Salut à tous,
Je viens de détecter Hiddenext/crypted et TR/Vundo.gen comme virus avec Antivir
J'ai lu pas mal de forum et pas mal de gens conseillaient de lancer ComboFix.
Il a donc procédé à la désinfection.... mais j'aimerai avoir votre avis.
Voici le rapport :
ComboFix 09-10-30.01 - Maître 31/10/2009 13:59.1.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1014.568 [GMT 1:00]
Lancé depuis: c:\documents and settings\Maître\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\a2g21.exe
C:\autorun.inf
c:\docume~1\MATRE~1\LOCALS~1\Temp\cvasds0.dll
c:\docume~1\MATRE~1\LOCALS~1\Temp\cvasds1.dll
c:\recycler\S-1-5-21-3375437352-3766727421-2216168879-1003
c:\windows\afevenupehukuh.dll
c:\windows\akikewejo.dll
c:\windows\amawohon.dll
c:\windows\apumezocijezoweq.dll
c:\windows\aqazewujon.dll
c:\windows\avazoqocefuw.dll
c:\windows\averayap.dll
c:\windows\axaceris.dll
c:\windows\axonupiy.dll
c:\windows\ayovamik.dll
c:\windows\ebeyevevamiw.dll
c:\windows\ehecejaq.dll
c:\windows\ekisihiki.dll
c:\windows\ekugavopiwam.dll
c:\windows\epifoxoqo.dll
c:\windows\eruqemaq.dll
c:\windows\evecexuc.dll
c:\windows\ifevenupeh.dll
c:\windows\imojokilomini.dll
c:\windows\iqocaben.dll
c:\windows\irogubelixibug.dll
c:\windows\ofowehapaximiba.dll
c:\windows\opijubijamehigat.dll
c:\windows\osutatux.dll
c:\windows\oyipoxaziguquxu.dll
c:\windows\oyupoqoxe.dll
c:\windows\system32\drivers\gasfkyudjelwxy.sys
c:\windows\system32\gasfkypmhsbpxy.dat
c:\windows\system32\gasfkyrubrrpqc.dll
c:\windows\system32\gasfkyxtlxfkdu.dll
c:\windows\system32\gasfkyxviupwkm.dll
c:\windows\system32\gasfkyyrrbwvim.dat
c:\windows\uhenihuqajacuqe.dll
c:\windows\ulohadaj.dll
c:\windows\upijacuqepi.dll
c:\windows\uyitided.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-28 au 2009-10-31 ))))))))))))))))))))))))))))))))))))
.
2009-10-31 11:40 . 2009-10-31 11:40 -------- d--h--w- c:\temp\dvmexp
2009-10-31 11:40 . 2009-10-31 11:40 -------- d-----w- C:\dvmexp
2009-10-31 11:16 . 2009-03-30 09:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-31 11:16 . 2009-03-24 15:07 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-31 11:16 . 2009-02-13 11:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-31 11:16 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-31 11:16 . 2009-10-31 11:16 -------- d-----w- c:\program files\Avira
2009-10-31 11:16 . 2009-10-31 11:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-10-17 21:15 . 2009-10-17 21:15 -------- d-----w- c:\windows\SQL9_KB970892_ENU
2009-10-15 14:59 . 2009-10-15 14:58 116414 --sh--r- C:\2sm66r.exe
2009-10-15 12:42 . 2009-10-15 12:42 0 ----a-w- c:\windows\nsreg.dat
2009-10-14 09:59 . 2009-10-15 07:55 115522 --sh--r- C:\s3ek.exe
2009-10-14 06:59 . 2009-10-14 06:59 8652 ----a-w- c:\windows\owanusij.dll
2009-10-13 07:10 . 2009-10-13 07:09 114400 --sh--r- C:\ycvvj.exe
2009-10-12 10:42 . 2009-10-12 10:42 114888 --sh--r- C:\mje12tni.exe
2009-10-09 15:06 . 2009-10-09 15:06 116526 --sh--r- C:\vlvtdflx.exe
2009-10-09 12:45 . 2009-10-09 12:45 117508 --sh--r- C:\1di1w.exe
2009-10-08 09:44 . 2009-10-08 09:44 117945 --sh--r- C:\r2g20.exe
2009-10-07 09:41 . 2009-10-07 09:41 117625 --sh--r- C:\f9o8o.exe
2009-10-06 11:22 . 2009-10-06 11:21 118651 --sh--r- C:\ctu8r.exe
2009-10-05 15:18 . 2009-10-05 15:18 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-10-05 08:29 . 2009-10-05 08:29 117453 --sh--r- C:\sp1jensi.exe
2009-10-05 08:28 . 2009-09-26 11:21 111956 --sh--r- C:\w9uxx92.exe
2009-10-05 07:52 . 2009-10-05 07:52 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-31 12:50 . 2008-07-18 13:36 568222 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-31 12:50 . 2008-07-18 13:36 108684 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-31 11:37 . 2009-02-28 23:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-10-23 09:39 . 2009-09-26 09:05 65024 ----a-w- c:\windows\system32\usbctl.exe
2009-10-17 21:15 . 2009-02-06 14:29 -------- d-----w- c:\program files\Microsoft SQL Server
2009-10-17 21:14 . 2009-02-06 14:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-05 15:17 . 2009-02-06 14:18 -------- d-----w- c:\program files\Windows Live
2009-09-26 19:03 . 2009-09-26 19:03 -------- d-----w- c:\program files\VideoLAN
