Infection suite moe, régis...

re ! alors j'ai pu tout virer (dans ce que tu m'as marqué sur le post) mais il y en a deux pour lesquels il m'a dit que c'était des fichiers systeme ?!! est-ce dangereux ? j'ai silent runners mais impossible de le trouver il se cache dans l'ordi et le lien que tu m'as passé ne marche pas...
merci moe

26 réponses

Résumé de la discussion

Plusieurs échanges traitent de la détection et de la suppression de programmes de démarrage malveillants, notamment l’outil Silent Runners et des fichiers jugés système par les utilisateurs. Les contributeurs proposent des méthodes pour repérer les entrées de démarrage dans le registre et identifier les composants associés, précisant que certains éléments indésirables peuvent être légitimes selon le contexte. Des liens de téléchargement et des versions de Silent Runners sont évoqués, certains problèmes liés à des liens obsolètes ou à des difficultés de localisation rendant l’analyse et l’application plus complexes. La discussion montre une démarche étape par étape pour vérifier les clés Run et les chemins système, tout en recommandant des sources fiables et une assistance technique lorsque des doutes persistent.

Bobot (l’IA à votre service)
  1. ok;
    de rien

    Bon we; merci a moe ;-)
    0
    1. re
      oui ils sont supp et je dois plus avoir de soucis maintenant, voila merci encore !
      0
      1. Re,

        ceci haha.exe et msnsrv.exe, ils sont supprimés?

        Refais un scan chez kaspersky et dis nous ou en sont tes soucis

        a+
        0
        1. re
          je n'ai pas de spyware si c'est de ça dont tu parles j'ai supp les clés j'ai mis un silent car moe me l'a demandé , si j'ai rien tant mieux
          0
          1. Re,

            Je n ai rien vu....

            Tu as essayer de les supprimer en sans echec?

            a+
            0
            1. re !!! j'ai pu réussir a avoir cela

              "Silent Runners.vbs", revision 39, http://www.silentrunners.org/
              Operating System: Windows XP
              Output limited to non-default values, except where indicated by "{++}"

              Startup items buried in registry:
              ---------------------------------

              HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
              "msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS]

              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
              "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]
              "Openwares LiveUpdate" = "C:\Program Files\LiveUpdate\LiveUpdate.exe" ["Openwares"]
              "Zone Labs Client" = "C:\karim\ZoneAlarm\ZoneAlarm\zlclient.exe" ["Zone Labs, LLC"]

              HKLM\Software\Microsoft\Active Setup\Installed Components\
              {5945c046-1e7d-11d1-bc44-00c04fd912be}\(Default) = "Windows Messenger 4.7"
              \StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Remove.PerUser" [MS]

              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
              {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
              -> {CLSID}\InProcServer32\(Default) = "C:\DOCUME~1\sabrina\Bureau\NOUVEA~2\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
              {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = "SSVHelper Class" [from CLSID]
              -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]

              HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
              "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
              -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
              "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
              -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
              "{5b4dae26-b807-11d0-9815-00c04fd91972}" = "Bande de menus"
              -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
              "{8278F931-2A3E-11d2-838F-00C04FD918D0}" = "Suivi du menu Shell"
              -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
              "{E13EF4E4-D2F2-11d0-9816-00C04FD91972}" = "Menu Site"
              -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
              "{ECD4FC4F-521C-11D0-B792-00A0C90312E1}" = "Menu Barre du Bureau"
              -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
              "{D82BE2B0-5764-11D0-A96E-00C04FD705A2}" = "IShellFolderBand"
              -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
              "{0E5CBF21-D15F-11d0-8301-00AA005B4383}" = "&Liens"
              -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
              "{7487cd30-f71a-11d0-9ea7-00805f714772}" = "Image miniature"
              -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
              "{3779D068-8AA6-11d2-B8FF-0080C84D9C69}" = "WinFast Information Property Sheet 2000"
              -> {CLSID}\InProcServer32\(Default) = "WF2KCPL.DLL" ["Leadtek Research Inc."]
              "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
              -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
              "{AB77609F-2178-4E6F-9C4B-44AC179D937A}" = "a² Context Menu Shell Extension"
              -> {CLSID}\InProcServer32\(Default) = "C:\karim\a-squared\a2contmenu.dll" [null data]
              "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
              -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
              INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
              -> {CLSID}\InProcServer32\(Default) = "C:\Documents and Settings\sabrina\Bureau\Nouveau dossier (2)\ewido anti-malware\shellhook.dll" ["TODO: <Firmenname>"]

              HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
              avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
              -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
              ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
              -> {CLSID}\InProcServer32\(Default) = "C:\Documents and Settings\sabrina\Bureau\Nouveau dossier (2)\ewido anti-malware\context.dll" ["ewido networks"]
              WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
              -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

              HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
              ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
              -> {CLSID}\InProcServer32\(Default) = "C:\Documents and Settings\sabrina\Bureau\Nouveau dossier (2)\ewido anti-malware\context.dll" ["ewido networks"]
              WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
              -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

              HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
              a2ContMenu\(Default) = "{AB77609F-2178-4E6F-9C4B-44AC179D937A}"
              -> {CLSID}\InProcServer32\(Default) = "C:\karim\a-squared\a2contmenu.dll" [null data]
              avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
              -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
              WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
              -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

              Default executables:
              --------------------

              .HTA: HKLM\SOFTWARE\Classes\htafile\shell\open\command\
              INFECTION WARNING! "Default" = "NOTEPAD.EXE %1" [MS]

              Active Desktop and Wallpaper:
              -----------------------------

              Active Desktop is disabled at this entry:
              HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

              HKCU\Control Panel\Desktop\
              "Wallpaper" = "C:\Documents and Settings\sabrina\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

              Enabled Screen Saver:
              ---------------------

              HKCU\Control Panel\Desktop\
              "SCRNSAVE.EXE" = "C:\WINDOWS\SYSTEM32\logon.scr" [MS]

              Startup items in "sabrina" & "All Users" startup folders:
              ---------------------------------------------------------

              C:\Documents and Settings\sabrina\Menu Démarrer\Programmes\Démarrage
              "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\Osa9.exe -b -l" [MS]

              Enabled Scheduled Tasks:
              ------------------------

              "Démarrage du programme de réglages" -> launches: "walign" [file not found]
              "Maintenance en 1 clic" -> launches: "C:\karim\SystemOptimizer.exe /schedulestart" [file not found]

              Winsock2 Service Provider DLLs:
              -------------------------------

              Namespace Service Providers

              HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
              000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
              000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
              000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

              Transport Service Providers

              HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
              0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
              %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
              %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

              Toolbars, Explorer Bars, Extensions:
              ------------------------------------

              Extensions (Tools menu items, main toolbar menu buttons)

              HKCU\Software\Microsoft\Internet Explorer\Extensions\
              {1462651F-F4BA-4C76-A001-C4284D0FE16E}\
              "ButtonText" = "Wanadoo"
              "Exec" = "www.wanadoo.fr" [file not found]

              HKLM\Software\Microsoft\Internet Explorer\Extensions\
              {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
              "MenuText" = "Console Java (Sun)"
              "CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}"
              -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."]

              {85D1F590-48F4-11D9-9669-0800200C9A66}\
              "MenuText" = "Uninstall BitDefender Online Scanner v8"
              "Exec" = "%windir%\bdoscandel.exe" [null data]

              {CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\

              Miscellaneous IE Hijack Points
              ------------------------------

              C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

              Added lines (compared with English-language version):
              [Strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/"

              Missing lines (compared with English-language version):
              [Strings]: 1 line

              HKLM\Software\Microsoft\Internet Explorer\AboutURLs\
              HIJACK WARNING! "TuneUp" = "file://C|/Documents and Settings/All Users/Application Data/TuneUp Software/Common/base.css" [file not found]

              HOSTS file
              ----------

              HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\
              HIJACK WARNING! "DataBasePath" = "C:\WINDOWS\help"

              Running Services (Display Name, Service Name, Path {Service DLL}):
              ------------------------------------------------------------------

              avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data]
              avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data]
              avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
              avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
              Creative Service for CDROM Access, Creative Service for CDROM Access, "C:\WINDOWS\System32\CTsvcCDA.exe" ["Creative Technology Ltd"]
              Diskeeper, Diskeeper, "C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe" ["Executive Software International, Inc."]
              ewido security suite control, ewido security suite control, "C:\Documents and Settings\sabrina\Bureau\Nouveau dossier (2)\ewido anti-malware\ewidoctrl.exe" ["ewido networks"]
              ewido security suite guard, ewido security suite guard, "C:\Documents and Settings\sabrina\Bureau\Nouveau dossier (2)\ewido anti-malware\ewidoguard.exe" ["ewido networks"]
              TrueVector Internet Monitor, vsmon, "C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe -service" ["Zone Labs, LLC"]
              WMDM PMSP Service, WMDM PMSP Service, "C:\WINDOWS\System32\MsPMSPSv.exe" [MS]

              ----------
              + This report excludes default entries except where indicated.
              + To see *everywhere* the script checks and *everything* it finds,
              launch it from a command prompt or a shortcut with the -all parameter.
              + To search all directories of local fixed drives for DESKTOP.INI
              DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
              use the -supp parameter or answer "Yes" at the first message box.
              ---------- (total run time: 120 seconds, including 0 second for message boxes)
              0
              1. re
                non pareil qu'au message 4...
                0
                1. re,
                  je l'ai téléchargé au moins 10 fois mais a chaque fois il y a un bloc note qui s'ouvre avec écrit des choses dedans (voir message 4)
                  0
                  1. Re,

                    Rétélécharges le..

