Infection par Trojan.Win32.BHO.abo

Fermé
omenone - 6 janv. 2008 à 16:13
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 - 7 févr. 2008 à 13:18
Bonjour à toutes et à tous,

Tout d'abord merci pour l'aide que vous apportez à nous les Nubies qui parcourons votre forum et qui glanons les bonnes informations que vous y laissez.
Comme beaucoup de personnes mon PC est actuellement infecté par le très coriace "Trojan.Win32.BHO.abo" ... Ni Avast, ni Spybot, ni AdAware ne l'ont vu, et Kaspersky ou AVG ne peuvent le supprimer : "les privilèges d'écritures manquent" (même en mode sans échec).
Apparement le trojan est situé ici : "C\Windows\system32\cryptu.dll//PE_Patch.UPX//UPX" suivant les indications de Kaspersky.
Je joins à ce message un log Hijackthis et un log Combofix.
J'espère avoir fait les choses de la bonne manière, je suis un novice.
Quelqu'un peut il m'aider s'il vous plaît ?

1 - Log Hijacthis :

Logfile of HijackThis v1.99.1
Scan saved at 15:09:44, on 06/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Documents and Settings\thomas\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C88D1F4-0561-407F-9C85-50CA02A4D620} - C:\WINDOWS\system32\cryptu.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\FICHIE~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by143fd.bay143.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: OvisLink Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Unknown owner - C:\Program Files\Fichiers communs\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

2 - Log Combofix :

ComboFix 08-01-04.1 - thomas 2008-01-06 15:32:04.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1578 [GMT 1:00]
Running from: C:\Documents and Settings\thomas\Bureau\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((( Fichiers créés 2007-12-06 to 2008-01-06 ))))))))))))))))))))))))))))))))))))
.

