Bonjour,
J'ai pratiquement tout essayé pour enlever un virus gênant qui me fait des redirections de liens Google et plein de trucs du genre. J'ai essayé des dizaines d'anti-spywares / anti-malwares et autres, mais rien n'y fait. Le virus semble se réinstaller tout seul sans cesse et m'empêche de faire fonctionner certains utilitaires qui pourraient l'éliminer.
Après avoir lu plusieurs forums, j'ai utilisé ComboFix... Voici le rapport. Vous seriez très aimables si vous pouviez m'aider.
ComboFix 11-01-22.03 - Pierre-Luc 2011-01-23 16:09:49.1.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1012.531 [GMT -5:00]
Lancé depuis: c:\documents and settings\Pierre-Luc\Mes documents\Downloads\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Pierre-Luc\System
c:\documents and settings\Pierre-Luc\System\win_qs8.jqx
c:\program files\RegGenie
c:\program files\RegGenie\Backups\40566,6179043634
c:\program files\RegGenie\RegGenie.ini
c:\windows\RegGenieOnUninstall.exe
c:\windows\system32\drivers\ntfs.sys . . . est infecté!!
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-12-23 au 2011-01-23 ))))))))))))))))))))))))))))))))))))
.
2011-01-23 20:37 . 2011-01-23 20:37 -------- d-----w- c:\documents and settings\PL Powers
2011-01-23 19:51 . 2011-01-23 19:51 -------- d-----w- c:\documents and settings\Pierre-Luc\Application Data\RegGenie
2011-01-22 23:01 . 2011-01-22 23:01 -------- d-----w- c:\documents and settings\Pierre-Luc\Application Data\Malwarebytes
2011-01-22 23:00 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-22 23:00 . 2011-01-22 23:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-01-22 23:00 . 2010-12-20 23:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-22 23:00 . 2011-01-22 23:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-22 21:00 . 2010-11-06 00:28 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-01-22 21:00 . 2010-11-06 00:28 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2011-01-22 20:46 . 2011-01-22 20:46 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-01-22 20:45 . 2011-01-22 20:45 -------- d-sh--w- c:\documents and settings\Pierre-Luc\IETldCache
2011-01-22 20:40 . 2011-01-23 19:07 -------- d-----w- c:\windows\ie8updates
2011-01-22 20:34 . 2011-01-22 21:06 -------- d--h--w- c:\windows\msdownld.tmp
2011-01-22 20:34 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-01-22 20:33 . 2010-11-06 00:21 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-01-22 20:33 . 2010-11-06 00:21 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-01-22 20:33 . 2010-11-06 00:21 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-01-22 19:17 . 2011-01-23 15:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2011-01-22 19:17 . 2011-01-22 19:17 -------- d-----w- c:\program files\Alwil Software
2011-01-21 15:28 . 2011-01-21 15:28 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-01-21 15:26 . 2011-01-21 15:26 -------- d-----w- c:\documents and settings\Pierre-Luc\Local Settings\Application Data\Sunbelt Software
2011-01-21 15:22 . 2011-01-22 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-01-21 13:51 . 2011-01-23 17:53 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-21 13:51 . 2011-01-23 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-01-20 20:58 . 2011-01-20 20:58 142336 --sha-r- c:\windows\system32\vssadmina.dll
2011-01-20 20:58 . 2011-01-20 20:58 -------- d-----w- c:\program files\Common Files
2011-01-04 18:30 . 2011-01-04 18:30 -------- d-----w- c:\documents and settings\Pierre-Luc\Application Data\SmartDraw
2011-01-04 18:29 . 2011-01-18 18:40 -------- d-----w- c:\program files\SmartDraw 2010
2011-01-04 18:24 . 2011-01-04 18:24 -------- d-----w- c:\documents and settings\Pierre-Luc\Application Data\Python-Eggs
2011-01-04 18:24 . 2011-01-20 20:59 -------- d-----w- c:\documents and settings\Pierre-Luc\Application Data\BitLord
2011-01-04 18:23 . 2011-01-20 22:17 -------- d-----w- c:\program files\BitLord 1.2
2010-12-27 18:47 . 2010-12-27 18:47 -------- d-----w- c:\documents and settings\LocalService\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 18:12 . 2008-04-14 06:00 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2008-04-14 06:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:28 . 2008-04-14 06:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-11-03 12:25 . 2008-04-14 06:00 389120 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2008-04-14 06:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:14 . 2008-04-14 06:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 14:07 . 2008-04-14 06:00 1853440 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gestionnaire Antidote.exe"="c:\program files\Druide\Antidote\Gestionnaire Antidote.exe" [2007-04-16 534200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-30 18082304]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"jkss.exe"="c:\program files\Common Files\Microsoft Shared\Web Components\cffmon.exe" [2011-01-17 93400]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2010-7-8 113664]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 04:07 932288 ----a-r- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 09:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
2006-07-18 03:40 53248 ------w- c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
2008-05-22 20:30 425984 ----a-w- c:\acer\Empowering Technology\eRecovery\eRAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-02-16 00:24 133104 ----atw- c:\documents and settings\Pierre-Luc\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2004-09-13 19:49 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 06:00 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2008-05-14 03:14 821768 ----a-w- c:\progra~1\LAUNCH~1\QtZgAcer.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2008-04-14 06:00 59392 ----a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-06-10 13:45 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-07-09 19:39 570664 ----a-w- c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 06:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 06:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetL]
2007-07-05 17:35 94208 ----a-w- c:\windows\PLFSetL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-04-25 01:32 1044480 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\phpdev\\apache\\Apache.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1542:TCP"= 1542:TCP:Realtek WPS TCP Prot
"1542:UDP"= 1542:UDP:Realtek WPS UDP Prot
S2 gupdate;Service Google Update (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S3 Crtautckmwn;Crtautckmwn; [x]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-07-08 96856]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2009-07-21 18432]
S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2007-11-02 83496]
.
Contenu du dossier 'Tâches planifiées'
2010-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.bing.fr/
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Pierre-Luc\Application Data\Mozilla\Firefox\Profiles\2956tmig.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ilblogue.com
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-snp2uvc - c:\windows\vsnp2uvc.exe
MSConfigStartUp-MSC - c:\program files\Microsoft Security Client\msseces.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-RegGenie Scheduler - c:\program files\RegGenie\RegGenieScheduler.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-23 16:18
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(3376)
c:\windows\system32\eappprxy.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Heure de fin: 2011-01-23 16:24:47 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-01-23 21:24
Avant-CF: 117 520 175 104 octets libres
Après-CF: 118 021 062 656 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
- - End Of File - - 595D135A9E4226817456EA1E6D44B224
