Salut à tous,
Moi aussi j ai duis quelques jours un message de PC CILLIN me disant que j ai ce virus: Cryp Tap-2 et mon antivirus ne peut effectuer aucune action pour s en debarrasser.
Mon ordi fonctionne tres mal depuis. Sur forum j ai suivi la demarche proposée et telechargé Combofix mais je ne crois pas avoir compris comment ça marche car mon virus est toujous là.
Je vais copier cidessous le rapport de Combo-Fix. Si quelqu un pouvait m aider à savoir comment je dois poursuivre, merci beaucoup pour votre réponse.
ComboFix 08-04-04.1 - ANAIS CRESTIN 2008-04-05 5:18:18.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.425 [GMT 2:00]
Endroit: C:\Documents and Settings\ANAIS CRESTIN\Local Settings\Temporary Internet Files\Content.IE5\W7IXJQ4V\ComboFix[1].exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\aIlRstwa.ini
C:\WINDOWS\system32\aIlRstwa.ini2
C:\WINDOWS\system32\awtsRlIa.dll
C:\WINDOWS\system32\cbXOIaWn.dll
C:\WINDOWS\system32\ddcdEwxv.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlJaaWMd.dll
C:\WINDOWS\system32\nnNebYRl.dll
C:\WINDOWS\system32\vtUmmnNf.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-05 to 2008-04-05 ))))))))))))))))))))))))))))))))))))
.
2008-04-02 03:43 . 2003-09-01 13:10 266,240 --a------ C:\WINDOWS\system32\hpdj3600
2008-04-02 03:41 . 2007-02-15 15:30 163,644 --a------ C:\WINDOWS\hpdj3600.hi1
2008-04-02 03:41 . 2007-02-15 15:30 7,565 --a------ C:\WINDOWS\hpdj3600.bu1
2008-03-29 19:04 . 2008-03-29 19:04 <REP> d-------- C:\Program Files\Crystal Player
2008-03-27 00:12 . 2008-03-27 00:11 79,872 -r-hs---- C:\WINDOWS\system32\msnuserv.exe
2008-03-24 20:10 . 2008-03-24 16:28 85,504 -r-hs---- C:\WINDOWS\system32\msnhosts.exe
2008-03-24 06:35 . 2004-08-04 01:40 25,856 --a------ C:\WINDOWS\system32\drivers\hidbth.sys
2008-03-24 06:35 . 2004-08-04 01:40 25,856 --a------ C:\WINDOWS\system32\dllcache\hidbth.sys
2008-03-24 06:34 . 2004-08-04 00:10 38,016 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys
2008-03-24 06:34 . 2004-08-04 00:10 38,016 --a------ C:\WINDOWS\system32\dllcache\bthmodem.sys
2008-03-23 01:03 . 2008-03-23 01:03 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2008-03-16 19:28 . 2008-03-16 19:33 <REP> d-------- C:\Program Files\Winamp
2008-03-16 19:28 . 2008-03-16 19:33 <REP> d-------- C:\Documents and Settings\ANAIS CRESTIN\Application Data\Winamp
2008-03-13 14:02 . 2008-02-22 03:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-10 15:50 . 2008-03-10 15:50 85,504 --a------ C:\WINDOWS\system32.cpl
2008-03-10 15:50 . 2008-03-10 15:50 150 --a------ C:\WINDOWS\fuidominado.partizan
2008-03-10 15:50 . 2008-03-10 15:50 5 --a------ C:\WINDOWS\winload.inf
2008-03-10 15:49 . 2008-03-10 15:49 <REP> d-------- C:\daemon
2008-03-10 15:49 . 2008-03-10 15:50 2,663,403 --a------ C:\WINDOWS\system\codecs.exe
2008-03-10 15:49 . 2008-03-10 15:49 396,820 --a------ C:\WINDOWS\system\sysmod.exe
2008-03-10 15:49 . 2008-03-10 15:49 69,515 --a------ C:\WINDOWS\system\outlok.exe
2008-03-10 15:49 . 2008-03-10 15:49 60,416 --a------ C:\WINDOWS\system32\drivers\kodnkwnv.sys
2008-03-10 15:49 . 2008-03-10 15:49 6,773 --a------ C:\WINDOWS\system\regdaemon.cmd
2008-03-10 15:49 . 2008-03-10 15:49 2,453 --a------ C:\WINDOWS\system32\cleardel.reg
2008-03-10 15:49 . 2008-03-10 15:49 542 --a------ C:\WINDOWS\regdeamon2.reg
2008-03-10 15:49 . 2008-03-10 15:49 539 --a------ C:\WINDOWS\regdeamon.reg
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-05 03:22 --------- d-----w C:\Documents and Settings\ANAIS CRESTIN\Application Data\DNA
2008-04-03 18:53 --------- d-----w C:\Program Files\Hewlett-Packard
2008-04-03 14:57 --------- d-----w C:\Documents and Settings\ANAIS CRESTIN\Application Data\BitTorrent
2008-03-24 04:50 --------- d-----w C:\Documents and Settings\ANAIS CRESTIN\Application Data\DataLayer
2008-03-22 23:02 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-03-22 17:32 --------- d-----w C:\Program Files\Fichiers communs\AVSMedia
2008-03-20 18:48 --------- d-----w C:\Program Files\AOL 9.0
2008-03-20 18:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-03-13 12:02 --------- d-----w C:\Program Files\Java
