Trojan Spy.gen2
RésoluAntivir a détecté un trojan sur mon PC :
C:\Documents and Settings\JEREMY\Local Settings\irdimar.bak Is the TR/Spy.Gen2 Trojan
et il n'arrive pas à m'en séparer :/
J'ai nettoyé avec CCleaner, essayé Malwarebyte, tuneUp, fait un scan en ligne avec Nod32 : tjrs pas de résultat, Antivir détecte tjrs Spy.gen2
A court de solutions, je suis preneur de toute aide pour me dépétrer de ce probleme :)
Jeremy
Ci-dessous mon log Hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:31, on 17/01/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\CSHelper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.noos.fr/abonnes.php
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1\bin\npjpi141.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1\bin\npjpi141.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game05.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} (YYGInstantPlay Control) - http://www.yoyogames.com/downloads/activex/YoYo.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager.CacheManagerCtrl) - https://www.pch.com/games?source=candystand
O20 - AppInit_DLLs: winmm.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: XlashServ (XlashSrv) - Unknown owner - C:\WINDOWS\xlash.exe (file missing)
--
End of file - 7857 bytes
Configuration: Windows XP, IE 7
28 réponses
Une détection par Antivir signale un trojan TR/Spy.Gen2 sur Windows XP SP2, lié au fichier irdimar.bak, et des tentatives de nettoyage qui échouent. Les logs relatent des essais de suppression via ComboFix et Malwarebytes, et des éléments suspects dans HijackThis, notamment des démarrages et des DLL injectées. Un balayage GMER signale des hooks dans winlogon.exe et d’autres processus critiques, avec le driver awtdypow.sys proche d’un rootkit. En l’absence d’un outil de réparation fiable, une réinstallation complète ou un formatage après sauvegarde des données pourrait s’imposer.
-
Contributeur sécuritéSalut kearny
Bien de rien, cela a été un plaisir.
Tu t'es fais infecté sur un site web piégé, si ton système aurais été a jour, surement que l'infection aurais passé son chemin.
https://forum.malekal.com/viewtopic.php?t=13629&start=#p104313
Et ton infection :
https://forum.malekal.com/viewtopic.php?t=18337&start=
Bonne lecture
@++ :) -
Merci pour ton aide et tes précieux conseils ! Je te suis infiniment reconnaissant pour la patience que tu as eue pour régler mes petites soucis informatiques :)
Pour les mises à jour système, c'est vrai que je ne suis pas un pro. Je suis meilleur en mise à jour antivirus... parce qu'elle se fait tout seul ! Pour le reste, je suis assez prudent, mais on ne l'est jamais assez, preuve en est.
Encore bravo pour ton travail !
(et je vais valider en résolu)
A très bientot ! (enfin, j'espère, pas trop vite) -
Contributeur sécuritéSalut kearny
Si plus de souci, je te donne quelques consignes de sécurité :
- Windows Update parfaitement à jour http://www.windowsupdate.com/windowsupdate/v6/default.aspx (catégories critique, Services Pack et Services Release)
- pare-feu bien paramétré, je te conseil ZoneAlarm :
https://www.malekal.com/tutoriel-zonealarm-firewall/
- antivirus bien paramétré et mis à jour régulièrement (quotidiennement s'il le faut) avec un scan complet régulier (journalier s'il le faut).
- une attitude prudente vis à vis de la navigation (pas de sites douteux : cracks, warez, sexe...) et vis à vis de la messagerie (fichiers joints aux messages doivent être scannés avant d'être ouverts)
- pas de téléchargement illégal, qui est le principal facteur d’infection (µTorrent, BitTorrent, eMule, Limewire, etc..) http://forum.malekal.com/ftopic893.php
- une attitude vigilante (être à l'affût d'un fonctionnement inhabituel de son système)
- nettoyage hebdomadaire du système (suppression des fichiers inutiles, nettoyage de la base de registre, scandisk, defrag)
- scan hebdomadaire antispyware, je conseil MalwareByte's Anti-Malware :
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
- un contrôle régulier de la console JAVA pour s'assurer qu'elle est à jour :
https://www.java.com/en/download/uninstalltool.jsp
- faire régulièrement un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités :
https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/
De bonne lecture si tu veux en savoir plus sur la sécurité et le fonctionnement de Windows :
http://www.malekal.com/menu_windows_general.php
http://www.malekal.com/menu_windows_securite.php
Si tu considères ton problème comme résolu, tu pourras mettre en résolu :
https://www.commentcamarche.net/infos/25917-marquer-un-fil-de-discussion-comme-etant-resolu/
Bonne journée/soirée et bon surf
@++ :) -
[ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]
--> Recherche:
C:\Combofix.txt: trouvé !