2009-09-11 14:18 . 2008-07-18 13:36 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 08:25 . 2009-05-23 18:23 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-04 21:04 . 2008-07-18 13:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2008-07-18 13:36 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:01 . 2008-07-18 13:36 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-06 18:24 . 2008-07-18 03:47 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 18:24 . 2008-07-18 03:47 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 18:24 . 2009-02-06 14:18 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 18:24 . 2008-07-18 03:47 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 18:24 . 2008-07-18 03:47 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 18:24 . 2008-07-18 13:36 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 18:23 . 2008-07-18 03:47 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 18:23 . 2009-03-01 10:53 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 18:23 . 2008-10-16 13:07 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 18:23 . 2008-07-18 03:47 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:00 . 2008-07-18 13:36 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 17:27 . 2008-04-13 19:07 2147328 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:27 . 2008-04-13 19:07 2025984 ----a-w- c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-02-06 14:13 241752 ----a-w- c:\windows\system32\IcnOvrly.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-08 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-23 1146880]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2008-07-09 4456448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-08-28 1283984]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-17 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-02-06 323584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"TVT Scheduler Proxy"="c:\program files\Fichiers communs\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-16 148888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-09-24 16859648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2008-6-23 600680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PicNotify]
2009-02-06 14:13 1163264 ----a-w- c:\windows\system32\PicNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli dbgrvc.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [31/10/2009 12:16 108289]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\qstart.sys\config\DVMExportService.exe [20/11/2008 17:55 307200]
R2 usbctl;Microsoft USB Bus Controller;c:\windows\system32\usbctl.exe [26/09/2009 10:05 65024]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [06/02/2009 15:06 9472]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [06/02/2009 15:11 157696]
S2 gupdate1c9ffcedf936236;Service Google Update (gupdate1c9ffcedf936236);c:\program files\Google\Update\GoogleUpdate.exe [08/07/2009 14:20 133104]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
.
Contenu du dossier 'Tâches planifiées'
2009-09-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-10-31 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-08 13:19]
2009-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 13:20]
2009-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 13:20]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.agefi.fr/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MIF269~1\OFFICE11\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
IE: Envoyer à Bluetooth - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Maître\Application Data\Mozilla\Firefox\Profiles\acy0cwo5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.agefi.fr/
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-31 14:11
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys atapi.sys speg.sys hal.dll >>UNKNOWN [0x86F87938]<<
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 1 !
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
atapi.sys @ 0x0 0x0 bytes
\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF73D8B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF73D8B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF73D8B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF73D8B40 atapi.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF73D8B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF73D8B40 atapi.sys
\Driver\atapi IRP hooks detected !
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\PicNotify.dll
c:\windows\system32\FaceVerify.dll
c:\windows\system32\MainOp.dll
c:\windows\system32\VideoOp.dll
c:\windows\system32\Image.dll
c:\windows\system32\Momo.dll
c:\windows\system32\Apblend.dll
c:\windows\system32\SetDev.dll
c:\windows\system32\FunFrm.dll
c:\windows\system32\facev.dll
- - - - - - - > 'lsass.exe'(916)
c:\windows\dbgrvc.dll
.
Heure de fin: 2009-10-31 14:13
ComboFix-quarantined-files.txt 2009-10-31 13:13
Avant-CF: 134 382 309 376 octets libres
Après-CF: 137 670 721 536 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
- - End Of File - - 2A8F3E0EA0E08F0104220244D914360E