                    Que se passe t il, explique nous.?

                    a+
                    0
                    1. Silent runner ca marche plus?
                      0
                      1. re moe,

                        toujours rien, avec le meme bloc note...
                        0
                        1. re moe,
                          ok j'ai supp le fichier
                          quant aux deux autres ils se sont volatilisés lorsque j'ai mis réorganisation automatique du bureau ?!! lol !
                          et pour silent runners ? je vais essayer une derniere fois
                          a toute
                          0
                          1. re moe,

                            ***j'ai supp C:\WINDOWS\backup\T\51107000.DAT
                            ***C:\update227.exe n'est plus la
                            ***par contre il y a ce fichier C:\WINDOWS\backup\T\51015000.DAT que dois-je en faire ?
                            *** il y a deux fichiers qui sont apparus sur mon bureau ~WRL0220 et ~WRL3568 c'est quoi ? dois-je les supprimer ?
                            merci beaucoup
                            0
                            1. Apparement bitdefender les a supprimés, vérifie quand même on sait jamais:

                              C:\update227.exe
                              C:\WINDOWS\backup\T\51107000.DAT
                              0
                              1. re,

                                oui pareil... j'ai un rapport bitdefender tu peux y jeter un coup d'oeil merci !!

                                BitDefender Online Scanner

                                Scan report generated at: Sat, Jan 21, 2006 - 18:39:19

                                Scan path: A:\;C:\;D:\;

                                Statistics

                                Time

                                01:11:01

                                Files

                                236147

                                Folders

                                3330

                                Boot Sectors

                                2

                                Archives

                                1766

                                Packed Files

                                28438

                                Results

                                Identified Viruses

                                3

                                Infected Files

                                4

                                Suspect Files

                                0

                                Warnings

                                0

                                Disinfected

                                0

                                Deleted Files

                                4

                                Engines Info

                                Virus Definitions

                                252357

                                Engine build

                                AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)

                                Scan plugins

                                13

                                Archive plugins

                                39

                                Unpack plugins

                                4

                                E-mail plugins

                                6

                                System plugins

                                1

                                Scan Settings

                                First Action

                                Disinfect

                                Second Action

                                Delete

                                Heuristics

                                Yes

                                Enable Warnings

                                Yes

                                Scanned Extensions

                                *;

                                Exclude Extensions

                                Scan Emails

                                Yes

                                Scan Archives

                                Yes

                                Scan Packed

                                Yes

                                Scan Files

                                Yes

                                Scan Boot

                                Yes

                                Scanned File

                                Status

                                C:\WINDOWS\backup\T\51015000.DAT=>(Embedded EXE g)

                                Infected with: Trojan.Rootkit.L

                                C:\WINDOWS\backup\T\51015000.DAT=>(Embedded EXE g)

                                Disinfection failed

                                C:\WINDOWS\backup\T\51015000.DAT=>(Embedded EXE g)

                                Deleted

                                C:\WINDOWS\backup\T\51015000.DAT

                                Update failed

                                C:\WINDOWS\backup\T\51015000.DAT=>(Embedded EXE g)

                                Infected with: Backdoor.SDBot.0C159D81

                                C:\WINDOWS\backup\T\51015000.DAT=>(Embedded EXE g)

                                Deleted

                                C:\WINDOWS\backup\T\51015000.DAT

                                Update failed

                                C:\WINDOWS\backup\T\51107000.DAT=>(Embedded EXE g)

                                Infected with: Trojan.Rootkit.L

                                C:\WINDOWS\backup\T\51107000.DAT=>(Embedded EXE g)

                                Disinfection failed

                                C:\WINDOWS\backup\T\51107000.DAT=>(Embedded EXE g)

                                Deleted

                                C:\WINDOWS\backup\T\51107000.DAT

                                Update failed

                                C:\update227.exe

                                Infected with: BehavesLike:Trojan.FirewallBypass

                                C:\update227.exe

                                Disinfection failed

                                C:\update227.exe

                                Deleted
                                0
                                1. et si tu fais un clic droit dessus>ouvrir
                                  c'est pareil ?
                                  0
                                  • 1
                                  • 2