C:\hijackthis.log: trouvé !
C:\SDFIX: trouvé !
C:\_OTM: trouvé !
C:\Rsit: trouvé !
C:\Backups\catchme.log: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\JEREMY\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\JEREMY\Bureau\DiagHelp.zip: trouvé !
C:\Documents and Settings\JEREMY\Bureau\OTM.exe: trouvé !
C:\Documents and Settings\JEREMY\Bureau\ComboFix.exe: trouvé !
C:\Documents and Settings\JEREMY\Bureau\OAD.exe: trouvé !
C:\Documents and Settings\JEREMY\Bureau\DiagHelp: trouvé !
C:\Documents and Settings\JEREMY\Bureau\DiagHelp\catchme.exe: trouvé !
C:\Documents and Settings\JEREMY\Bureau\DiagHelp\mbr.exe: trouvé !
C:\Documents and Settings\JEREMY\Mes documents\hijackthis.log: trouvé !
C:\Downloaded Files\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\SDFix\catchme.exe: trouvé !
C:\WINDOWS\mbr.exe: trouvé !
---------------------------------
--> Suppression:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\JEREMY\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\JEREMY\Bureau\DiagHelp.zip: supprimé !
C:\Documents and Settings\JEREMY\Bureau\OTM.exe: supprimé !
C:\Documents and Settings\JEREMY\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
C:\Documents and Settings\JEREMY\Bureau\DiagHelp\catchme.exe: supprimé !
C:\Downloaded Files\HijackThis.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\SDFix\catchme.exe: supprimé !
C:\Combofix.txt: supprimé !
C:\hijackthis.log: supprimé !
C:\Backups\catchme.log: supprimé !
C:\Documents and Settings\JEREMY\Bureau\OAD.exe: supprimé !
C:\Documents and Settings\JEREMY\Bureau\DiagHelp\mbr.exe: supprimé !
C:\Documents and Settings\JEREMY\Mes documents\hijackthis.log: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\WINDOWS\mbr.exe: supprimé !
C:\SDFIX: supprimé !
C:\_OTM: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\JEREMY\Bureau\DiagHelp: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
Point de restauration crée !
Corbeille vidée!
Fichiers temporaires nettoyés !
Sauvegarde du registre crée !
Il reste quelques programmes sur le bureau, mais je le ferai manuellement (si ajout/suppression de programmes fonctionne bien) Et j'ai fait les mises à jour sur le système et le navigateur. -
Contributeur sécuritéSalut kearny
Cela est bon, ton système n'est pas à jour et est vulnérable au infections.
https://forum.malekal.com/viewtopic.php?f=45&t=3259
Désactive la restauration système sur tous les lecteurs :
- Clique droit sur le Poste de travail sur le bureau, dans propriété tu cliques sur l'onglet Restauration système
- Coche la case désactiver la restauration et applique
Redémarre l’ordinateur et réactive la restauration système.
Tutoriel XP : http://www.libellules.ch/desactiver_restauration.php
----
On va faire un ménage des outils téléchargés pour la désinfection, télécharge Tools Cleaner sur le bureau :
http://pc-system.fr/
- Double clique sur ToolsCleaner2.exe sur le bureau
- Clique sur Recherche et laisse le scan agir.
- Clique sur Suppression pour finaliser.
- Tu peux, si tu le souhaites, te servir des Options facultatives.
- Clique sur Quitter pour obtenir le rapport.
- Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
- Si des outils restes après le passage de Tools Cleaner, tu pourras les supprimer manuellement ainsi que tous les rapports qui on été généré lors de la désinfection.
-----
Important de mettre à jour Windows et tes logiciels :
Mettre Windows(catégories critique, Services Pack et Services Release) à jour : http://www.windowsupdate.com/windowsupdate/v6/default.aspx
Faire un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités et mettre à jour :
https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/
Faire un ménage des fichiers inutiles et de la base de registre :
https://www.malekal.com/tutoriel-ccleaner/
Dis moi quand cela est fais où si tu as des soucis et on passe à la résolution du sujet par la suite.
@++ :) -
Le scan ne passait pas en mode sans échec, je l'ai fait en mode normal, et deux trojans ont été détectés et mis en quarantaine, voila le rapport :
Avira AntiVir Personal
Report file date: mardi 19 janvier 2010 01:00
Scanning for 1566455 virus strains and unwanted programs.
Licensed to: Avira AntiVir Personal - FREE Antivirus
Serial number: 0000149996-ADJIE-0000001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: JEREMY
Version information:
BUILD.DAT : 8.2.0.354 17048 Bytes 23/10/2009 13:15:00
AVSCAN.EXE : 8.1.4.10 315649 Bytes 26/11/2008 17:15:05
AVSCAN.DLL : 8.1.4.0 40705 Bytes 17/07/2008 21:57:20
LUKE.DLL : 8.1.4.5 164097 Bytes 17/07/2008 21:57:22
LUKERES.DLL : 8.1.4.0 12033 Bytes 17/07/2008 21:57:22
ANTIVIR0.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 23:45:56
ANTIVIR1.VDF : 7.10.1.11 1395568 Bytes 19/11/2009 23:46:06
ANTIVIR2.VDF : 7.10.2.224 2514336 Bytes 18/01/2010 23:44:02
ANTIVIR3.VDF : 7.10.2.226 172544 Bytes 18/01/2010 23:44:03
Engineversion : 8.2.1.142
AEVDF.DLL : 8.1.1.2 106867 Bytes 15/09/2009 18:54:51
AESCRIPT.DLL : 8.1.3.7 594296 Bytes 16/01/2010 23:46:41
AESCN.DLL : 8.1.3.1 127348 Bytes 16/01/2010 23:46:39
AESBX.DLL : 8.1.1.1 246132 Bytes 16/01/2010 23:46:38
AERDL.DLL : 8.1.3.4 479605 Bytes 16/01/2010 23:46:37
AEPACK.DLL : 8.2.0.5 422262 Bytes 16/01/2010 23:46:35
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 17/06/2009 22:40:04
AEHEUR.DLL : 8.1.0.195 2232695 Bytes 16/01/2010 23:46:33
AEHELP.DLL : 8.1.10.0 237942 Bytes 16/01/2010 23:46:27
AEGEN.DLL : 8.1.1.83 369014 Bytes 16/01/2010 23:46:26
AEEMU.DLL : 8.1.1.0 393587 Bytes 03/10/2009 11:15:17
AECORE.DLL : 8.1.9.5 184693 Bytes 16/01/2010 23:46:24
AEBB.DLL : 8.1.0.3 53618 Bytes 18/10/2008 22:42:46
AVWINLL.DLL : 1.0.0.12 15105 Bytes 17/07/2008 21:57:20
AVPREF.DLL : 8.0.2.0 38657 Bytes 17/07/2008 21:57:20
AVREP.DLL : 8.0.0.3 155688 Bytes 20/04/2009 18:54:43
AVREG.DLL : 8.0.0.1 33537 Bytes 17/07/2008 21:57:20
AVARKT.DLL : 1.0.0.23 307457 Bytes 15/04/2008 21:03:22
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 17/07/2008 21:57:20
SQLITE3.DLL : 3.3.17.1 339968 Bytes 15/04/2008 21:03:23
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 17/07/2008 21:57:22
NETNT.DLL : 8.0.0.1 7937 Bytes 15/04/2008 21:03:22
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 17/07/2008 21:57:14
RCTEXT.DLL : 8.0.52.0 86273 Bytes 17/07/2008 21:57:14
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: mardi 19 janvier 2010 01:00
The scan of running processes will be started
Scan process 'OneClickStarter.exe' - '0' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
Scan process 'TuneUpUtilitiesApp32.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'OCRAWR32.EXE' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'TuneUpUtilitiesService32.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'CSHelper.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'ntvdm.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
29 processes with 29 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '54' files ).
Starting the file scan:
Begin scan in 'C:\' <SYSTEME>
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\JEREMY\Menu Démarrer\Programmes\Internet Explorer.lnk
[DETECTION] Is the TR/StartPage.KA.3 Trojan
[NOTE] The file was moved to '4bc8f706.qua'!
C:\System Volume Information\_restore{8C16EA5C-C499-4766-A24A-2E01D69CFE5F}\RP751\A0081262.lnk
[DETECTION] Is the TR/StartPage.KA.3 Trojan
[NOTE] The file was moved to '4b84fa3a.qua'!
Begin scan in 'D:\' <DATA>
End of the scan: mardi 19 janvier 2010 01:29
Used time: 29:26 Minute(s)
The scan has been done completely.
5112 Scanning directories
164943 Files were scanned
2 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
2 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
164939 Files not concerned
1024 Archives were scanned
2 Warnings
2 Notes -
Contributeur sécuritéSalut kearny
Effectivement c'est la quarantaine de Combofix, supprime le dossier en gras et vide la corbeille :
c:\Qoobox
Mettre à jour Antivir, faire un scan en mode sans échec et poste le rapport après avoir démarré en mode normal.