2008-03-04 23:48 --------- d-----w C:\Program Files\LimeWire
2008-03-02 17:12 --------- d-----w C:\Program Files\Streamload
2008-03-01 14:41 --------- d-----w C:\Program Files\Windows Live
2008-03-01 14:40 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-03-01 14:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-23 02:35 --------- d-----w C:\Documents and Settings\ANAIS CRESTIN\Application Data\Crystal Player
2008-02-22 02:04 --------- d-----w C:\Program Files\DNA
2008-02-22 02:04 --------- d-----w C:\Program Files\BitTorrent
2007-03-09 12:58 327 -c--a-w C:\Program Files\setup.ini
2007-03-07 15:37 3,826,176 -c--a-w C:\Program Files\tmpcc64.msi
2007-03-07 15:34 64 -c--a-w C:\Program Files\Tmsrl.dat
2007-03-07 15:34 61,440 -c--a-w C:\Program Files\1036.mst
2007-03-07 15:34 38,119 -c--a-w C:\Program Files\db_pcc.dat
2007-03-07 15:34 353,808 -c--a-w C:\Program Files\setup.exe
2007-03-07 15:34 3,927,024 -c--a-w C:\Program Files\pcc.exe
2007-03-07 15:34 3,342,848 -c--a-w C:\Program Files\tmpcc.msi
2007-03-07 15:34 106,552 -c--a-w C:\Program Files\license.rtf
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BFA7416F-6EBA-43E5-B485-D32C6C78E1DB}]
C:\WINDOWS\system32\jkkKabaw.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="C:\APPS\SMP\SmpSys.exe" [2005-11-17 10:51 975360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-23 19:25 68856]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-04-20 10:57 847872]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-03-27 12:45 288576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 15:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 15:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 15:00 455168]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 15:01 67584]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-03 16:25 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-03 16:22 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-03 16:26 118784]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-05-25 15:37 14477312 C:\WINDOWS\RTHDCPL.EXE]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-20 12:50 729178]
"AGRSMMSG"="AGRSMMSG.exe" [2005-05-11 13:12 88204 C:\WINDOWS\AGRSMMSG.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 15:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 10:39 167936]
"DataLayer"="C:\Program Files\Fichiers communs\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 10:30 1106944]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-02-12 16:57 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-02-12 16:59 77824]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [2006-04-03 21:54 901185]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57 282624]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-16 00:54 37376]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-03-23 01:02 185896]
"MSN User Services"="msnuserv.exe" [2008-03-27 00:11 79872 C:\WINDOWS\system32\msnuserv.exe]
"nebyxtg"="C:\WINDOWS\system32\nebyxtg.exe" [ ]
"volume"="C:\windows\system\sysmod.exe" [2008-03-10 15:49 396820]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 15:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BFA7416F-6EBA-43E5-B485-D32C6C78E1DB}"= C:\WINDOWS\system32\jkkKabaw.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXOIaWn]
cbXOIaWn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkKabaw]
jkkKabaw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.mpegacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm
"MSVideo8"= VfWWDM32.dll
"msacm.enc"= ITIG726.acm
"MSVideo"= vfwwdm32.dll
"msacm.scg726"= scg726.acm
"msacm.alf2cd"= alf2cd.acm
"msacm.ac3acm"= AC3ACM.acm
"vidc.dvsd"= mcdvd_32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a155f7c-36aa-11dc-ac8b-00038a000015}]
\Shell\AutoRun\command - wd_windows_tools\setup.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-03 12:59:14 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
- C:\WINDOWS\system32\rundll32.exelC:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.2.25.1.sxt _RegistrationOffer@16
"2008-04-05 03:27:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"