Infectée par le ver Bagle

Résolu
Bonjour,

Je cherche quelqu'un pour m'aider avec les suivis de rapport concernant le ver bagle (impossible de demarrer
en mode sans echec, d'installer un antivirus..etc).

Merci d'avance
Configuration: Windows XP
Firefox 3.5.3

19 réponses

  1. Contributeur sécurité
    Bonjour sarahpc

    Télécharge FindyKill de Chiquitine29 sur ton bureau :

    http://pagesperso-orange.fr/NosTools/Chiquitine29/FindyKill.exe

    Double clique "FindyKill.exe"

    Tuto : http://pagesperso-orange.fr/NosTools/tuto_fyk2.html

    Choisis F pour Français puis l’option 1 (recherche)

    Laisse travailler l’outil.

    Une fois terminé, poste le rapport FindyKill.txt qui est généré ...
    1
    1. J'ai vu que c'était possible avec elibagla, combofix, etc...
      0
      1. Merci, enfin je tombe sur quelqu'un d'efficace. j'avais deja lancé la recherche en attendant , voila le rapport :

        ############################## | FindyKill V5.017 |

        # User : jung (Administrateurs) # JUNG-813519060E
        # Update on 01/11/2009 by Chiquitine29
        # Start at: 19:58:38 | 07/11/2009
        # Website : http://pagesperso-orange.fr/NosTools/index.html
        # Contact : FindyKill.Contact@gmail.com

        # Intel(R) Pentium(R) M processor 1.60GHz
        # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
        # Internet Explorer 6.0.2900.2180
        # Windows Firewall Status : Disabled

        # C:\ # Disque fixe local # 74,53 Go (30,1 Go free) # NTFS
        # D:\ # Disque CD-ROM
        # E:\ # Disque amovible # 950,19 Mo (550,29 Mo free) [UDISK] # FAT32

        ############################## | Processus actifs |

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
        C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
        C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\DOCUME~1\jung\LOCALS~1\Temp\ndfr.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe

        ################## | C: |

        Présent ! E:\autorun.inf

        ################## | C:\WINDOWS |

        ################## | C:\WINDOWS\system32 |

        ################## | C:\WINDOWS\system32\drivers |

        ################## | C:\Documents and Settings\jung\Application Data |

        ################## | Autres detections ... |

        ################## | Temporary Internet Files |

        ################## | Registre / Clés infectieuses |

        Présent ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
        Présent ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
        Présent ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
        Présent ! [HKLM\software\microsoft\security center] "FirewallOverride"
        Présent ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"
        Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
        Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"
        Présent ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"

        ################## | Etat / Services / Informations |

        # Affichage des fichiers cachés : OK

        Clé manquante : HKLM\SYSTEM\...\SafeBoot\Minimal | Mode sans echec non fonctionnel !

        # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
        # Ip6Fw -> Start = 3 ( Good = 2 | Bad = 4 )
        # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
        # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
        # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

        ################## | Cracks / Keygens / Serials |

        ################## | ! Fin du rapport # FindyKill V5.017 ! |
        0
        1. Contributeur sécurité
          Branche toutes tes unités externes au PC ( DD externes, clé USB, lecteur mp3, ect...) mais sans les ouvrir !
          Tu les retireras après la manip ...

          Ferme toutes les applications en cours !

          Relance FindyKill :

          choisis cette fois-ci l'option 2 (suppression).

          /!\ ton PC va redémarrer de lui même , c'est normal !... Laisse travailler l'outil

          --> Poste le nouveau rapport FindyKill.txt qui est généré.

          ( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )

          PS : Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr , Onglet "Fichier"-> "Nouvelle tâche":
          tapes explorer.exe et valide .
          0
          1. ############################## | FindyKill V5.017 |

            # User : jung (Administrateurs) # JUNG-813519060E
            # Update on 01/11/2009 by Chiquitine29
            # Start at: 20:33:10 | 07/11/2009
            # Website : http://pagesperso-orange.fr/NosTools/index.html
            # Contact : FindyKill.Contact@gmail.com

            # Intel(R) Pentium(R) M processor 1.60GHz
            # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
            # Internet Explorer 6.0.2900.2180
            # Windows Firewall Status : Disabled

            # C:\ # Disque fixe local # 74,53 Go (30,03 Go free) # NTFS
            # D:\ # Disque CD-ROM
            # E:\ # Disque amovible # 950,19 Mo (550,29 Mo free) [UDISK] # FAT32

            ############################## | Processus actifs |

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            C:\WINDOWS\system32\logonui.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\userinit.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            ################## | C: |

            Supprimé ! E:\"autorun.inf"

            ################## | C:\WINDOWS |

            Supprimé ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-17681AA8.pf

            ################## | C:\WINDOWS\system32 |

            ################## | C:\WINDOWS\system32\drivers |

            ################## | C:\Documents and Settings\jung\Application Data |

            ################## | Autres suppressions ... |

            ################## | Temporary Internet Files |

            ################## | Registre / Clés infectieuses |

            Supprimé ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
            Supprimé ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
            Supprimé ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
            Supprimé ! [HKLM\software\microsoft\security center] "FirewallOverride"
            Supprimé ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"
            Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
            Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"
            Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"

            ################## | Etat / Services / Informations |

            # Mode sans echec restauré !

            # Affichage des fichiers cachés : OK

            # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
            # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
            # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
            # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
            # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

            ################## | PEH ... |

            ################## | Cracks / Keygens / Serials |

            ################## | ! Fin du rapport # FindyKill V5.017 ! |
            0
            1. Contributeur sécurité
              OK
              Maintenant essaie de réinstaller ce qui ne fonctionnait pas.
              0
              1. Non toujours pas d'installation possible.
                Quelle est donc la prochaine étape ?
                0
                1. Contributeur sécurité
                  Qu'est-ce qui ne veut pas s'installer ?
                  0
                  1. Antivir, spybot, les deux seuls que j'ai essayé.
                    0
                    1. Contributeur sécurité
                      • Télécharge Random's System Information Tool (RSIT) de Random / Random et sauvegarde-le sur ton Bureau,

                      -> http://images.malwareremoval.com/random/RSIT.exe

                      • Double-clique sur RSIT.exe pour lancer le programme,
                      • Clique sur continuer sur l'écran Disclaimer,
                      • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
                      • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (<<qui sera affiché)
                      Ferme info.txt (<<qui sera réduit dans la Barre des Tâches), il ne te sera demandé qu’en cas de besoin.

                      Tuto si besoin : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
                      0
                      1. voila le rapport :

                        Logfile of random's system information tool 1.06 (written by random/random)
                        Run by jung at 2009-11-07 21:57:19
                        Microsoft Windows XP Professionnel Service Pack 2
                        System drive C: has 31 GB (40%) free of 76 GB
                        Total RAM: 510 MB (43% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 21:57:26, on 07/11/2009
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                        C:\WINDOWS\system32\wscntfy.exe
                        C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                        C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                        C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\DOCUME~1\jung\LOCALS~1\Temp\winismts.exe
                        C:\WINDOWS\system32\NOTEPAD.EXE
                        C:\Documents and Settings\jung\Mes documents\Téléchargements\RSIT.exe
                        C:\Program Files\trend micro\jung.exe

                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O4 - HKLM\..\Run: [CARPService] carpserv.exe
                        O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                        O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                        O17 - HKLM\System\CCS\Services\Tcpip\..\{09FC102B-F193-4502-99D0-CC71B6FDAEBD}: NameServer = 212.27.53.252,212.27.54.252
                        O17 - HKLM\System\CS1\Services\Tcpip\..\{09FC102B-F193-4502-99D0-CC71B6FDAEBD}: NameServer = 212.27.53.252,212.27.54.252
                        O17 - HKLM\System\CS2\Services\Tcpip\..\{09FC102B-F193-4502-99D0-CC71B6FDAEBD}: NameServer = 212.27.53.252,212.27.54.252
                        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                        O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                        O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                        0
                        1. Contributeur sécurité
                          Imprime ces instructions ou sauvegarde les sur ton Bureau car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                          Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