Aide : https://www.malekal.com/avira-free-security-antivirus-gratuit/
@++ :) -
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=6.00.2900.5512 (xpsp.080413-2105)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=f0f39f5acd579d428af598019122b98b
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-01-18 02:29:35
# local_time=2010-01-18 03:29:35 (+0100, Paris, Madrid)
# country="France"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 89360 89360 0 0
# compatibility_mode=8192 67108863 100 0 10400 10400 0 0
# compatibility_mode=9217 16777214 0 4 99541049 99541049 0 0
# scanned=75140
# found=0
# cleaned=0
# scan_time=5052
Sinon, j'ai reçu encore des alertes Antivir, moins fréquentes cela dit, sur le fichier irdimar.bak (Spy.gen2) dans le dossier c:\Qoobox. Peut être un dossier de quarantaine créé par Combofix ? -
Contributeur sécuritéSalut kearny
Faire un scan avec Nod32 en ligne (il faut utiliser Internet Explorer) ici :
https://www.eset.com/int/home/online-scanner/
(coche toutes les cases à chaque fois)
A la fin, colle le rapport : C:\Program Files\EsetOnlineScanner\log.txt
@++ :) -
DaonolFix (15.04.09) by jpshortstuff
Log created at 11:21 on 18/01/2010 by JEREMY
Running from C:\Documents and Settings\JEREMY\Bureau\DaonolFix.exe
=====Find Daonol=====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midi"="wdmaud.drv"
"midi1"="wdmaud.drv"
"midimapper"="midimap.dll"
"mixer"="wdmaud.drv"
"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm"
"msacm.msadpcm"="msadp32.acm"
"msacm.msaudio1"="msaud32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msg723"="msg723.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.siren"="sirenacm.dll"
"msacm.sl_anet"="sl_anet.acm"
"msacm.trspch"="tssoft32.acm"
"MSVideo8"="VfWWDM32.dll"
"vidc.cvid"="iccvid.dll"
"vidc.DIVX"="DivX.dll"
"VIDC.I420"="msh263.drv"
"vidc.iv31"="ir32_32.dll"
"vidc.iv32"="ir32_32.dll"
"vidc.iv41"="ir41_32.ax"
"vidc.iv50"="ir50_32.dll"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.M261"="msh261.drv"
"vidc.M263"="msh263.drv"
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"vidc.yv12"="DivX.dll"
"VIDC.YVU9"="tsbyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"wave"="wdmaud.drv"
"wavemapper"="msacm32.drv"
-=Daonol Files=-
(none found)
-=End Of File=- -
ComboFix 10-01-16.04 - JEREMY 18/01/2010 10:49:25.2.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.383.231 [GMT 1:00]
Lancé depuis: c:\documents and settings\JEREMY\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\JEREMY\Bureau\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\windows\system32\perfc00C.dat"
"c:\windows\system32\perfh00C.dat"
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\perfc00C.dat
c:\windows\system32\perfh00C.dat
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-18 au 2010-01-18 ))))))))))))))))))))))))))))))))))))
.
2010-01-18 09:25 . 2010-01-18 09:25 -------- d-----w- c:\windows\system32\fr-fr
2010-01-18 09:25 . 2010-01-18 09:25 -------- d-----w- c:\windows\l2schemas
2010-01-18 09:24 . 2010-01-18 09:24 -------- d-----w- c:\windows\system32\fr
2010-01-18 09:24 . 2010-01-18 09:24 -------- d-----w- c:\windows\system32\bits
2010-01-18 09:14 . 2010-01-18 09:14 -------- d-----w- c:\windows\EHome
2010-01-18 00:29 . 2008-04-13 18:36 44672 ------w- c:\windows\system32\drivers\uagp35.sys
2010-01-18 00:28 . 2008-04-14 02:33 4274816 ------w- c:\windows\system32\nv4_disp.dll
2010-01-18 00:27 . 2008-04-14 02:33 37376 ------w- c:\windows\system32\l2gpstore.dll
2010-01-18 00:26 . 2008-04-14 02:33 9216 ------w- c:\windows\system32\dot3dlg.dll
2010-01-18 00:21 . 2010-01-18 09:21 -------- d-----w- c:\windows\ServicePackFiles
2010-01-17 23:35 . 2008-06-14 17:33 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-01-17 23:35 . 2008-06-14 17:33 272768 ------w- c:\windows\system32\drivers\bthport.sys
2010-01-17 23:34 . 2009-11-21 15:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-17 23:27 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-01-17 23:27 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-01-17 23:27 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2010-01-17 23:10 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-01-17 23:09 . 2008-04-11 19:05 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-01-17 23:07 . 2008-12-16 12:31 354304 -c----w- c:\windows\system32\dllcache\winhttp.dll
2010-01-17 23:07 . 2008-10-15 16:35 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-01-17 23:06 . 2008-04-21 21:15 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-01-17 21:55 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-01-17 21:55 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-01-17 18:31 . 2010-01-17 18:31 -------- d-----w- c:\windows\ERUNT
2010-01-17 18:26 . 2010-01-17 19:38 -------- d-----w- C:\SDFix
