M-le-Maudit
-
1 oct. 2009 à 15:17
crapoulou
Messages postés28158Date d'inscriptionmercredi 28 novembre 2007StatutModérateur, Contributeur sécuritéDernière intervention16 avril 2024
-
4 oct. 2009 à 23:24
Bonjour,
Mon ordi rame depuis quelques temps. J'ai décidé aujourd'hui de le nettoyer.
J'ai passé un coup de Ccleaner, Regcleaner et Ad-Aware. A priori, il n'y avait rien de bien méchant.
Pourtant, après avoir passé Trojan Killer, je me rends compte que mon PC n'est pas si clean que ça.
Je vous poste le rapport de Trojan Killer ainsi que celui de Hijackthis.
Je vous serais reconnaissant de bien vouloir m'aider à me débarrasser de ces sales bestioles.
----- C:\WINDOWS\system32\ansi.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\append.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\avicap.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\avifile.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\comm.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\commdlg.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\compobj.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\country.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ctl3dv2.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\ddeml.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\debug.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\drwatson.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\ds16gt.dLL ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dsound.vxd ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\edlin.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\exe2bin.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\fastopen.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\gdi.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\himem.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\key01.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\keyboard.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\lanman.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\lzexpand.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\mciavi.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\mciole16.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\mciseq.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\mciwave.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\mem.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\mouse.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\msacm.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\mscdexnt.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\msvideo.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\krnl386.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\netapi.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\nlsfunc.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\ntdos.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ntdos411.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ntdos412.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ntdos404.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ntdos804.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ntio.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ntio404.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ntio411.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ntio412.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\odbc16gt.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\ole2.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\ole2disp.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\ole2nls.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\olecli.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\olesvr.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\pmspl.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\setver.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\share.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\shell.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\sound.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\storage.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\sysedit.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\system.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\tapi.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\timer.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\toolhelp.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\typelib.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\user.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\ver.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\vga.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\wfwnet.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\wifeman.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\win87em.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\winnls.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\winsock.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\winspool.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\wowdeb.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\wowexec.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\redir.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\keyboard.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\ntio804.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\mmsystem.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\javasup.vxd ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dosx.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\_003712_.tmp.dll ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\_003743_.tmp.dll ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\spool\drivers\w32x86\3\WAVS.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\spool\drivers\w32x86\3\HLP256.DLL ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_x1100_seriesf27b\WAVS.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_x1100_seriesf27b\HLP256.DLL ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\ansi.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\append.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\dllcache\avicap.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\avifile.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\compobj.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\commdlg.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\country.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\ctl3dv2.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\twunk_16.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\ddeml.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\typelib.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\debug.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\dllcache\gdi.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\himem.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\drwatson.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\ds16gt.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\edlin.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\dllcache\exe2bin.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\dllcache\key01.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\keyboard.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\fastopen.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\dllcache\keyboard.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\lzexpand.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\mciavi.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\mciole16.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\mciseq.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\mciwave.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\mem.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\dllcache\msvideo.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\netapi.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\nlsfunc.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\dllcache\ntdos404.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\ntdos411.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\ntdos.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\ntdos412.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\ntdos804.sys ---- General
Invalid DOS signature
----- C:\WINDOWS\system32\dllcache\mouse.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\odbc16gt.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\ole2disp.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\ole2nls.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\ole2.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\olecli.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\olesvr.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\msacm.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\pmspl.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\mscdexnt.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\dllcache\storage.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\sysedit.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\system.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\tapi.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\timer.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\toolhelp.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\twain.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\user.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\ver.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\vga.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\share.exe ---- General
Not a PE file
----- C:\WINDOWS\system32\dllcache\shell.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\wfwnet.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\winnls.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\wifeman.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\win87em.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\winhelp.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\winsock.dll ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\winspool.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\wowdeb.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\wowexec.exe ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\dllcache\sound.drv ---- General
Invalid PE signature (probably NE file)
----- C:\WINDOWS\system32\IOSUBSYS\pxhelper.vxd ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\MSN\MSNCoreFiles\Setup\msn9xmig.dll ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\Internet Explorer\iexplore.exe ---- General
Win32.AutoRun.H, W32.Addsones, Worm.Win32.AutoRun.p, PE_AGENT.ZA
MD5: 385D1644E676C96EB07848ADA63E37FA:93184
EP: E8 0A 00 00 00 E9 50 FF FF FF CC CC CC CC CC 8B FF 55 8B EC 83 EC 10 A1 94 30 40 00 85 C0 74 07 3D 40 BB 00 00 75 4D 56 8D 45 F8 50 FF 15 A8 10 40 00 8B 75 FC 33 75 F8 FF 15 58 10 40 00 33 F0 FF
SEC:
.text:95690012BE915072CD7868D00CC7D471:7680
.data:3250EBD1E3513E9AA0C55AD75A9F41C3:512
.rsrc:93E8692532A826F47DC9C34580777A47:83968
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\PMagicBt.exe ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\PQVXD.vxd ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\DOS\BTIni.exe ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\DOS\FSIMAGE.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\DOS\partinfo.exe ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\DOS\PQBOOT.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\DOS\PQBOOTX.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\DOS\PQMAGIC.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\DOS\PTEDIT.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\DOS\SNUTIL.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\DOS\WRPROG.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\Setup.exe ---- General
Backdoor.Win32.Hupigon
MD5: C63ED941CF9D3DDB78F2B8B7EA9F1EB8:165888
EP: 55 8B EC 83 EC 44 53 56 FF 15 70 80 40 00 8B F0 33 DB 3B F3 75 08 6A FF FF 15 6C 80 40 00 57 53 53 53 FF 15 68 80 40 00 8B 3D D8 81 40 00 A3 24 A6 40 00 8A 06 3C 22 75 1B 56 FF D7 8B F0 8A 06 3C
SEC:
.text:5DCF24CEA98F3AE15E1BE28E90484754:27648
.rdata:FA18EC528EFA2D13B469F71BE57B56FE:4608
.data:254B09234BB40A020C82152F5087054D:2048
.rsrc:CCD4821307C821A56DD3F1294EBEF202:130560
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\DOSYSTEM\CHKDSK.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\DOSYSTEM\CONFIG.SYS ---- General
Invalid DOS signature
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\DOSYSTEM\CONFIG9x.SYS ---- General
Invalid DOS signature
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\DOSYSTEM\CONFIGME.SYS ---- General
Invalid DOS signature
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\DOSYSTEM\DISPLAY.SYS ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\DOSYSTEM\EMM386.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\DOSYSTEM\HIMEM.SYS ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\DOSYSTEM\MYDOS.SYS ---- General
Invalid DOS signature
----- C:\Program Files\PowerQuest\PartitionMagic 8.0\RESCUEME\DOSYSTEM\NWCDEX.EXE ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\Lexmark X1100 Series\Drivers\French\setup.exe ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\Lexmark X1100 Series\Drivers\French\_isdel.exe ---- General
Invalid PE signature (probably NE file)
----- C:\Program Files\Lexmark X1100 Series\Drivers\French\_setup.dll ---- General
Invalid PE signature (probably NE file)
Scan completed.
Scan result: 6 infected items
Scan completed in: Scan completed in 36 minute(s) 35 sec.
Files were scanned: 11215
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:08:55, on 01/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal