Virus TR/Dropper.Gen

Bonjour,
lorsque je démarre mon pc j'ai antivir qui me dis que j'ai le virus TR/Dropper.Gen, et quand je fait une analyse antivirus antivir me trouve des virus qu'il enleve mais a chaque fois que je redémarre l'ordi ça recommence.

Du coup si quelqu'un peu m'aider se serai cool.

Merci merci
Configuration: Windows XP

7 réponses

  1. Contributeur
    Bonjour,

    télécharge GenProc http://www.genproc.com/GenProc.exe

    double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre
    1. Alors voici le rapport de GenProc

      Rapport GenProc 2.633 [2] - 30/09/2009 à 10:43:38
      @ Windows XP Service Pack 2 - Mode normal
      @ Google Chrome (3.0.195.21) [Navigateur par défaut]

      Il est impératif de désactiver le résident TeaTimer de Spybot pendant l'ensemble des manipulations qui vont suivre. Aide Tea-Timer : http://ww11.genproc.com/spybot/spybot.html

      # Etape 1/ Télécharge :

      - Toolbar-S&D https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3 (Team IDN) sur ton Bureau.

      Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; Choisis ta session courante *** Antoine *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[2]" sur ton bureau).

      # Etape 2/

      Lance Toolbar-S&D situé sur le Bureau. Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.

      # Etape 3/

      Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

      # Etape 4/

      Redémarre normalement et poste, dans la même réponse :

      - Le contenu du rapport TB.txt situé dans C:\ ;
      - Un nouveau rapport HijackThis ;
      - Un nouveau rapport GenProc ;

      Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

      ~~ Arguments de la procédure ~~

      # Détections [1] GenProc 2.633 30/09/2009 à 10:22:15
      Toolbar:le 30/09/2009 à 10:23:06 "C:\WINDOWS\iun6002.exe"

      # Détections [2] GenProc 2.633 30/09/2009 à 10:43:41
      Toolbar:le 30/09/2009 à 10:44:34 "C:\WINDOWS\iun6002.exe"

      ----------------------------------------------------------------------
      Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
      ----------------------------------------------------------------------

      ~~ Fin à 10:44:58 ~~

      Par contre j'ai essayer de faire ce qui est indiqué mais ça ne change rien quand je redemarre le pc.
      1. Contributeur
        poste les rapports demandés dans GenProc et surtout précise où ce trouve ce "TR/Dropper.Gen" exactement
        sinon on en va pas avancer
        1. Alors voici le rapport tb.txt :

          -----------\\ ToolBar S&D 1.2.9 XP/Vista

          Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
          X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ )
          BIOS : Default System BIOS
          USER : Antoine ( Administrator )
          BOOT : Fail-safe boot
          A:\ (USB)
          C:\ (Local Disk) - NTFS - Total:29 Go (Free:10 Go)
          D:\ (Local Disk) - NTFS - Total:268 Go (Free:54 Go)
          E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
          F:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
          G:\ (Local Disk) - NTFS - Total:233 Go (Free:50 Go)

          "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
          Option : [1] ( 30/09/2009|10:37 )

          -----------\\ Recherche de Fichiers / Dossiers ...

          C:\WINDOWS\iun6002.exe

          -----------\\ Extensions

          (Antoine) - {25F97EB4-1C02-45BA-BA0C-E67AACE64D4A} => vretoolbar
          (Antoine) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
          (Antoine) - {c45c406e-ab73-11d8-be73-000a95be3b12} => webdeveloper

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="https://www.hugedomains.com/domain_profile.cfm?d=duxet&e=com"
          "Search Page"="https://www.google.fr/?gws_rd=ssl"
          "Search Bar"="http://www.google.fr/toolbar/ie8/sidebar.html"
          "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
          "Url"="http://www.microsoft.com/athome/community/rss.xml"
          "Url"="http://www.microsoft.com/atwork/community/rss.xml"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Start Page"="https://www.hugedomains.com/domain_profile.cfm?d=duxet&e=com"
          "Search Bar"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"

          --------------------\\ Recherche d'autres infections

          Aucune autre infection trouvée !

          1 - "C:\ToolBar SD\TB_1.txt" - 30/09/2009|10:38 - Option : [1]

          -----------\\ Fin du rapport a 10:38:52,98

          Et le rapport hijackthis.log
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 11:10:25, on 30/09/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.5730.0011)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\brsvc01a.exe
          C:\WINDOWS\system32\brss01a.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\PnkBstrA.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\RealVNC\VNC4\WinVNC4.exe
          C:\WINDOWS\mslsrv32.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\WINDOWS\system32\lclock.exe
          C:\Program Files\MSN Messenger\MsnMsgr.Exe
          C:\WINDOWS\system32\rundll32.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\NETGEAR\WPN111\wpn111.exe
          C:\WINDOWS\STVSPCButton.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.bin
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Documents and Settings\Antoine\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\Documents and Settings\Antoine\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\Documents and Settings\Antoine\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE
          C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=duxet&e=com
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=duxet&e=com
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Reloaded Lite V3.1
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
          O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\Vistadrive\vsdrv.exe
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [Service] C:\WINDOWS\Drivers\Microsoft\Servicerun.exe C:\WINDOWS\Drivers\Microsoft\Service.exe
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [sys64_nov] C:\WINDOWS\system32\sys64_nov.exe
          O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
          O4 - HKLM\..\Run: [restorer32_a] C:\WINDOWS\system32\restorer32_a.exe
          O4 - HKCU\..\Run: [LClock] lclock.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Antoine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
          O4 - HKCU\..\Run: [sys64_nov] C:\Documents and Settings\Antoine\sys64_nov.exe
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [restorer32_a] C:\Documents and Settings\Antoine\restorer32_a.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKLM\..\Policies\Explorer\Run: [Microsoft Driver Setup] C:\WINDOWS\mslsrv32.exe
          O4 - HKUS\S-1-5-19\..\Run: [LClock] lclock.exe (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [LClock] lclock.exe (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-20\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [LClock] lclock.exe (User 'SYSTEM')
          O4 - HKUS\S-1-5-18\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [LClock] lclock.exe (User 'Default user')
          O4 - HKUS\.DEFAULT\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
          O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
          O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
          O4 - Global Startup: STVSPCButton.lnk = C:\WINDOWS\STVSPCButton.exe
          O8 - Extra context menu item: Tout télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
          O8 - Extra context menu item: Télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
          O8 - Extra context menu item: Télécharger toutes les vidéos avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
          O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll/206 (file missing)
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
          O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
          1. Contributeur
            il y a trop d'oublis :
            - tu postes le rapport de recherche de TB alors que c'est celui de suppression qui est demandé
            - manque le nouveau rapport GenProc

            ensuite tu utilises une version illégale de windows, la suite se fera donc sans moi