Infection par Win32:Beagle-AAW[Trj] et HDLRR

Résolu
Jeanphi78 -  
afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour,

Mon PC est infecté par Win32:Beagle-AAW[Trj] et HDLRR en ouvrant un fichier zip. J'ai essayé de les supprimer en utilisant Killbox et ELIBAGLA mais sans succès.
J'ai enfin essayé avec ComboFix et voici le rapport:

ComboFix 08-09-11.02 - Jean-Philippe NEAV 2008-09-12 22:04:30.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.573 [GMT 2:00]
Endroit: C:\Documents and Settings\Jean-Philippe NEAV\Bureau\CaumbauFeex.exe
* Création d'un nouveau point de restauration

[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Jean-Philippe NEAV\Cookies\jean-philippe_neav@ad.yieldmanager[2].txt
C:\Documents and Settings\Jean-Philippe NEAV\Cookies\jean-philippe_neav@bluestreak[1].txt
C:\Documents and Settings\Jean-Philippe NEAV\Cookies\jean-philippe_neav@clickintext[1].txt
C:\Documents and Settings\Jean-Philippe NEAV\Cookies\jean-philippe_neav@edt02[1].txt
C:\Documents and Settings\Jean-Philippe NEAV\Cookies\jean-philippe_neav@serving-sys[2].txt
C:\Documents and Settings\Jean-Philippe NEAV\Cookies\jean-philippe_neav@trafiz[1].txt
C:\Documents and Settings\Jean-Philippe NEAV\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\InfoSat.txt
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\PopSwatr\History\allowed
C:\Program Files\FunWebProducts\PopSwatr\History\notallow
C:\Program Files\MyWay
C:\Program Files\MyWay\myBar\History\search
C:\Program Files\MyWay\SrchAstt\1.bin\PARTNER.DAT
C:\Program Files\MyWay\SrchAstt\Cache\[u]0[/u]0023936
C:\Program Files\MyWay\SrchAstt\Cache\[u]0[/u]002428D
C:\Program Files\MyWay\SrchAstt\Cache\[u]0[/u]002B4BF
C:\Program Files\MyWay\SrchAstt\Cache\[u]0[/u]006AD69
C:\Program Files\MyWay\SrchAstt\Cache\files.ini
C:\Program Files\MyWay\SrchAstt\Settings\prevcfg.htm
C:\WINDOWS\system32\drivers\downld

.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-12 to 2008-09-12 ))))))))))))))))))))))))))))))))))))
.

2008-08-24 01:28 . 2008-09-07 12:59 13 --a------ C:\WINDOWS\msgtn.ini
2008-08-24 01:26 . 2008-09-12 21:00 <REP> d-------- C:\Documents and Settings\Jean-Philippe NEAV\Application Data\ppstream
2008-08-13 18:39 . 2008-05-01 16:31 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-12 18:36 36,868,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-12 18:36 195,476 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-12 17:52 --------- d-----w C:\Program Files\MSN Messenger
2008-09-12 17:07 --------- d-----w C:\Program Files\eMule
2008-09-11 05:22 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\AdobeUM
2008-09-10 18:27 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Azureus
2008-08-11 19:44 --------- d-----w C:\Program Files\QuickMediaConverter
2008-08-11 18:42 --------- d-----w C:\Program Files\ProjectX_0.90.4.00
2008-08-10 16:20 --------- d-----w C:\Program Files\NetDrive
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:18 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-07-04 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-07-04 23:46 66912 --a------ C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-17 761945]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-11-30 73728]
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 118784]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 919016]
"WebDriveTray"="C:\Program Files\NetDrive\netdrive.exe" [2003-06-04 294912]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-10 C:\WINDOWS\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 C:\WINDOWS\agrsmmsg.exe]
"TPSMain"="TPSMain.exe" [2005-08-03 C:\WINDOWS\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" [2005-09-15 C:\WINDOWS\system32\TDispVol.exe]
"CFSServ.exe"="CFSServ.exe" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VP40"= vp4vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Kingsoft\\Powerword 2007\\xdict.exe"=
"C:\\Program Files\\Kingsoft\\Powerword 2007\\update.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-05 14336]
R2 WebDriveFSD;WebDrive File System Driver;C:\Program Files\NetDrive\rffsd.sys [2002-11-27 67032]
S2 FILESpy;FILESpy;C:\Program Files\Softwin\BitDefender9\filespy.sys [ ]
S3 DTVFW;DVB-T USB adapter firmware;C:\WINDOWS\system32\DRIVERS\dtvfw.sys [2005-11-30 22016]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2005-04-21 112384]
S3 usbdtv;DVB-T TV Tuner;C:\WINDOWS\system32\Drivers\usbdtv.sys [2005-11-30 31232]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\AUTORUN.EXE

*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-TOSCDSPD - C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
HKLM-Run-TkBellExe - C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
HKLM-Run-BDSwitchAgent - C:\progra~1\softwin\bitdef~2\bdswitch.exe

.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Mozilla\Firefox\Profiles\yv2v9op7.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.fr/
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-12 22:11:04
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cachés ...

Balayage caché autostart entries ...

Balayage des fichiers cachés ...

Scan terminé avec succès
Les fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\RFHelper.dll
.
Temps d'accomplissement: 2008-09-12 22:12:40
ComboFix-quarantined-files.txt 2008-09-12 20:12:32

Pre-Run: 2,312,871,936 octets libres
Post-Run: 2,837,004,288 octets libres

171 --- E O F --- 2008-09-11 01:04:19

Merci d'avance pour votre aide.

JP
Configuration: Windows XP
Internet Explorer 7.0

11 réponses

  1. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Bonsoir vous deux

    Télécharge FindyKill

    - Fais un clic droit sur le lien suivant > "enregistrer sous ..." > sur le bureau
    ----> http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.rar
    Dézippe-le (= extraire) sur le bureau
    Notes importantes :
    * si tu as téléchargé le programme Elibagla sur ton PC , supprime-le .
    * branche toutes tes unités externes au PC ( DD externes , clé USB , lecteur mp3, etc.) mais sans les ouvrir ! --> Tu les retireras après la manipulation.
    Entre dans le dossier FindyKill
    Double clic sur findyKill.bat

    Choisis l'option 1 (recherche)
    Un rapport va s ouvrir, post le dans ta prochaine réponse stp
    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

    Suppression : (Unités externes toujours branchés ...)
    Rouvre findykill,
    Choisis cette fois-ci l’option 2 (suppression)

    Il y aura 2 redémarrages, laisse travailler l’outil jusqu’à l’apparition du message "nettoyage effectué”
    Un rapport va s’ouvrir, poste-le dans ta prochaine réponse stp
    Note : le rapport FindyKill.txt est sauvegardé à la racine du disque

    ELIBAGLA ensuite
    Terminer par Malwarebytes Anti-Malware
    Et un nouveau ComboFix

    Merci
    Al.
    4
    1. Jeanphi78 Messages postés 5 Statut Membre
       
      Bonsoir,

      J'ai utilisé FindyKill et voici le rapport:



