Help infection Beagle!

Lolo -  
 Lolo -
Bonjour,

Mon PC vient d'être infecté par Beagle.
J'ai essayé de lancer plusieurs utilitaires pour le supprimer mais impossible, ni en mode normal, ni en mode sans échec.
Après qqs recherches, j'ai vu qu'il fallait que je répare le mode sans échec mais je suis sous Vista SP 2 et du coup, ça ne marche pas (apparement il faut Vista sans SP).
Pourriez-vous m'aider à me débarrasser de ce trojan svp??
Merci d'avance.
Configuration: Windows Vista
Firefox 3.5.5

4 réponses

  1. Utilisateur anonyme
     
    bonsoir
    c'est quels utilitaires que tu as essayé ?
    0
  2. Lolo
     
    Malwarebytes, spybot, combofix, fxbeagle.
    A chaque fois je n'arrive pas à les lancer, il me dit application win32 non valide, ou vous n'êtes pas administrateur...
    0
  3. Utilisateur anonyme
     
    Tu essayer ceci

    Tu as ine infection Bagle sur ton PC
    Le bagle s'attrape en téléchargeant des faux cracks par le P2P, les cracks sont un vrai danger et sont sources d'infections. Le bagle fait des dégats: il neutralise le fonctionnement des logiciels de sécurité, tel que l'anti-virus, qui va se retrouver corrompu, il supprime la clé safeboot (mode sans échec). Eviter de redémarrer le PC en mode sans échec par msconfig, car le PC redémarrerai en boucle sans pouvoir accéder en mode normal

    lit ceci sur le danger des cracks en cliquant sur ce lien:
    https://forum.malekal.com/viewtopic.php?t=893&start=

    Désactive l'UAC: contrôle de comptes d'utilisateurs

    Clique sur le menu Démarrer puis sur Panneau de configuration , Comptes d'utilisateurs
    Clique sur Activer ou désactiver le contrôle des comptes d'utilisateurs:
    Une nouvelle fenêtre s'ouvre,décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur puis OK:
    Une demande s'affiche si vous voulez redémarrer votre ordinateur, clique sur redémarrer maintenant

    https://forums.cnetfrance.fr

    ▶ Télécharge FindyKill de Chiquitine29 sur ton bureau :
    http://findykill.changelog.fr/FindyKill.exe
    Renomme le lolo.exe

    • Double clique sur "lolo.exe" pour lancer l'installation avec les paramètres par par défaut .
    • Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)
    • Clic droit sur FindyKill présent sur ton bureau, puis clique sur éxécuter en tant qu'administrateur
    • Sélectionne l'option F pour le français, puis appuie sur la touche entrée
    • Sélectione l'option 1 (recherche), puis appuie sur la touche entrée

    ▶ Laisse travailler l'outil et ne touche à rien ...

    --> Poste le rapport qui apparait à la fin , sur le forum ...

    ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )
    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    Aides en images : http://pagesperso-orange.fr/NosTools/findykill.html
    0
  4. Utilisateur anonyme
     
    bonjour
    je vois que tu as ouvert un second sujet, je suppose que c'est pour un second PC ?
    As tu fait ce que je t'ai demandé ?
    0
    1. Lolo
       
      Bonjour Nathandre,

      Et merci de ton aide.
      Non je n'ai pas ouvert de 2ème sujet.
      Je viens de terminer le scan avec FindyKill et voici le rapport :


      ############################## | FindyKill V5.017 |

      # User : SYSTEM ()
      # Update on 01/11/2009 by Chiquitine29
      # Start at: 19:04:14 | 12/11/2009
      # Website : http://pagesperso-orange.fr/NosTools/index.html
      # Contact : FindyKill.Contact@gmail.com

      # Intel(R) Core(TM)2 Duo CPU T7300 @ 2.00GHz
      # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
      # Internet Explorer 7.0.6000.16764
      # Windows Firewall Status : Enabled
      # AV : avast! antivirus 4.8.1351 [VPS 091111-1] 4.8.1351 [ (!) Disabled | Updated ]
      # FW : ZoneAlarm Firewall[ Enabled ]7.1.254.000

      # C:\ # Disque fixe local # 141,59 Go (47,37 Go free) # NTFS
      # D:\ # Disque fixe local # 7,46 Go (2,31 Go free) [HP_RECOVERY] # NTFS
      # E:\ # Disque CD-ROM

