Probleme privacyremover et virtumonde

comakepi Messages postés 21 Statut Membre -  
chimay8 Messages postés 7947 Statut Contributeur sécurité -
Salut,
je suis infecté par plusieurs virus ou spyware, j'aurai besoin de quelques conseils, voici le rapport malwarebytes:

Malwarebytes' Anti-Malware 1.25
Version de la base de données: 1103
Windows 5.1.2600 Service Pack 2

16:34:17 01/09/2008
mbam-log-09-01-2008 (16-34-02).txt

Type de recherche: Examen rapide
Eléments examinés: 75597
Temps écoulé: 9 minute(s), 47 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 7
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 22
Fichier(s) infecté(s): 84

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\5636b6af (Rootkit.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\5636b6af (Rootkit.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zpeceu (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\shcttcj0e1ce (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\rhcvtcj0e1ce (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\shcttcj0e1ce (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> No action taken.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcrtcj0e1ce (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smrhcvtcj0e1ce (Trojan.FakeAlert) -> No action taken.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine\Autorun (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\HKCU (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\HKLM (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine\BrowserObjects (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\NetworkService.AUTORITE NT.001\Application Data\rhcvtcj0e1ce\Quarantine\Packages (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine\Autorun (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\HKCU (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\HKLM (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine\BrowserObjects (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\lea\Application Data\rhcvtcj0e1ce\Quarantine\Packages (Rogue.Multiple) -> No action taken.

Fichier(s) infecté(s):
C:\WINDOWS\system32\drivers\5636b6af.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\bio07.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\blphcrtcj0e1ce.scr (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\drivers\hou20.sys.vir (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\lry20.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\mta17.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\mta20.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\mub06.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\nub17.sys.vir (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\ovd06.sys.vir (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\ryf17.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\sag06.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\sag64.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winah85.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winbh30.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winel30.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winhn64.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winhn85.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winhr33.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winjs86.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winub85.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winub86.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winvc18.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winvd28.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winwd41.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winwe64.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\winyf18.sys.vir (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\xfl18.sys.vir (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\xfl28.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\xfl64.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\zpeceu.dll (Trojan.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc15.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc19.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc2.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc22.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc23.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc24.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc26.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc29.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc3.vir (Trojan.FakeAlert) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc34.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc36.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc37.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc46.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc47.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc48.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc49.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc50.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc51.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc52.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc53.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc54.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc55.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc56.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc57.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc58.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc59.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc60.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc61.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc62.vir (Rootkit.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-1229272821-152049171-854245398-1011\Dc65.vir (Trojan.Agent) -> No action taken.
C:\WINDOWS\Temp\7594D812.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\Temp\vwr1.tmp (Trojan.Peed) -> No action taken.
C:\Documents and Settings\LocalService.AUTORITE NT.001\Local Settings\Temporary Internet Files\Content.IE5\O16B452R\sysftp[1].exe (Trojan.Agent) -> No action taken.
C:\Program Files\Mozilla Firefox\setupapi.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\lphcrtcj0e1ce.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\phcrtcj0e1ce.bmp (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\pphcrtcj0e1ce.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\E.tmp (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\lea\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> No action taken.
C:\WINDOWS\Temp\.tt15.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\Temp\.tt2.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt3.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt4.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt5.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt6.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt7.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt8.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt9.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.ttA.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.ttB.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.ttD.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.ttE.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\drivers\spoolsv.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.

Puis-je supprimer tous ces fichiers sans soucis? Quelles autres actions entreprendre? Je tourne sur win XP Sp2.
Merci d'avance.

21 réponses

chimay8 Messages postés 7947 Statut Contributeur sécurité 60
 
ok
0