                          https://download.cnet.com/Malwarebytes/3000-8022_4-10804572.html

                          A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                          Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                          Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                          MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

                          Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                          MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

                          Lorsque le message indiquant la fin de l’analyse s’affiche, clique sur « Afficher le résultat » pour poursuivre..

                          Si des malwares ont été détectés, leur liste s'affiche.
                          Coche tous les éléments détectés par Malwarebytes' Anti-Malware puis clique sur « Supprimer la sélection » afin d'éradiquer les malwares détectés. MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                          MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                          Ferme MBAM en cliquant sur Quitter.

                          Poste le rapport sur le forum.

                          Tuto si besoin : https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
                          0
                          1. apres une trentaine de minute, voila le travail :

                            Malwarebytes' Anti-Malware 1.41
                            Version de la base de données: 3118
                            Windows 5.1.2600 Service Pack 2

                            07/11/2009 23:19:04
                            mbam-log-2009-11-07 (23-19-04).txt

                            Type de recherche: Examen complet (C:\|)
                            Eléments examinés: 189199
                            Temps écoulé: 33 minute(s), 52 second(s)

                            Processus mémoire infecté(s): 1
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 2
                            Dossier(s) infecté(s): 1
                            Fichier(s) infecté(s): 13

                            Processus mémoire infecté(s):
                            C:\Documents and Settings\jung\Local Settings\temp\winismts.exe (Trojan.Downloader) -> Unloaded process successfully.

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                            Dossier(s) infecté(s):
                            C:\Program Files\Save (Adware.WhenU) -> Quarantined and deleted successfully.

                            Fichier(s) infecté(s):
                            C:\Documents and Settings\jung\Local Settings\temp\winismts.exe (Trojan.Downloader) -> Delete on reboot.
                            C:\8e.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\1rfw8hjr.com.vir (Trojan.Vaklik) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\abk.bat.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\ij.bat.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F0C7F623-EB25-4367-AD6C-0E2EB48E9025}\RP4\A0001112.com (Trojan.Vaklik) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F0C7F623-EB25-4367-AD6C-0E2EB48E9025}\RP4\A0001115.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F0C7F623-EB25-4367-AD6C-0E2EB48E9025}\RP4\A0001123.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F0C7F623-EB25-4367-AD6C-0E2EB48E9025}\RP4\A0001141.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F0C7F623-EB25-4367-AD6C-0E2EB48E9025}\RP4\A0001148.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F0C7F623-EB25-4367-AD6C-0E2EB48E9025}\RP4\A0001151.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F0C7F623-EB25-4367-AD6C-0E2EB48E9025}\RP4\A0001155.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\a.condy\Menu Démarrer\Programmes\Démarrage\¡¡¡¡¡¡.lnk (Worm.AutoRun) -> Quarantined and deleted successfully.
                            0
                            1. Même résultat pour l'installation d'antivir.
                              0
                              1. Merci pour votre aide tout d'abord, que dois-je faire à présent ?
                                0
                                1. Up!
                                  0
                                  1. Aide !
                                    0
                                2. Je desespère la...quelqu'un d'autre peut il prendre la releve ?
                                  Merci d'avance
                                  0
                                  1. a mon avis il faut formater votre disque dur et reinstaller windows
                                    -1
                                    1. Contributeur sécurité
                                      Ou brûler l'ordinateur, ça va plus vite....
                                      0
                                  2. a bon dacord en fin de compte jai du mal conprendre pouver vous mexipliquer votre problem et commen et il arriver et je pourer surment vous aider car linformatique je conais pas mal
                                    -1