2008-01-06 15:30 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-15 00:39 . 2007-12-15 00:39 106 --a------ C:\index.ini
2007-12-15 00:31 . 2007-12-15 00:31 <REP> d-------- C:\Documents and Settings\thomas\Application Data\PrevxCSI
2007-12-15 00:31 . 2007-12-15 00:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2007-12-15 00:17 . 2007-12-15 00:16 1,632,200 --a------ C:\Program Files\a2HiJackFreeSetup.exe
2007-12-14 21:28 . 2007-12-14 23:49 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-12-12 18:49 . 2007-12-12 18:51 1,393 --a------ C:\WINDOWS\imsins.BAK
2007-12-10 11:59 . 2007-12-10 11:59 1,158 --a------ C:\WINDOWS\mozver.dat
2007-12-10 05:01 . 2007-12-20 19:42 91,492 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-10 05:01 . 2007-12-12 22:15 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-10 05:00 . 2007-12-10 05:00 <REP> d-------- C:\Program Files\Kaspersky Lab
2007-12-10 05:00 . 2008-01-06 15:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-10 05:00 . 2008-01-06 15:11 9,614,112 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-10 05:00 . 2008-01-06 15:11 210,720 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-10 05:00 . 2008-01-03 14:04 112,412 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-10 05:00 . 2008-01-03 14:04 15,260 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-10 04:58 . 2007-12-10 04:59 24,802,086 --a------ C:\Program Files\kav7.0.0.125.fr.01NET.exe
2007-12-10 04:10 . 2007-12-10 04:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-10 04:06 . 2007-12-10 04:06 <REP> d-------- C:\Documents and Settings\thomas\Application Data\Talkback
2007-12-10 04:06 . 2007-12-10 04:06 0 --a------ C:\WINDOWS\nsreg.dat
2007-12-10 04:00 . 2007-12-10 04:01 5,843,256 --a------ C:\Program Files\Firefox Setup 2.0.0.11.exe
2007-12-10 01:24 . 2007-12-10 03:57 <REP> d-------- C:\Documents and Settings\thomas\Application Data\SUPERAntiSpyware.com
2007-12-10 01:24 . 2007-12-10 01:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-09 16:06 . 2007-12-09 16:06 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-12-07 14:03 . 2007-03-22 03:37 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2007-12-07 14:03 . 2007-03-22 03:37 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-12-07 14:03 . 2007-03-22 02:40 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2007-12-07 14:03 . 2007-03-22 03:37 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2007-12-07 14:03 . 2007-03-22 03:37 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2007-12-07 14:03 . 2007-03-22 03:37 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2007-12-07 14:03 . 2007-12-10 04:10 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-12-07 03:50 . 2007-12-07 14:17 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-07 03:49 . 2007-12-07 03:49 <REP> d-------- C:\Documents and Settings\thomas\Application Data\Simply Super Software
2007-12-07 03:49 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2007-12-07 03:49 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2007-12-07 03:49 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2007-12-07 03:49 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2007-12-07 03:49 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2007-12-07 01:04 . 2007-12-10 04:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-07 00:55 . 2007-12-07 00:55 31,768,752 --a------ C:\Program Files\avg75free_503a1205.exe
2007-12-06 20:23 . 19,456 C:\WINDOWS\system32\drivers\ulmburfg.dat
2007-12-06 01:34 . 2007-12-19 16:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-06 01:33 . 2007-12-06 01:33 7,467,056 --a------ C:\Program Files\spybotsd15.exe
2007-12-06 00:35 . 2004-08-05 13:00 84,992 --a------ C:\WINDOWS\system32\cryptu.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 14:13 --------- d-----w C:\Documents and Settings\thomas\Application Data\WTablet
2008-01-06 13:55 --------- d-----w C:\Program Files\eMule
2007-12-27 18:14 --------- d-----w C:\Documents and Settings\thomas\Application Data\OpenOffice.org2
2007-12-10 03:09 --------- d-----w C:\Documents and Settings\thomas\Application Data\Lavasoft
2007-12-10 02:57 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-12-09 14:15 16,591,390 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_12_09_02_01_49_full.dmp.zip
2007-12-09 14:15 112,835 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_12_09_02_01_16_small.dmp.zip
2007-12-07 00:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-12-04 17:39 3,522,434 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-01 02:00 --------- d-----w C:\Program Files\MSXML 4.0
2007-11-30 11:18 --------- d-----w C:\Program Files\Disc2Phone
2007-11-30 11:14 --------- d-----w C:\Documents and Settings\thomas\Application Data\Teleca
2007-11-30 11:13 --------- d-----w C:\Documents and Settings\thomas\Application Data\Sony Ericsson
2007-11-30 11:10 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2007-11-30 11:10 --------- d-----w C:\Program Files\Fichiers communs\Sony Ericsson Shared
2007-11-30 11:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Teleca
2007-11-30 11:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2007-11-30 11:09 --------- d-----w C:\Program Files\Sony Ericsson
2007-11-27 15:40 1,700,301 ----a-w C:\Program Files\foobar2000_0.9.4.5.exe
2007-11-26 00:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 00:06 --------- d-----w C:\Program Files\Microsoft Digital Image 10
2007-11-01 13:45 2,356,231 ----a-w C:\Program Files\cdbxp_setup_4.0.022.370.exe
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-14 17:47 70,768,312 ----a-w C:\Program Files\163.71_forceware_winxp_32bit_international_whql.exe
2007-08-29 15:33 6,253,563 ----a-w C:\Program Files\freeBrowser-Setup.exe
2007-07-23 15:43 6,360,005 ----a-w C:\Program Files\nvu-1.0-win32-installer-fr.exe
2007-07-11 15:47 5,540,612 ----a-w C:\Program Files\Fptest-3.0.exe
2007-07-11 15:05 12,015,715 ----a-w C:\Program Files\Freeplayer-Win32-20070531.exe
2007-07-08 14:35 3,858,985 ----a-w C:\Program Files\eMule0.48a-Installer.exe
2007-06-28 15:57 41,653,912 ----a-w C:\Program Files\zlsSetup_70_337_000_fr.exe
2007-06-27 23:43 9,679,815 ----a-w C:\Program Files\vlc-0.8.6c-win32.exe
2007-05-08 11:14 17,929,072 ----a-w C:\Program Files\Install_Messenger.exe
2007-05-02 23:24 10,139,765 ----a-w C:\Program Files\TuneUp.Utilities.2007.v6.0.2200.FR.Incl-Keygen.rar
2007-05-01 15:19 6,753,504 ----a-w C:\Program Files\winamp534_full_emusic-7plus.exe
2007-05-01 15:19 1,439,315 ----a-w C:\Program Files\french_translated.exe
2007-04-09 12:58 2,833,783 ----a-w C:\Program Files\MAC_399F.exe
2007-04-04 21:58 1,423,586 ----a-w C:\Program Files\FSCaptureSetup52.exe
2007-04-04 19:53 19,994,184 ----a-w C:\Program Files\QuickTimeInstaller.exe
2007-04-04 18:52 17,241,692 ----a-w C:\Program Files\exapass.exe
2007-04-03 22:32 14,993,976 ----a-w C:\Program Files\GoogleEarthWin_EARW.exe
2007-04-03 21:07 3,992,565 ----a-w C:\Program Files\Matroska_Pack_Full_v1.1.2.exe
2007-04-03 20:30 900,192 ----a-w C:\Program Files\GoogleToolbarInstaller.exe
2007-04-03 16:42 102,461,916 ----a-w C:\Program Files\OOo_2.2.0_Win32Intel_install_fr.exe
2007-04-03 16:09 13,446,648 ----a-w C:\Program Files\setupfre.exe
2006-04-19 19:39 322,008 ----a-w C:\Program Files\dBpowerAMP-codec-musepack.exe
2006-04-19 19:34 1,545,218 ----a-w C:\Program Files\dMC-r9.exe
2006-03-20 13:37 5,689,344 ----a-w C:\Program Files\mplayerc.exe
2006-03-04 01:30 6,652,812 ----a-w C:\Program Files\sld.codec.pack.2.2.exe
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C88D1F4-0561-407F-9C85-50CA02A4D620}]
2004-08-05 13:00 84992 --a------ C:\WINDOWS\system32\cryptu.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-03 21:07 68856]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 15:21 61952 C:\WINDOWS\system32\HdAShCut.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 02:11 925696]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-09-07 15:35 716800]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-04-03 22:25 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54 282624]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-08 23:02 919280]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 22:24 620152]
"Adobe_ID0EYTHM"="C:\PROGRA~1\FICHIE~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 15:40 1884160]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 00:07 8491008]
"nwiz"="nwiz.exe" [2007-09-17 00:07 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 00:07 81920]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51 218376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 23:01:50]
Lancement rapide d'Adobe Acrobat.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2007-09-08 13:55:43]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"OWF"="C:\Program Files\OvisLink\OWF.exe" -nogui

