 vienne t'aider ou je peut continuer ?
0