      ----------------- FindyKill V3.O75 -----------------


      Suppression effectuée à 23:22:36 le 12/09/2008
      Emplacement : C:\Documents and Settings\Jean-Philippe NEAV\Bureau\FindyKill\FindyKill.bat
      Outils Mis a jours le 11/09/08




      ------------*** Suppression ***-------------




      »»»» Suppression des fichiers dans C:


      »»»» Suppression des fichiers dans C:\WINDOWS


      »»»» Suppression des fichiers dans C:\WINDOWS\Prefetch

      Supprime ! - C:\WINDOWS\Prefetch\HLDRRR.EXE-????????.pf

      »»»» Suppression des fichiers dans C:\WINDOWS\system32


      »»»» Suppression des fichiers dans C:\WINDOWS\system32\drivers


      »»»» Suppression des fichiers dans C:\Documents and Settings\Jean-Philippe NEAV\Application Data



      ------------*** Verification ***-------------




      »»»» Suppression des fichiers dans C:\WINDOWS


      »»»» Presence des fichiers dans C:


      »»»» Presence des fichiers dans C:\WINDOWS\Prefetch


      »»»» Presence des fichiers dans C:\WINDOWS\system32


      »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers


      »»»» Presence des fichiers dans C:\Documents and Settings\Jean-Philippe NEAV\Application Data



      »»»» Suppression des clefs du registre..


      "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA " - Supprime !
      "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Hardware Profiles\0001\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA " - Supprime !


      »»»» Suppression des clefs du registre effectuée !


      »»»» Affichage des fichiers cachés réparé !


      »»»» Services de securité Windows redemarré !


      »»»» Suppression des fichiers temporaires :


      Supprimé ! - "C:\WINDOWS\TEMP\Perflib_Perfdata_26c.dat"
      Supprimé ! - "C:\WINDOWS\TEMP\Perflib_Perfdata_2dc.dat"
      Supprimé ! - "C:\WINDOWS\TEMP\WGAErrLog.txt"
      Supprimé ! - "C:\WINDOWS\TEMP\WGANotify.settings"
      Supprimé ! - "C:\WINDOWS\TEMP\ZLT02296.TMP"
      Supprimé ! - "C:\WINDOWS\TEMP\ZLT0229a.TMP"
      Supprimé ! - "C:\WINDOWS\TEMP\ZLT06e49.TMP"
      Supprimé ! - "C:\WINDOWS\TEMP\ZLT06e4d.TMP"



      »»»» Suppression des fichiers dans Support amovible :



      ---------- ! Nettoyage realisé avec succès ! ----------


      »»»» Recherche d autres infections :


      C:\Documents and Settings\Jean-Philippe NEAV\Recent\cracked.nfo.lnk


      -------------- ! Fin du rapport ! ---------------

      Ensuite j'ai lancé ELIBAGLA dont voici le rapport:


      Fri Sep 12 23:33:13 2008
      EliBagle v11.71 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 12 de Septiembre del 2008)
      ----------------------------------------------
      Lista de Acciones (por Acción Directa):

      Fri Sep 12 23:33:14 2008
      EliBagle v11.71 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 12 de Septiembre del 2008)
      ----------------------------------------------
      Lista de Acciones (por Exploración):
      Explorando Unidad C:\

      Nº Total de Directorios: 7628
      Nº Total de Ficheros: 83522
      Nº de Ficheros Analizados: 11760
      Nº de Ficheros Infectados: 0
      Nº de Ficheros Limpiados: 0

      Puis j'ai lancé Malwarebytes Anti-Malware et voici le résultat:

      Malwarebytes' Anti-Malware 1.28
      Version de la base de données: 1142
      Windows 5.1.2600 Service Pack 2

      13/09/2008 00:15:33
      mbam-log-2008-09-13 (00-15-33).txt

      Type de recherche: Examen complet (C:\|D:\|)
      Eléments examinés: 117788
      Temps écoulé: 31 minute(s), 11 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 2
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 0

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\MyWay (Adware.MyWay) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Et enfin j'ai lancé ComboFix:

      ComboFix 08-09-11.02 - Jean-Philippe NEAV 2008-09-13 0:17:12.2 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.618 [GMT 2:00]
      Endroit: C:\Documents and Settings\Jean-Philippe NEAV\Bureau\CaumbauFeex.exe

      [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\InfoSat.txt

      .
      ((((((((((((((((((((((((((((( Fichiers créés 2008-08-12 to 2008-09-12 ))))))))))))))))))))))))))))))))))))
      .

      2008-09-12 23:42 . 2008-09-12 23:42 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
      2008-09-12 23:42 . 2008-09-12 23:42 <REP> d-------- C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Malwarebytes
      2008-09-12 23:42 . 2008-09-12 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
      2008-09-12 23:42 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
      2008-09-12 23:42 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
      2008-08-24 01:28 . 2008-09-07 12:59 13 --a------ C:\WINDOWS\msgtn.ini
      2008-08-24 01:26 . 2008-09-12 21:00 <REP> d-------- C:\Documents and Settings\Jean-Philippe NEAV\Application Data\ppstream
      2008-08-13 18:39 . 2008-05-01 16:31 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-09-12 21:22 36,868,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
      2008-09-12 21:22 197,108 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
      2008-09-12 17:52 --------- d-----w C:\Program Files\MSN Messenger
      2008-09-12 17:07 --------- d-----w C:\Program Files\eMule
      2008-09-11 05:22 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\AdobeUM
      2008-09-10 18:27 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Azureus
      2008-08-11 19:44 --------- d-----w C:\Program Files\QuickMediaConverter
      2008-08-11 18:42 --------- d-----w C:\Program Files\ProjectX_0.90.4.00
      2008-08-10 16:20 --------- d-----w C:\Program Files\NetDrive
      2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
      2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
      2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
      2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
      2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
      2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
      2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
      2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
      2008-07-07 20:18 253,952 ----a-w C:\WINDOWS\system32\es.dll
      2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
      2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
      2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
      2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
      .

      ((((((((((((((((((((((((((((( snapshot@2008-09-12_22.12.16.43 )))))))))))))))))))))))))))))))))))))))))
      .
      + 2008-09-12 21:24:15 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_26c.dat
      .
      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
      "{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-07-04 66912]

      [HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
      2008-07-04 23:46 66912 --a------ C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
      "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
      "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-17 761945]
      "THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
      "Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-11-30 73728]
      "SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 118784]
      "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
      "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
      "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
      "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
      "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
      "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 919016]
      "WebDriveTray"="C:\Program Files\NetDrive\netdrive.exe" [2003-06-04 294912]
      "RTHDCPL"="RTHDCPL.EXE" [2005-12-10 C:\WINDOWS\RTHDCPL.exe]
      "AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 C:\WINDOWS\agrsmmsg.exe]
      "TPSMain"="TPSMain.exe" [2005-08-03 C:\WINDOWS\system32\TPSMain.exe]
      "NDSTray.exe"="NDSTray.exe" [BU]
      "TFncKy"="TFncKy.exe" [BU]
      "TDispVol"="TDispVol.exe" [2005-09-15 C:\WINDOWS\system32\TDispVol.exe]
      "CFSServ.exe"="CFSServ.exe" [BU]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "VIDC.VP40"= vp4vfw.dll