2010-01-17 15:22 . 2010-01-17 15:22 -------- d-----w- C:\_OTM
2010-01-17 14:34 . 2010-01-17 14:35 -------- d-----w- C:\rsit
2010-01-17 13:16 . 2010-01-17 13:16 -------- d-----w- c:\program files\Trend Micro
2010-01-17 11:46 . 2009-12-17 20:03 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-01-17 11:46 . 2009-12-17 19:56 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-01-17 11:46 . 2010-01-17 11:46 -------- d-----w- c:\documents and settings\JEREMY\Application Data\TuneUp Software
2010-01-17 11:46 . 2010-01-17 11:46 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-01-17 11:45 . 2010-01-17 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-17 11:45 . 2010-01-17 11:45 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-01-17 01:46 . 2010-01-17 01:46 -------- d-----w- c:\documents and settings\JEREMY\Application Data\Malwarebytes
2010-01-17 01:46 . 2010-01-17 01:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-17 01:46 . 2010-01-17 18:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-03 23:28 . 2010-01-03 23:28 -------- d-----w- c:\documents and settings\JEREMY\Application Data\Mozilla-Cache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-18 09:58 . 2010-01-18 09:58 356120 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2010-01-18 09:26 . 2006-11-22 09:22 76507 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-18 08:54 . 2009-09-16 07:37 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-18 00:12 . 2007-09-23 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition Classic
2010-01-17 23:32 . 2006-11-28 01:44 -------- d-----w- c:\program files\InstantTouch
2010-01-03 23:28 . 2006-12-20 21:37 -------- d-----w- c:\program files\PartyGaming.Net
2009-11-21 15:58 . 2004-08-05 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-10-29 05:25 . 2004-08-05 12:00 671232 ----a-w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\JEREMY\Menu D‚marrer\Programmes\D‚marrage\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-3-6 36864]
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2006-11-30 51360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-30 108544]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVG Anti-Spyware Guard"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\PeerTV\\PeerCast.exe"=
"c:\\UT2004\\System\\UT2004.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:eMule TCP
"4672:UDP"= 4672:UDP:eMule UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [17/03/2009 11:40 266240]
R2 ScFBPNT;CanoScan FBP Port Driver;c:\windows\system32\drivers\SCFBPNT.SYS [30/11/2006 16:31 16288]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [17/12/2009 21:00 1044808]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14/10/2009 07:24 10064]
S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
S3 ADM8511;Convertisseur USB vers Fast Ethernet ADMtek ADM8511/AN986;c:\windows\system32\drivers\ADM8511.SYS [22/11/2006 12:32 20160]
S3 DCamUSBDigitalCamera;Digital Camera;c:\windows\system32\drivers\MPIXVID.SYS [23/12/2006 04:47 104593]
S3 v800bus;Sony Ericsson V800-Vodafone 802SE driver (WDM);c:\windows\system32\drivers\v800bus.sys [04/09/2007 14:41 52416]
S3 v800mdfl;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Filter;c:\windows\system32\drivers\v800mdfl.sys [04/09/2007 14:41 6160]
S3 v800mdm;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Driver;c:\windows\system32\drivers\v800mdm.sys [04/09/2007 14:41 84544]
S3 v800mgmt;Sony Ericsson V800-Vodafone 802SE USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\v800mgmt.sys [04/09/2007 14:48 77760]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2010-01-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 13:21]
2010-01-18 c:\windows\Tasks\Recherche de problèmes automatique.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-17 20:07]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.noos.fr/abonnes.php
uInternet Connection Wizard,ShellNext = iexplore
IE: Barre RoboForm - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Enregistrer le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Personnaliser le menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Remplir le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} - hxxp://data.jeuxclassiques.com/npwwg.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-18 10:56
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\windows\system32\PerfStringBackup.TMP 356120 bytes
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Swearware\backup\winsock2]
@DACL=(02 0000)
@SACL=
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(3612)
c:\oplimit\oahook32.dll
c:\windows\system32\eappprxy.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\AntiVir PersonalEdition Classic\sched.exe
c:\windows\system32\wdfmgr.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\oplimit\ocrawr32.exe
.