R0 tdgemfyt;tdgemfyt;C:\WINDOWS\system32\drivers\ulmburfg.dat []
R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 08:34]
R2 UxTuneUp;Extension de conception TuneUp;C:\WINDOWS\System32\svchost.exe [2004-08-05 13:00]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 10:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 09:30]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{15160668-6a8e-11dc-8f7d-001a920990c6}]
\Shell\AutoRun\command - F:\wd_windows_tools\setup.exe

*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-12-18 18:19:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-04 16:16:56 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 15:44:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-06 15:46:16
.
2007-12-12 17:52:35 --- E O F ---

En espérant vraiment que quelqu'un pourra m'aider SVP, merci.

2 réponses

Infection par virus.win 32.hllp.shodi.d aide moi
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
7 févr. 2008 à 13:18
salut omenone,

la suite :

Copie le texte ci-dessous :

File::
C:\WINDOWS\system32\cryptu.dll
C:\WINDOWS\system32\drivers\ulmburfg.dat

Folder::


Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C88D1F4-0561-407F-9C85-50CA02A4D620}]

Driver::
tdgemfyt

Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt.

Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

http://serveur1.archive-host.com/membres/up/1366464061/CFScript.gif

Cela va relancer Combofix,

Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

Ne touche à rien tant que le scan n'est pas terminé.

Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

S'il n'y a pas de rédémarrage, poste quand même les rapports.

@+
0