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
      @="Driver"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
      @="Driver"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
      @="Driver"

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusDisableNotify"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "C:\\Program Files\\eMule\\emule.exe"=
      "C:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
      "C:\\Program Files\\MSN Messenger\\livecall.exe"=
      "C:\\Program Files\\Kingsoft\\Powerword 2007\\xdict.exe"=
      "C:\\Program Files\\Kingsoft\\Powerword 2007\\update.exe"=
      "C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
      "C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=

      R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
      R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
      R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-05 14336]
      R2 WebDriveFSD;WebDrive File System Driver;C:\Program Files\NetDrive\rffsd.sys [2002-11-27 67032]
      S2 FILESpy;FILESpy;C:\Program Files\Softwin\BitDefender9\filespy.sys [ ]
      S3 DTVFW;DVB-T USB adapter firmware;C:\WINDOWS\system32\DRIVERS\dtvfw.sys [2005-11-30 22016]
      S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2005-04-21 112384]
      S3 usbdtv;DVB-T TV Tuner;C:\WINDOWS\system32\Drivers\usbdtv.sys [2005-11-30 31232]

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
      UxTuneUp
      .
      Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
      .
      .
      ------- Supplementary Scan -------
      .
      FireFox -: Profile - C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Mozilla\Firefox\Profiles\yv2v9op7.default\
      FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
      FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.fr/
      .

      **************************************************************************

      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-09-13 00:20:24
      Windows 5.1.2600 Service Pack 2 NTFS

      Balayage processus cachés ...

      Balayage caché autostart entries ...

      Balayage des fichiers cachés ...

      Scan terminé avec succès
      Les fichiers cachés: 0

      **************************************************************************
      .
      --------------------- DLLs a chargé sous des processus courants ---------------------

      PROCESS: C:\WINDOWS\system32\winlogon.exe
      -> C:\WINDOWS\system32\RFHelper.dll
      .
      Temps d'accomplissement: 2008-09-13 0:22:21
      ComboFix-quarantined-files.txt 2008-09-12 22:22:04
      ComboFix2.txt 2008-09-12 20:12:40

      Pre-Run: 2,550,861,824 octets libres
      Post-Run: 2,533,089,280 octets libres

      153 --- E O F --- 2008-09-11 01:04:19

      Pensez-vous que les virus ont été supprimés?

      Merci

      JP
      0
  2. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Salut JP

    Parfait
    Merci pour l'ordre de ces applications

    Supprime FindyKill et Elibagla

    Ensuite, tu as toujours l'icône de ComboFix sur le bureau (CaumbauFeex.exe).

    1°- PREALABLES :
    A)-Désactiver le TeaTimer
    ==> Si tu n'as pas Spybot S&D, passe outre de cette partie !
    ==> Si tu as Spybot S&D.
    •- Tout d'abord > Désactive le Tea-Timer de Spybot en passant par les options de Spybot: une fois dans le logiciel, il faut aller dans le menu "Mode" => coche "Mode avancé" => "Outils"(en bas de page)=> "Résident" => et tu décoches cette case: "Résident Teatimer" . Tu ne dois plus voir l'icône du Tea- Timer dans la barre de tâches!
    •- Ne fais pas l'impasse sur cette étape, car ça peut faire échouer la procédure de désinfection !
    B)- ==> Désactive provisoirement (et seulement le temps de l'utilisation de ComboFix), la protection en temps réel de ton Antivirus et de ton Antispywares, (activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil).

    2°- Désactive ta restauration système comme ceci:
    Clic sur « Démarrer »
    Clic droit sur « Poste de travail », puis sur « Propriétés »,
    Vas sur l’onglet « Restauration système »
    Tu y coches la case « Désactiver la restauration »
    Termine par [Appliquer] [OK]

    3°- Sélectionne (mettre en surbrillance) tout le texte en caractères gras suivant :

    File::
    C:\Documents and Settings\Jean-Philippe NEAV\Recent\cracked.nfo.lnk

    Folder::
    C:\Program Files\AskSBar

    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"=-
    [-HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]


    4°- Copie le texte sélectionné (CTRL+C) ==> en appuyant simultanément sur les touches CTRL et C.
    Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
    Colle (bien dans le coin supérieur gauche) ce texte dans ce bloc-notes (CTRL+V) ==> en appuyant simultanément sur les touches CTRL et V .
    Sauvegarde (enregistre-le sur le bureau) sous le nom CFScript1.txt
    • Regarde ici (ce n’est qu’un exemple !) < http://img509.imageshack.us/img509/5984/screenshot332wc3.png >

    5°- Ensuite, dépose ce fichier texte sur l'application de ComboFix (icône rouge “ComboFix.exe” sur le bureau -CaumbauFeex.exe- ) en faisant un “glisser/déposer” de ce fichier “ gras>CFScript1.txt</gras> ” sur le fichier “ComboFix.exe” comme sur la capture: < http://apu.mabul.org/up/apu/2008/08/12/img-210914jjufm.gif >
    L'icône ComboFix.exe (CaumbauFeex.exe) change alors de "brillance" dans sa couleur.
    Un module s'affiche ==> clic sur "Exécuter"

    Patiente le temps du scan.
    Le bureau va disparaître à plusieurs reprises: c'est normal!

    (CAUTION: Do not mouse-click ComboFix's window while it is running. = Ne touche à rien tant que le scan n'est pas terminé. That may cause it to stall.)

    6°- Une fois le scan achevé, un rapport va s'afficher: poste son contenu sur le forum.
    Si le fichier n'apparaît pas, il se trouve ici > C:\ComboFix.txt

    7°- Arrêter puis redémarrer le PC

    8°- Termine avec ce "Scan en ligne de Kaspersky" https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr sous "Internet Explorer".
    Il faut utiliser la version 7 disponible sur ce lien : href= http://www.kaspersky.com/virusscanner' target='_blank' rel='nofollow'>https://www.kaspersky.fr/downloadshttps://www.kaspersky.fr/downloads</a>
    Branche ton Disque Externe (clé USB) éventuellement
    - Clique sur "Démarrer Online-Scanner" (en bas à droite de la page) .
    - Clique maintenant sur "J'accepte".
    - Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
    - Patiente pendant l'installation des "Mises à jour".
    Clic sur « Paramètres d'analyse »
    Coche la case "Étendue" >> Ok
    - Choisis par la suite l'analyse du "Poste de travail" pour faire un « Scan complet ».
    - Sauvegarde puis colle le rapport généré en fin d'analyse.
    http://i204.photobucket.com/albums/bb106/Juliet702/Kas-SaveReport-1.gif
    http://i204.photobucket.com/albums/bb106/Juliet702/Kas-Savetxt.gif

    AIDE : Configurer le contrôle des ActiveX < http://www.inoculer.com/activex.php3 >
    Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html , ou là : https://forum.pcastuces.com/sujet.asp?f=25&s=37641 (par Morgane & nico_dodo)

    NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.