**************************************************************************
.
Heure de fin: 2010-01-18 11:01:45 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-01-18 10:01
ComboFix2.txt 2010-01-18 00:09
Avant-CF: 32 529 289 216 octets libres
Après-CF: 32 510 435 328 octets libres
- - End Of File - - AA9FBE6B5D736A7100EFB420322ADCD5 -
Contributeur sécuritéSalut kearny
- Clique sur le menu démarrer/Exécuter, tape notepad à l’invite de commande et OK.
- Copie/colle ce qui est en gras ci-dessous dans le Bloc-Notes :
KillAll::
File::
c:\windows\system32\perfc00C.dat
c:\windows\system32\perfh00C.dat
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi9"=-
- Enregistre ce fichier sur le bureau (Impératif)
-Nom du fichier : CFScript.txt
-Type du fichier : tous les fichiers
- Clique sur Enregistrer et quitte le Bloc Notes
Important Désactive ton Antivirus et antispyware avant de faire le glisser/déposer
- Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe sur le bureau, comme sur cette capture (l’icône est un lion) :
http://free0.hiboox.com/images/2409/9126d3b136f7db9ab6242ad715b44296.gif
* Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
* Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
* Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
-----
Télécharge DaonolFix sur le bureau ici :
http://jpshortstuff.247fixes.com/beta/DaonolFix.exe
Double clique sur DaonolFix.exe qui est sur le bureau pour l'exécuter
Choisir l'option 1. Find Daonol
Laisse le scan se dérouler et poste le contenu du rapport qui est sur le bureau DaonolFix.txt
@++ :) -
Cette dernière intervention me semble pas mal.
Voila le rapport de l'opération :
ComboFix 10-01-16.04 - JEREMY 18/01/2010 0:56.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.383.152 [GMT 1:00]
Lancé depuis: c:\documents and settings\JEREMY\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2397974594-337539203-1138793434-1001
C:\bold.log
c:\docume~1\JEREMY\LOCALS~1\irdimar.bak
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-18 au 2010-01-18 ))))))))))))))))))))))))))))))))))))
.
2010-01-17 21:55 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-01-17 21:55 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-01-17 18:31 . 2010-01-17 18:31 -------- d-----w- c:\windows\ERUNT
2010-01-17 18:26 . 2010-01-17 19:38 -------- d-----w- C:\SDFix
2010-01-17 15:22 . 2010-01-17 15:22 -------- d-----w- C:\_OTM
2010-01-17 14:34 . 2010-01-17 14:35 -------- d-----w- C:\rsit
2010-01-17 13:16 . 2010-01-17 13:16 -------- d-----w- c:\program files\Trend Micro
2010-01-17 11:46 . 2009-12-17 20:03 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-01-17 11:46 . 2009-12-17 19:56 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-01-17 11:46 . 2010-01-17 11:46 -------- d-----w- c:\documents and settings\JEREMY\Application Data\TuneUp Software
2010-01-17 11:46 . 2010-01-17 11:46 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-01-17 11:45 . 2010-01-17 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-17 11:45 . 2010-01-17 11:45 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-01-17 01:46 . 2010-01-17 01:46 -------- d-----w- c:\documents and settings\JEREMY\Application Data\Malwarebytes
2010-01-17 01:46 . 2010-01-17 01:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-17 01:46 . 2010-01-17 18:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-03 23:28 . 2010-01-03 23:28 -------- d-----w- c:\documents and settings\JEREMY\Application Data\Mozilla-Cache
1601-01-01 00:00 . 1601-01-01 00:00 -------- d-----w- c:\windows\LastGood.Tmp
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-17 23:43 . 2007-09-23 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition Classic
2010-01-17 23:32 . 2006-11-28 01:44 -------- d-----w- c:\program files\InstantTouch
2010-01-03 23:28 . 2006-12-20 21:37 -------- d-----w- c:\program files\PartyGaming.Net
2009-10-25 04:53 . 2004-08-05 12:00 48856 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-25 04:53 . 2004-08-05 12:00 368076 ----a-w- c:\windows\system32\perfh00C.dat
.