      ############################## | Processus actifs |

      C:\Windows\System32\smss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\wbem\wmiprvse.exe

      ################## | |


      ################## | C:\Windows |


      ################## | C:\Windows\system32 |

      Présent ! C:\Windows\system32\ban_list.txt
      Présent ! C:\Windows\system32\mdelk.exe
      Présent ! C:\Windows\system32\srosa2.sys
      Présent ! C:\Windows\system32\wfsintwq.sys
      Présent ! C:\Windows\system32\wintems.exe

      ################## | C:\Windows\system32\drivers |


      ################## | |

      ################## | Autres detections ... |

      ################## | Temporary Internet Files |


      ################## | Registre / Clés infectieuses |

      Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\sK9Ou0s]
      Présent ! [HKLM\SYSTEM\ControlSet001\Services\sK9Ou0s]
      Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\srosa]
      Présent ! [HKLM\SYSTEM\ControlSet001\Services\srosa]
      Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S]
      Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S]
      Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
      Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
      Présent ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
      Présent ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
      Présent ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
      Présent ! [HKLM\software\microsoft\security center] "FirewallOverride"
      Présent ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"
      Présent ! [HKLM\software\microsoft\security center\Svc] "AntiVirusOverride"
      Présent ! [HKLM\software\microsoft\security center\Svc] "FirewallOverride"

      ################## | Etat / Services / Informations |

      # Affichage des fichiers cachés : OK

      # Mode sans echec : OK

      # (!) Uac = 0x0

      # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
      # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
      # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
      # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
      # (!) windefend -> Start = 4 ( Good = 2 | Bad = 4 )
      # (!) wuauserv -> Start = 4 ( Good = 2 | Bad = 4 )
      # (!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )


      ################## | Cracks / Keygens / Serials |

      "C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe"
      27/03/2004 09:01 |Size 782336 |Crc32 2b375767 |Md5 0c156bcd9974eec48c72f5c29cae48f9

      "C:\Users\Loan\Downloads\JEUX\PES\PES 2009\Keygen-FFF.exe"
      18/10/2008 22:19 |Size 53248 |Crc32 e92eb4be |Md5 61a713e1c6dd026b7694873e065f10cc

      "C:\Users\Loan\Downloads\JEUX\PES\PES 2009\v1.20 crack no cd\pes2009.exe"
      08/11/2008 12:55 |Size 28143616 |Crc32 781b9cac |Md5 bcb2c42f92ac09209cc6af5bdbceab8e


      ################## | ! Fin du rapport # FindyKill V5.017 ! |
      0
      1. Lolo > Lolo
         
        Bonjour,

        Quelqu'un pourrait-il m'aider svp?
        Mon Pc ne démarre plus maintenant! seulement en mode sans échec...
        Merci d'avance.
        0
      2. Lolo > Lolo
         
        Bonjour,

        Après avoir passé l'option 2 de FindyKill il y a un peu d'amélioration, mon PC démarre à nouveau.
        Mon antivirus, malware, spybot sont à nouveau actifs aussi.
        Mais apparement j'ai toujours des clés de registre infectées et même après avoir passé tt ces utilitaires, elles restent présentes.

        J'ai fait un scan avec RSIT comme j'ai vu dans plusieurs autres posts et voici le rapport du fichier log.text.
        SVP, j'ai vraiment besoin d'aide pr me débarrasser complètement de ce virus.

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by at 2009-11-15 18:16:37
        Microsoft® Windows Vista™ Édition Familiale Premium
        System drive C: has 66 GB (46%) free of 145 GB
        Total RAM: 2046 MB (51% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:16:58, on 15/11/2009
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16764)
        Boot mode: Normal

        Running processes:
        c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
        C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Windows\WindowsMobile\wmdSync.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\wuauclt.exe
        C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Users\Loan\Desktop\RSIT.exe
        C:\Program Files\trend micro\Loan.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
        O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll,RegisterModule
        O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
        O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O17 - HKLM\System\CCS\Services\Tcpip\..\{BF72AF36-B8E7-4195-9B62-C4414915DFDA}: NameServer = 192.168.1.1
        O17 - HKLM\System\CCS\Services\Tcpip\..\{CBE0B267-DAD2-4FA5-8829-560CA7FDF460}: NameServer = 192.168.1.1
        O20 - AppInit_DLLs: C:\Windows\System32\APSHook.dll
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
        O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
        O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
        O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
        0