    Réactive tes protections désactivées au début .
    Ne réactive pas la restauration système maintenant (je dois lire le rapport Kaspersky d'abord).

    Merci
    Al.
    3
  3. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Re,

    Parfait

    A)- Supprime ToolBar-S&D

    B)- Désinstalle ComboFix comme ceci:
    Supprime le dossier Qoobox. (il est à la racine de ton disque dur c:\)
    Supprime l'application téléchargée sur le bureau (ComboFix.exe)
    Fais Démarrer/Exécuter copie-colle la commande suivante puis OK
    "%userprofile%\Bureau\combofix.exe" /u
    Ca désinstallera ComboFix, Supprimera les points de restauration système (qui sont infectés) et remettra les options de sécurité de Windows par défaut.

    C)- Pour en avoir le cœur net, désinstalle Symantec/Norton comme ceci:
    Télécharge ce fichier ftp://ftp.symantec.com/public/francais/removal_tools/Norton_Removal_Tool.exe et lance-le.
    (Tu n'as pas besoin du CD. Il faut que tu télécharges et que tu exécutes le fichier Norton_removal.)

    D)- Grosse faille de sécurité

    1°- C:\Program Files\Adobe\Acrobat 7.0\Reader
    Il faut faire la mise à jour version 9 https://get2.adobe.com/reader/otherversions/
    L'installation d' une nouvelle version désinstallera l' ancienne si besoin est.
    - Décocher "Téléchargez également :Adobe Photoshop® Album Édition"
    - Dans Ajout/Suppression des programmes tu supprimes toutes les autres versions.

    2°- Vérifie aussi si ta console JAVA est à jour; comme ceci:
    Dernière version Java Runtime Environment 1.6.0.7 disponible ici :
    https://filehippo.com/download_jre_32/?ex=CORE-116.0
    Ensuite, vas dans "Panneau de configuration" > "Ajout/suppr.de programmes", et supprime tes anciennes versions

    E)- Encore, remplace AVAST comme ceci:
    Avast ne te sert pas à grand-chose (sinon à t'avertir qu'il a laissé infecter ton PC !!).

    1)- Télécharger ANTIVIR à partir de ce lien et tuto http://www.libellules.ch/tuto_antivir.php

    Autres TUTORIELS :
    < https://www.astucesinternet.com/modules/news/article.php?storyid=253 > ==> enregistre-le sur ton bureau pour y accéder facilement.
    - ou < http://www.malekal.com/tutorial_antivir.html >
    - ou < http://www.vista-xp.fr/forum/topic227.html >

    2)- Désinstaller AVAST: <
    https://www.avast.com/fr-fr/uninstall-utility >

    3)- Attention, après le téléchargement, il faut se déconnecter du Net ( débrancher éventuellement le modem ) avant de lancer l'installation.

    - Attention : Sers-toi du tutoriel pour installer ANTIVIR,

    4)- Procédure d'utilisation:
    Après l'installation du programme et avant de lancer l'analyse, ...
    ...il faut redémarrer le PC en mode sans échec, comme ceci:
    < http://www.coupdepoucepc.com/modules/news/article.php?storyid=253 >

    L'analyse:
    - Lancer Antivir en Scan complet (analyse avancée) en faisant un click-droit sur l’icône d’Antivir dans la « barre des taches » en bas à droite (= Systray, à côté de l’horloge) puis clic sur « start Antivir »
    - Cliquer sur l’onglet « scanner »
    - Vérifier pour « RootKit search » et « Manuelle détection » (en développant avec la petite croix devant chacun d'eux) que tous les disques durs soient bien cochés, puis cliquer sur la loupe (en dessous de statut) .
    (Note : Pour activer l'antirootkit : aller dans CONFIGURATION puis EXPERT MODE puis SCAN et cocher la case SEARCH FOR ROOTKIT...)
    - Une fenêtre va s’ouvrir « Luke Filewalker »
    - Le scan va démarrer.
    - Mettre tout ce qu il trouve en "quarantine"

    Le rapport:
    Une fois le scan achevé, fermer les deux fenêtres d'Antivir et sauvegarder sur le bureau le rapport qui vient d'apparaître.
    Redémarrer en mode normal puis poster le rapport d'Antivir (qui est sur le bureau).

    Voici un lien pour ne plus avoir de popup intempestif pour acheter la version payante lors des mises à jour https://forum.malekal.com/viewtopic.php?p=45326#p45326

    F)- Termine par Malwarebyte's Anti-Malware en mode sans échec pour une analyse complète du PC avec tes clés USB branchées.
    Télécharge et installe Malwarebyte's Anti-Malware
    http://www.malwarebytes.org/mbam/program/mbam-setup.exe
    Suivre ce tutoriel https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm

    G)- ATTENTION
    Ensuite réactive ta restauration système; comme ceci:
    (Clic-droit sur « Poste de travail », puis clic sur « Propriétés »,
    Vas sur l’onglet « Restauration système »
    Tu décoches la case « Désactiver la restauration »
    Termine par [Appliquer], attendre, terminer par [OK]
    )

    Je crois que ton PC est désinfecté.
    Courage
    Bonne nuit

    Al.

    Précautions

    A)- Le malware Beagle est en réalité un ver informatique se propageant essentiellement par :
    - les logiciels p2p
    - via de faux cracks (=logiciels piratés !)
    - ainsi que par mail.
    L'internaute croyant « télécharger un crack pour un logiciel en faisant une recherche via un logiciel p2p » installe lui-même le ver sur son ordinateur ; car le fichier.exe contenu dans l'archive est en réalité le ver Beagle !
    Les noms des logiciels crackés sont très divers et touchent une gamme assez étendue de type de programme.

    B)- 2°- --> Plus que jamais, il devient ESSENTIEL d'éviter tous les sites de cracks, warez, ...
    3°- Pour t'en convaincre, lis le contenu très clair de ces liens:
    •- les premiers sont de Malekal_morte et concernent les cracks =>
    http://forum.malekal.com/ftopic4869.php
    http://forum.malekal.com/ftopic893.php
    http://forum.malekal.com/ftopic4442.php
    •- le second de Tesgaz concerne le P2P en général =>
    https://forum.zebulon.fr/topic/85544-pr%C3%A9vention-le-p2p-et-ses-cons%C3%A9quences/
    * Le P2P ( l'utilisation de logiciels comme eMule, Sharazaa, LimeWire, Bit torrent):
    Les infections véhiculées pas le p2p sont une menace réelle!! par exemple le vers "Worm.Win32_Sumom-A" qui est un ver de messagerie instantanée et de réseaux peer-to-peer,se met dans le dossier "incoming/Shared" afin d'être expédié à toutes les personnes qui partagent tes téléchargements...
    L’infection « Worm.Win32_Sumom-A » => http://www.virustraq.com/info_virus/10134/details/
    Pourquoi éviter le P2P : http://www.speedweb1.org/forum-tesgaz/viewtopic.php?t=1793