------- Sigcheck -------
[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp3qfe\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp3gdr\tcpip.sys
[-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp2gdr\tcpip.sys
[-] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp2qfe\tcpip.sys
[-] 2006-11-30 . 6A603809F598332DBEDD535BDBCE313E . 359040 . . [5.1.2600.2180] . . c:\windows\system32\drivers\TCPIP.SYS
[-] 2006-11-30 . 6A603809F598332DBEDD535BDBCE313E . 359040 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\TCPIP.SYS
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
c:\documents and settings\JEREMY\Menu D‚marrer\Programmes\D‚marrage\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-3-6 36864]
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2006-11-30 51360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-30 108544]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi9"=c:\docume~1\JEREMY\LOCALS~1\irdimar.bak 2yKAHJNFFL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVG Anti-Spyware Guard"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\PeerTV\\PeerCast.exe"=
"c:\\UT2004\\System\\UT2004.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:eMule TCP
"4672:UDP"= 4672:UDP:eMule UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [17/03/2009 11:40 266240]
R2 ScFBPNT;CanoScan FBP Port Driver;c:\windows\system32\drivers\SCFBPNT.SYS [30/11/2006 16:31 16288]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [17/12/2009 21:00 1044808]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14/10/2009 07:24 10064]
S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
S3 ADM8511;Convertisseur USB vers Fast Ethernet ADMtek ADM8511/AN986;c:\windows\system32\drivers\ADM8511.SYS [22/11/2006 12:32 20160]
S3 DCamUSBDigitalCamera;Digital Camera;c:\windows\system32\drivers\MPIXVID.SYS [23/12/2006 04:47 104593]
S3 v800bus;Sony Ericsson V800-Vodafone 802SE driver (WDM);c:\windows\system32\drivers\v800bus.sys [04/09/2007 14:41 52416]
S3 v800mdfl;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Filter;c:\windows\system32\drivers\v800mdfl.sys [04/09/2007 14:41 6160]
S3 v800mdm;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Driver;c:\windows\system32\drivers\v800mdm.sys [04/09/2007 14:41 84544]
S3 v800mgmt;Sony Ericsson V800-Vodafone 802SE USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\v800mgmt.sys [04/09/2007 14:48 77760]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2010-01-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 13:21]
2010-01-18 c:\windows\Tasks\Recherche de problèmes automatique.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-17 20:07]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.noos.fr/abonnes.php
uInternet Connection Wizard,ShellNext = iexplore
IE: Barre RoboForm - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Enregistrer le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Personnaliser le menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Remplir le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} - hxxp://data.jeuxclassiques.com/npwwg.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
SafeBoot-AVG Anti-Spyware Driver
AddRemove-HijackThis - c:\docume~1\JEREMY\LOCALS~1\Temp\Rar$EX01.324\HijackThis.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-18 01:04
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Swearware\backup\winsock2]
@DACL=(02 0000)
@SACL=
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2616)
c:\oplimit\oahook32.dll
c:\windows\system32\msi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\AntiVir PersonalEdition Classic\sched.exe
c:\windows\system32\wdfmgr.exe
c:\oplimit\ocrawr32.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2010-01-18 01:09:22 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-01-18 00:09
Avant-CF: 34 511 286 272 octets libres
Après-CF: 34 620 452 864 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
- - End Of File - - 1BD03498FEA729D2CD0312ED1EE699D1 -
Contributeur sécuritéSalut kearny
Télécharge combofix.exe (de sUBs) sur le bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/
Important Désactive ton Antivirus, antispyware et Pare feu avant le scan avec Combofix :
https://forum.pcastuces.com/default.asp
https://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/
==> Sauvegarde ton travail et ferme toutes les fenêtres actives, il peut y avoir un redémarrage du PC. Ne lance aucun programme tant que Combofix n’est pas fini. <==
Double clique sur combofix.exe, clique sur OUI et valide par Entrée
Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure
@++ :) -
ah oui ! pas bête :)
le rapport :
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-17 23:48:02
Windows 5.1.2600 Service Pack 2
Running: 2cb649ee.exe; Driver: C:\DOCUME~1\JEREMY\LOCALS~1\Temp\awtdypow.sys
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\winlogon.exe[208] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
.text C:\WINDOWS\system32\winlogon.exe[208] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
.text C:\WINDOWS\system32\winlogon.exe[208] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
.text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
.text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!send 719F428A 5 Bytes JMP 10003260
.text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
.text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!recv 719F615A 5 Bytes JMP 10002788
.text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
.text C:\WINDOWS\system32\services.exe[256] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
.text C:\WINDOWS\system32\services.exe[256] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
.text C:\WINDOWS\system32\services.exe[256] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
.text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
.text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
.text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
.text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
.text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