    C)- À propos des clés USB

    /!\ Ne double clique surtout pas sur les icônes pour les ouvrir, sous peine de relancer l'infection.
    Il est souhaitable de prendre l'habitude de faire "clic-droit > ouvrir"./!\

    Citation (merci Malekal_morte):

    1°- QUESTION: si j'ai bien compris, quand je vais sur un PC qui me semble être à risques, il suffit de ne pas double-cliquer sur les dossiers ou sur ma clé pour éviter d'activer ce virus ?
    2°- RÉPONSE: Non, ce serait trop facile.
    - Si tu vas avec ta clef USB sur un PC pourri, c'est fini, elle est infectée.
    - En revanche, si tu vas sur ton PC à toi qui est propre avec ta clef USB infectée et que tu n'ouvres pas en double-cliquant (ou s'il n'y a pas l'ouverture automatique), alors le PC ne sera pas infecté.
    MAIS la clef restera infectée par contre.
    Tout est expliqué ici: < https://forum.malekal.com/viewtopic.php?f=45&t=5544 >
    3°- COMMENTAIRES ET RECOMMANDATIONS:
    a)- Je pense que les PC à l'école, ou à la bibliothèque du quartier, là où vous avez le droit d'y connecter vos clefs USB, sont infectés.
    b)- Si tu veux te protéger, tu crées un fichier "autorun.inf sur ta clef USB" comme expliqué dans la page que je t'ai donnée.
    Ta clef ne pourra pas être infectée.
    Note de Afideg: Je ne l'ai jamais fait ==> donc, pas de question à ce sujet SVP. Merci. ;)

    2
  4. totobetourne Messages postés 5677 Statut Membre 65
     
    bonsoir

    si tu as des crackc vire les car beagle s attrape assez souvent avec des cracks infectes.

    1)refais maintenant elibagla..

    1er Méthode : ELIBAGLA

    Renommer ELIBAGLA

    * Voici en avant-première une astuce capable de rendre Elibagla plus efficace face aux variantes Bagle !
    * Il suffit de le renommer en utilisant le même nom qu'un des fichiers faisant partie de l'infection: ici mdelk.exe et le rootkit sera incapable de faire la différence avec le fichier de l'infection qui porte le même nom et qui lui autorise donc un champ d'action beaucoup plus important.
    * Elibagla ainsi renommé sera capable en un seul passage de neutraliser totalement l'infection. Il suffit ensuite d'un redémarrage du PC et d'un second scan pour supprimer les restes de l'infection.
    * A noter que cette astuce marche uniquement si l'exe d'Elibagla est correctement renommé en mdelk.exe !

    * Téléchargez ELIBAGLA (by SATINFO) en bas de cette page : http://www.zonavirus.com/datos/descargas/95/elibagla.asp
    * Cliquez sur le bouton Descargar Elibagla pour télécharger le fichier, placez le sur votre bureau.
    * Double-cliquez dessus pour l'ouvrir
    * Assurez-vous que dans le menu déroulant Unidad, vous avez bien C:\ (ou la partition contenant le système d'exploitation)
    * Vérifiez aussi que l'option en bas de la fenêtre Eliminar Ficheros Automaticamente est bien cochée
    * Cliquez sur le bouton Explorar pour lancer l'analyse, à la fin du scan, un rapport est généré, nommé infosat.txt, il est en outre sauvegardé sous la racine : C:\infosat.txt

    Exemple d'un rapport contenant des fichiers infectés :

    Thu Feb 28 21:49:09 2008
    EliBagle v11.08 (c)2008 S.G.H. / Satinfo S.L.
    ----------------------------------------------
    Lista de Acciones (por Acción Directa):
    C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Acceso Denegado.
    C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
    C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado.
    C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado.
    Restaurada Clave: "SafeBoot\Minimal y Network"
    Reinicie para Completar la Limpieza.

    Thu Feb 28 21:49:48 2008
    EliBagle v11.08 (c)2008 S.G.H. / Satinfo S.L.
    ----------------------------------------------
    Lista de Acciones (por Exploración):
    Explorando Unidad C:\
    C:\Program Files\ATI Technologies\ATI Control Panel\ATIPTAXX.EXE --> Eliminado Bagle.dldr
    C:\WINDOWS\system32\MDELK.EXE --> Acceso Denegado, Bagle (Reiniciar para completar la Limpieza)
    C:\WINDOWS\system32\WINTEMS.EXE --> Acceso Denegado, Bagle (Reiniciar para completar la Limpieza)

    Nº Total de Directorios: 7505
    Nº Total de Ficheros: 82386
    Nº de Ficheros Analizados: 12450
    Nº de Ficheros Infectados: 3
    Nº de Ficheros Limpiados: 3

    * Exploitation du rapport :
    o la mention : Eliminado Bagle signifie que la composante du ver a bien été supprimée
    o la mention : Bagle Acceso Denegado signifie que l'accès à ce fichier est refusé, il n'a donc pas été supprimé
    o la mention : Acceso Denegado, Bagle (Reiniciar para completar la Limpieza) signifie qu'il faut repasser l'outil pour en arriver à bout !
    o Elibagla a la capacité de réparer la clé safeboot supprimer par bagle, si c'est le cas, la mention suivante apparait dans le rapport : Restaurada Clave: "SafeBoot\Minimal y Network"

    Remarque : il est très important de passer plusieurs fois Elibagla en mode normal, ainsi qu'en mode sans échec si possible afin d'essayer de supprimer le plus de fichiers infectés possible !

    Dans notre exemple, Elibagla n'est pas arrivé à bout de l'infection du 1er coup, nous allons voir dans la suite comment d'autres outils peuvent venir compéter la suppression du ver Bagle.

    2)Telecharges malwares bytes anti malwares :

    Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
    fais comme indique,mise a jour , scan complet en mode sans echec et les rapports.

    garde le et lance un scan tout les mois comme indique.

    si tu as ad aware tu peux desinstalle car il ne reconnait plus grand chose.

    3)telecharge cela:util pour voir ce que peut etre l infection et agir ensuite.

    http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

    installe le normallement comme tout autre programme dans c/programme/...............
    clique sur do a scan and save a logfile, tu obtiens un rapport que tu colles.
    parfois alerte comme quoi, sans la fonction administrateur le rapport ne peut pas etre complet .
    a ce moment relance hijack avec un clique droit sur le raccourci et executer en tant qu administrateur.
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Allo ?
    Et alors ?
    Puis-je quitter enfin le PC ? --> je suis gelé !!
    Al.
    0
  7. Jeanphi78 Messages postés 5 Statut Membre
     
    Bonsoir AL,

    Désolé j'ai des fausses manips pendant le scan avec Kapersky. Finalement c'est fait et voici les rapports de ComboFix et Kapersky:
    1)ComboFix:

    ComboFix 08-09-11.02 - Jean-Philippe NEAV 2008-09-13 16:39:55.3 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.557 [GMT 2:00]
    Endroit: C:\Documents and Settings\Jean-Philippe NEAV\Bureau\CaumbauFeex.exe
    Command switches used :: C:\Documents and Settings\Jean-Philippe NEAV\Bureau\CFScript1.txt
    * Création d'un nouveau point de restauration

    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
    .

    ((((((((((((((((((((((((((((( Fichiers créés 2008-08-13 to 2008-09-13 ))))))))))))))))))))))))))))))))))))
    .

    2008-09-13 16:28 . 2008-09-13 16:28 <REP> d-------- C:\Program Files\AskSBar
    2008-09-12 23:42 . 2008-09-12 23:42 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-09-12 23:42 . 2008-09-12 23:42 <REP> d-------- C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Malwarebytes
    2008-09-12 23:42 . 2008-09-12 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-09-12 23:42 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-09-12 23:42 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-08-24 01:28 . 2008-09-07 12:59 13 --a------ C:\WINDOWS\msgtn.ini
    2008-08-24 01:26 . 2008-09-12 21:00 <REP> d-------- C:\Documents and Settings\Jean-Philippe NEAV\Application Data\ppstream
    2008-08-13 18:39 . 2008-05-01 16:31 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-13 07:29 --------- d-----w C:\Program Files\Freeplayer
    2008-09-13 06:44 36,868,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
    2008-09-13 06:44 199,724 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
    2008-09-13 06:33 --------- d-----w C:\Program Files\FreeRIP2
    2008-09-13 06:33 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
    2008-09-13 06:31 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Lavasoft
    2008-09-12 22:42 1,406,330 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
    2008-09-12 17:52 --------- d-----w C:\Program Files\MSN Messenger
    2008-09-12 17:07 --------- d-----w C:\Program Files\eMule
    2008-09-11 05:22 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\AdobeUM
    2008-09-10 18:27 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Azureus
    2008-08-10 16:20 --------- d-----w C:\Program Files\NetDrive
    2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
    2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
    2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
    2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
    2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
    2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
    2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
    2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
    2008-07-07 20:18 253,952 ----a-w C:\WINDOWS\system32\es.dll
    2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
    2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
    2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-09-12_22.12.16.43 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-01-17 15:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
    + 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
    + 2008-09-13 07:25:55 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_130.dat
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
    "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
    "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-17 761945]
    "THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
    "Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-11-30 73728]
    "SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 118784]
    "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 919016]
    "WebDriveTray"="C:\Program Files\NetDrive\netdrive.exe" [2003-06-04 294912]
    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
    "RTHDCPL"="RTHDCPL.EXE" [2005-12-10 C:\WINDOWS\RTHDCPL.exe]
    "AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 C:\WINDOWS\agrsmmsg.exe]
    "TPSMain"="TPSMain.exe" [2005-08-03 C:\WINDOWS\system32\TPSMain.exe]
    "NDSTray.exe"="NDSTray.exe" [BU]
    "TFncKy"="TFncKy.exe" [BU]
    "TDispVol"="TDispVol.exe" [2005-09-15 C:\WINDOWS\system32\TDispVol.exe]
    "CFSServ.exe"="CFSServ.exe" [BU]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.VP40"= vp4vfw.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=
    "C:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Program Files\\Kingsoft\\Powerword 2007\\xdict.exe"=
    "C:\\Program Files\\Kingsoft\\Powerword 2007\\update.exe"=
    "C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
    "C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=

    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
    R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-05 14336]
    R2 WebDriveFSD;WebDrive File System Driver;C:\Program Files\NetDrive\rffsd.sys [2002-11-27 67032]
    S2 FILESpy;FILESpy;C:\Program Files\Softwin\BitDefender9\filespy.sys [ ]
    S3 DTVFW;DVB-T USB adapter firmware;C:\WINDOWS\system32\DRIVERS\dtvfw.sys [2005-11-30 22016]
    S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2005-04-21 112384]
    S3 usbdtv;DVB-T TV Tuner;C:\WINDOWS\system32\Drivers\usbdtv.sys [2005-11-30 31232]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    *Newly Created Service* - ASWUPDSV
    *Newly Created Service* - AVAST!_ANTIVIRUS
    *Newly Created Service* - AVAST!_MAIL_SCANNER
    *Newly Created Service* - AVAST!_WEB_SCANNER
    .
    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-13 16:43:38
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************
    .
    --------------------- DLLs a chargé sous des processus courants ---------------------

    PROCESS: C:\WINDOWS\system32\winlogon.exe
    -> C:\WINDOWS\system32\RFHelper.dll

    PROCESS: C:\WINDOWS\explorer.exe
    -> C:\WINDOWS\system32\TDispVol.dll
    .
    Temps d'accomplissement: 2008-09-13 16:45:05
    ComboFix-quarantined-files.txt 2008-09-13 14:44:58
    ComboFix2.txt 2008-09-12 22:22:23
    ComboFix3.txt 2008-09-12 20:12:40

    Pre-Run: 4,001,849,344 octets libres
    Post-Run: 4,043,808,768 octets libres

    152 --- E O F --- 2008-09-11 01:04:19
    2) Kapersky:
    KASPERSKY ONLINE SCANNER 7 REPORT
    Saturday, September 13, 2008
    Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Saturday, September 13, 2008 14:46:04
    Records in database: 1220742

    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area My Computer
    C:\
    D:\

    Scan statistics
    Files scanned 83869
    Threat name 9
    Infected objects 10
    Suspicious objects 0
    Duration of the scan 00:49:47

    File name Threat name Threats count
    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\07ED268B.htm Infected: Trojan-Downloader.VBS.Small.dr 1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27CF2ABA.tmp Infected: Trojan-Downloader.Win32.Bagle.ba 1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2F940C2E.tmp Infected: Trojan-Downloader.Win32.Bagle.ba 1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6A722DA1.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1

    C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-54e206d6-75399207.zip Infected: Exploit.Java.Gimsh.a 1

    C:\Program Files\eMule\Incoming\video\softwares\pda\Ce Star v2.8.zip Infected: Trojan-Downloader.Win32.IstBar.us 1

    C:\Program Files\eMule\Incoming\video\softwares\Soft Divx\TS_vers_DVD.zip Infected: not-a-virus:AdWare.Win32.Rabio.es 1

    C:\System Volume Information\_restore{D475D116-DF88-45C4-8BF3-9AB6FC089BD7}\RP2\A0000077.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 1

    C:\System Volume Information\_restore{D475D116-DF88-45C4-8BF3-9AB6FC089BD7}\RP2\A0000077.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1

    C:\_JEANPHI\Faurecia\Faurecia Wuxi\archive190804.pst Infected: Email-Worm.Win32.Mydoom.m 1

    The selected area was scanned.

    Voilà, qu'en penses-tu?

    Merci

    JP
    0
  8. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Re,

    Merci
    J'en pense que ça ne va pas comme je le veux.

    ComboFix n'a pas supprimé:
    C:\Program Files\AskSBar
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

    Considérant que ton antivirus soit AVAST, il faut supprimer les traces de Symantec/Norton AntiVirus.