.text C:\WINDOWS\system32\lsass.exe[268] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
.text C:\WINDOWS\system32\lsass.exe[268] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
.text C:\WINDOWS\system32\lsass.exe[268] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
.text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
.text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!send 719F428A 5 Bytes JMP 10003260
.text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
.text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!recv 719F615A 5 Bytes JMP 10002788
.text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
.text C:\WINDOWS\system32\svchost.exe[428] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
.text C:\WINDOWS\system32\svchost.exe[428] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
.text C:\WINDOWS\system32\svchost.exe[428] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
.text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
.text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
.text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
.text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
.text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
.text C:\WINDOWS\system32\svchost.exe[496] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
.text C:\WINDOWS\system32\svchost.exe[496] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
.text C:\WINDOWS\system32\svchost.exe[496] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
.text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
.text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
.text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
.text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
.text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
.text C:\WINDOWS\system32\svchost.exe[556] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
.text C:\WINDOWS\system32\svchost.exe[556] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
.text C:\WINDOWS\system32\svchost.exe[556] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
.text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
.text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
.text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
.text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
.text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
.text C:\WINDOWS\Explorer.EXE[780] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
.text C:\WINDOWS\Explorer.EXE[780] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
.text C:\WINDOWS\Explorer.EXE[780] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
.text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
.text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
.text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
.text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
.text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
---- EOF - GMER 1.0.15 ---- -
Contributeur sécuritéSalut kearny
Voir en mode sans échec :
Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur
@++ :) -
Le scan commence, mais à la moitié du scan, l'application se ferme.
J'ai essayé toutes les situations, avec ou sans internet, avec ou sans antivirus, à chaque fois, l'application se ferme sans avertissement. -
Contributeur sécuritéSalut kearny
Télécharge Gmer et enregistre-le sur ton bureau.
http://www2.gmer.net/download.php
Note : l'application portera un nom aléatoire. Indique-le moi dans ton prochain message.
- Déconnecte toi d'internet si possible et ferme tous les programmes, puis lance l'outil.
- Clique sur le bouton "Scan" sur la droite.
- Lorsque le scan est terminé, clic sur "Copy".
- Ouvre le bloc-note et clic sur le Menu Edition / Coller
- Le rapport doit alors apparaître.
- Enregistre le fichier sur ton bureau et copie/colle le contenu ici.
@++ :) -
J'ai lancé runthis en mode sans échec, je l'ai laissé faire jusqu'au redémarrage automatique.
A partir de là, sur le mode normal, il a bloqué pdt 1h (j'avais replacé antivir - alors je l'ai désactivé à nouveau)
et ca s'est débloqué et le report est le suivant :
[b]SDFix: Version 1.240 [/b]
Run by JEREMY on 17/01/2010 at 19:34
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
No Trojan Files Found
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-17 20:37:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe"="C:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe:*:Enabled:CmCenter Module"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\PeerTV\\PeerCast.exe"="C:\\Program Files\\PeerTV\\PeerCast.exe:*:Enabled:PeerCast"
"C:\\Program Files\\PeerCast\\PeerCast.exe"="C:\\Program Files\\PeerCast\\PeerCast.exe:*:Enabled:PeerCast"
"C:\\UT2004\\System\\UT2004.exe"="C:\\UT2004\\System\\UT2004.exe:*:Enabled:UT2004"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[b]Remaining Files [/b]:
[b]Files with Hidden Attributes [/b]:
Thu 7 Dec 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 7 Dec 2006 4,348 A..H. --- "C:\Documents and Settings\JEREMY\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Wed 4 Apr 2007 20 A..H. --- "C:\Documents and Settings\JEREMY\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Thu 7 Dec 2006 9,655 A.SH. --- "C:\Documents and Settings\JEREMY\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Sat 28 Mar 2009 112,703,975 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c7335f2b91892ece82339556ae30331d\download\BIT35.tmp"
[b]Finished![/b]
Tu y vois un peu plus clair ? :) -
Contributeur sécuritéSalut kearny
Télécharge SDFix par AndyManchesta sur le Bureau :
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clic sur sdfix.exe sur le bureau et clic sur Install , un dossier sera créer a la racine du disque C:\SDFix
Redémarre ton PC en mode sans échec :
Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur.
Ouvre le dossier SDFix et double clique sur RunThis.bat, appuie sur Y pour lancer le nettoyage.
Il y aura redémarrage, quand Finished s’affichera appuie sur un touche pour terminer.
Poste le rapport qui se trouve dans le dossier SDFix sous le nom de Report.txt dans ta prochaine réponse.
@++ :)
- 1
- 2