    Relance la même manip (sans le Kaspersky) qu'au post # 4 avec ComboFix, mais en mode sans échec et avec ce nouveau CFSript :

    Folder::
    C:\Program Files\AskSBar
    C:\Documents and Settings\All Users\Application Data\Symantec
    C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Sun\Java\Deployment\cache\javapi
    C:\Program Files\eMule\Incoming\video\softwares\pda\Ce Star v2.8.zip
    C:\Program Files\eMule\Incoming\video\softwares\Soft Divx\TS_vers_DVD.zip
    C:\System Volume Information\_restore{D475D116-DF88-45C4-8BF3-9AB6FC089BD7}\RP2
    C:\_JEANPHI\Faurecia\Faurecia Wuxi\archive190804.pst

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]


    Ensuite Télécharge ToolBar-S&D ( Merci à Eric_71, Angeldark, Sham_Rock et XmichouX )
    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
    Sur ton bureau, impérativement.
    • Double-clique sur ToolBar-SD afin de lancer l'installation, --> un raccourci sera ajouté sur le Bureau.
    • Double-clique dessus pour démarrer l'outil; choisis la langue.

    Tape 1 puis sur la touche [Entrée] afin de lancer la recherche.
    • Patiente jusqu'à la fin de la recherche.
    • À la fin du scan, le rapport s'ouvrira dans le Bloc-notes.
    • Poste ce rapport, par copier/coller, dans ta prochaine réponse.
    • Le rapport se trouve également sous : C:\TB.txt
    ** Aide en images https://sites.google.com/site/toolbarsd/aideenimages

    Suppression des détections de ToolBar SD:

    .Important! .Désactive ton antivirus / antispyware résident / TeaTimer de Spybot (si présent et actif) - Aide en images ==> https://forum.pcastuces.com/default.asp

    * Double clique sur le raccourci de ToolBarSD présent sur ton bureau.

    Au menu principal, choisis l'option 2 et valide par la touche [Entrée].
    /!\ Ne ferme pas la fenêtre lors de la suppression /!\
    • Un rapport sera généré. Poste-le aussi.

    Note 2 : Si ton bureau ne réapparaît pas, fais CTRL+ALT+SUPP pour ouvrir le Gestionnaire de tâches...
    • Rends-toi à l'onglet "Processus", clique en haut à gauche sur -> Fichiers et choisis -> Exécuter...
    • Tape: explorer et valide. Cela te fera apparaître ton Bureau.

    Merci
    0
  9. Jeanphi78 Messages postés 5 Statut Membre
     
    Al,

    Voici les rapports:

    1/ComboFix:


    ComboFix 08-09-11.02 - Jean-Philippe NEAV 2008-09-13 21:57:39.4 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.611 [GMT 2:00]
    Endroit: C:\Documents and Settings\Jean-Philippe NEAV\Bureau\CaumbauFeex.exe
    Command switches used :: C:\Documents and Settings\Jean-Philippe NEAV\Bureau\CFScript2.txt
    * Création d'un nouveau point de restauration

    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Jean-Philippe NEAV\Cookies\jean-philippe_neav@wysistat[2].txt

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-08-13 to 2008-09-13 ))))))))))))))))))))))))))))))))))))
    .

    2008-09-13 16:28 . 2008-09-13 16:28 <REP> d-------- C:\Program Files\AskSBar
    2008-09-12 23:42 . 2008-09-12 23:42 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-09-12 23:42 . 2008-09-12 23:42 <REP> d-------- C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Malwarebytes
    2008-09-12 23:42 . 2008-09-12 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-09-12 23:42 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-09-12 23:42 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-08-24 01:28 . 2008-09-07 12:59 13 --a------ C:\WINDOWS\msgtn.ini
    2008-08-24 01:26 . 2008-09-12 21:00 <REP> d-------- C:\Documents and Settings\Jean-Philippe NEAV\Application Data\ppstream
    2008-08-13 18:39 . 2008-05-01 16:31 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-13 14:49 36,868,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
    2008-09-13 14:49 201,260 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
    2008-09-13 07:29 --------- d-----w C:\Program Files\Freeplayer
    2008-09-13 06:33 --------- d-----w C:\Program Files\FreeRIP2
    2008-09-13 06:33 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
    2008-09-13 06:31 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Lavasoft
    2008-09-12 22:42 1,406,330 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
    2008-09-12 17:52 --------- d-----w C:\Program Files\MSN Messenger
    2008-09-12 17:07 --------- d-----w C:\Program Files\eMule
    2008-09-11 05:22 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\AdobeUM
    2008-09-10 18:27 --------- d-----w C:\Documents and Settings\Jean-Philippe NEAV\Application Data\Azureus
    2008-08-10 16:20 --------- d-----w C:\Program Files\NetDrive
    2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
    2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
    2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
    2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
    2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
    2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
    2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
    2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
    2008-07-07 20:18 253,952 ----a-w C:\WINDOWS\system32\es.dll
    2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
    2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
    2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-09-12_22.12.16.43 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-01-17 15:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
    + 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
    + 2008-09-13 14:50:27 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_2f0.dat
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
    "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
    "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-17 761945]
    "THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
    "Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-11-30 73728]
    "SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 118784]
    "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 919016]
    "WebDriveTray"="C:\Program Files\NetDrive\netdrive.exe" [2003-06-04 294912]
    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
    "RTHDCPL"="RTHDCPL.EXE" [2005-12-10 C:\WINDOWS\RTHDCPL.exe]
    "AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 C:\WINDOWS\agrsmmsg.exe]
    "TPSMain"="TPSMain.exe" [2005-08-03 C:\WINDOWS\system32\TPSMain.exe]
    "NDSTray.exe"="NDSTray.exe" [BU]
    "TFncKy"="TFncKy.exe" [BU]
    "TDispVol"="TDispVol.exe" [2005-09-15 C:\WINDOWS\system32\TDispVol.exe]
    "CFSServ.exe"="CFSServ.exe" [BU]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.VP40"= vp4vfw.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=
    "C:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Program Files\\Kingsoft\\Powerword 2007\\xdict.exe"=
    "C:\\Program Files\\Kingsoft\\Powerword 2007\\update.exe"=
    "C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
    "C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=

    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
    R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-05 14336]
    R2 WebDriveFSD;WebDrive File System Driver;C:\Program Files\NetDrive\rffsd.sys [2002-11-27 67032]
    S2 FILESpy;FILESpy;C:\Program Files\Softwin\BitDefender9\filespy.sys [ ]
    S3 DTVFW;DVB-T USB adapter firmware;C:\WINDOWS\system32\DRIVERS\dtvfw.sys [2005-11-30 22016]
    S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2005-04-21 112384]
    S3 usbdtv;DVB-T TV Tuner;C:\WINDOWS\system32\Drivers\usbdtv.sys [2005-11-30 31232]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp
    .
    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-13 22:01:05
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************
    .
    --------------------- DLLs a chargé sous des processus courants ---------------------

    PROCESS: C:\WINDOWS\system32\winlogon.exe
    -> C:\WINDOWS\system32\RFHelper.dll
    .
    Temps d'accomplissement: 2008-09-13 22:02:31
    ComboFix-quarantined-files.txt 2008-09-13 20:02:21
    ComboFix2.txt 2008-09-13 14:45:06
    ComboFix3.txt 2008-09-12 22:22:23
    ComboFix4.txt 2008-09-12 20:12:40

    Pre-Run: 5,538,979,840 octets libres
    Post-Run: 5,579,071,488 octets libres

    151 --- E O F --- 2008-09-11 01:04:19

    2/ToolBar-S&D, recherche:

    -----------\\ ToolBar S&D 1.1.9 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
    X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2300 @ 1.66GHz )
    BIOS : BIOS Version 1.60
    USER : Jean-Philippe NEAV ( Administrator )
    BOOT : Normal boot
    Antivirus : avast! antivirus 4.8.1229 [VPS 080913-0] 4.8.1229 (Not Activated)
    Firewall : ZoneAlarm Firewall 7.0.473.000 (Not Activated)

    "C:\ToolBar SD" ( MAJ : 13-09-2008|02:54 )
    Option : [1] ( 13/09/2008|22:06 )

    -----------\\ Recherche de Fichiers / Dossiers ...

    C:\Program Files\AskSBar
    C:\Program Files\AskSBar\bar
    C:\WINDOWS\iun6002.exe

    -----------\\ Extensions

    (Jean-Philippe NEAV) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

    -----------\\ [..\Internet Explorer\Main]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
    "Start Page"="https://www.google.fr/?gws_rd=ssl"
    "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
    "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"

    --------------------\\ Recherche d'autres infections

    Aucune autre infection trouvée !

    1 - "C:\ToolBar SD\TB_1.txt" - 13/09/2008|22:07 - Option : [1]

    -----------\\ Fin du rapport a 22:07:01,50

    3/ToolBar-S&D, suppression:

    -----------\\ ToolBar S&D 1.1.9 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
    X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2300 @ 1.66GHz )
    BIOS : BIOS Version 1.60
    USER : Jean-Philippe NEAV ( Administrator )
    BOOT : Normal boot
    Antivirus : avast! antivirus 4.8.1229 [VPS 080913-0] 4.8.1229 (Not Activated)
    Firewall : ZoneAlarm Firewall 7.0.473.000 (Not Activated)

    "C:\ToolBar SD" ( MAJ : 13-09-2008|02:54 )
    Option : [2] ( 13/09/2008|22:08 )

    -----------\\ SUPPRESSION

    Supprime! - C:\Program Files\AskSBar\bar
    Supprime! - C:\WINDOWS\iun6002.exe
    Supprime! - C:\Program Files\AskSBar

    -----------\\ Recherche de Fichiers / Dossiers ...

    -----------\\ Extensions

    (Jean-Philippe NEAV) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

    -----------\\ [..\Internet Explorer\Main]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
    "Start Page"="https://www.google.fr/?gws_rd=ssl"
    "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
    "Start Page"="https://www.msn.com/fr-fr/"

    --------------------\\ Recherche d'autres infections

    Aucune autre infection trouvée !

    1 - "C:\ToolBar SD\TB_1.txt" - 13/09/2008|22:07 - Option : [1]
    2 - "C:\ToolBar SD\TB_2.txt" - 13/09/2008|22:09 - Option : [2]

    -----------\\ Fin du rapport a 22:09:21,23

    Ca s'est amélioré?

    JP
    0
  10. Jeanphi78 Messages postés 5 Statut Membre
     
    Merci Al pour tout.
    Je me mets à la tâche pour désinstaller et installer ce qu'il faut.

    Bonne nuit,

    JP
    0
  11. Jeanphi78 Messages postés 5 Statut Membre
     
    J'ai fait des scans avec Antivir et Malwarebyte's Anti-Malware et je crois que mon PC est complètement désinfecté:

    Avira AntiVir Personal
    Report file date: dimanche 14 septembre 2008 02:32

    Scanning for 1612438 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Boot mode: Save mode
    Username: Jean-Philippe NEAV
    Computer name: JPNEAV

    Version information:
    BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
    AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
    AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
    LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
    LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
    ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
    ANTIVIR2.VDF : 7.0.6.153 3341312 Bytes 12/09/2008 22:52:24
    ANTIVIR3.VDF : 7.0.6.154 2048 Bytes 12/09/2008 22:52:25
    Engineversion : 8.1.1.28
    AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
    AESCRIPT.DLL : 8.1.0.70 319866 Bytes 13/09/2008 22:52:33
    AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:49
    AERDL.DLL : 8.1.1.1 397683 Bytes 13/09/2008 22:52:32
    AEPACK.DLL : 8.1.2.1 364917 Bytes 15/07/2008 12:58:35
    AEOFFICE.DLL : 8.1.0.23 196987 Bytes 13/09/2008 22:52:31
    AEHEUR.DLL : 8.1.0.51 1397111 Bytes 13/09/2008 22:52:30
    AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:48
    AEGEN.DLL : 8.1.0.36 315764 Bytes 13/09/2008 22:52:28
    AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:21
    AECORE.DLL : 8.1.1.11 172406 Bytes 13/09/2008 22:52:26
    AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:48
    AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
    AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
    AVREP.DLL : 8.0.0.2 98344 Bytes 13/09/2008 22:52:25
    AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
    AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
    AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
    SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
    NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
    RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
    RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: on
    Scan boot sector.................: on
    Boot sectors.....................: C:,
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: on
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: dimanche 14 septembre 2008 02:32

    Starting search for hidden objects.
    The driver could not be initialized.

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'WISPTIS.EXE' - '1' Module(s) have been scanned
    Scan process 'MSPVIEW.EXE' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    14 processes with 14 modules were scanned

    Starting master boot sector scan:
    Master boot sector HD0
    [INFO] No virus was found!

    Start scanning boot sectors:
    Boot sector 'C:\'
    [INFO] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '63' files ).

    Starting the file scan:

    Begin scan in 'C:\'
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\system32\drivers\dtscsi.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\system32\drivers\sptd.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\system32\drivers\sptd9373.sys
    [WARNING] The file could not be opened!

    End of the scan: dimanche 14 septembre 2008 05:17
    Used time: 2:45:34 Hour(s)

    The scan has been done completely.

    7629 Scanning directories
    404728 Files were scanned
    0 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    0 files were moved to quarantine
    0 files were renamed
    4 Files cannot be scanned
    404724 Files not concerned
    8003 Archives were scanned
    4 Warnings
    0 Notes

    puis:

    Malwarebytes' Anti-Malware 1.28
    Version de la base de données: 1142
    Windows 5.1.2600 Service Pack 2

    14/09/2008 08:55:49
    mbam-log-2008-09-14 (08-55-49).txt

    Type de recherche: Examen complet (C:\|D:\|)
    Eléments examinés: 122337
    Temps écoulé: 1 hour(s), 39 minute(s), 11 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Merci encore Al,

    JP
    0
  12. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Re,

    Bonjour JP.

    Content d'avoir pu t'être utile.
    Bon dimanche.

    Al.
    0