TROJAN

Résolu
Bonjour,
Est ce quelqu'un peut m'aider....
Configuration: Windows XP
Firefox 3.0.5

119 réponses

Résumé de la discussion

Une machine Windows XP avec Firefox 3.0.5 est infectée et nécessite un nettoyage approfondi avec Antivir, ComboFix et RSIT, ainsi que des rapports de diagnostic. Les actions recommandées incluent la suppression de la quarantaine Antivir, la désinstallation de ComboFix via /u, la vérification du dossier Qoobox et la génération de rapports RSIT et FindyKill. Des conseils complémentaires préconisent la mise à jour du système et des applications (SP2/SP3 selon le cas, Acrobat Reader, Java via JavaRa), puis l’usage d’outils comme ToolsCleaner et CCleaner et l’installation d’un pare-feu. Par ailleurs, un rapport VirusTotal indique que de nombreux moteurs détectent le même fichier, ce qui renforce la nécessité d’un scan complet et d’un nettoyage approfondi.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonsoir,

    Télécharge et installe HijackThis .
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    Choisir « Download Hijackthis Installer »
    Après l'installation, un raccourci sera crée sur le bureau. Double-clique dessus pour le lancer ( si sous Vista --> Click droit et executer en tant qu’administrateur )

    Choisir l'option Do a system scan and save a logfile.
    Le rapport va s'ouvrir. Tu copies/colles le contenu de ce rapport dans ton prochain message

    A+
    1. bonsoir,

      Voici le rapport
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:48:20, on 07/01/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18241)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\fxssvc.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Dell\QuickSet\quickset.exe
      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
      C:\Program Files\Dell\Media Experience\DMXLauncher.exe
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
      C:\Program Files\MessengerPlus! 3\MsgPlus.exe
      C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
      C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
      C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
      C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Microsoft ActiveSync\wcescomm.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\PROGRA~1\MI3AA1~1\rapimgr.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/en-ca
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - Default URLSearchHook is missing
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
      O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
      O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
      O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
      O4 - HKLM\..\Run: [D-Link D-Link Wireless G DWA-110] C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
      O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
      O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Digital Line Detect.lnk = ?
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O17 - HKLM\System\CCS\Services\Tcpip\..\{1B487E6D-11CA-4970-92FB-C3A4479520A4}: NameServer = 212.27.53.252
      O17 - HKLM\System\CCS\Services\Tcpip\..\{5C8F6EEE-F82A-4ADB-BC59-95672CB12DB2}: NameServer = 212.27.40.241,212.27.40.240
      O17 - HKLM\System\CCS\Services\Tcpip\..\{5DAE992A-F552-419D-9387-E52AFFA5C973}: NameServer = 212.27.53.252,212.27.54.252
      O17 - HKLM\System\CCS\Services\Tcpip\..\{E353B724-DDB3-41ED-BE6A-C20883EDCF94}: NameServer = 212.27.53.252,212.27.54.252
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
      O20 - Winlogon Notify: 34694bd2511 - C:\WINDOWS\System32\ddeml32.dll
      O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
      O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
      O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      1. Contributeur sécurité
        Pourrais-tu me dire ce qui te fais penser que tu es infecté par un trojan ?
        Essaie de m'expliquer au mieux ton problème.

        Télécharges Random's System Information Tool (RSIT) de random/random et enregistre le sur ton Bureau.
        http://images.malwareremoval.com/random/RSIT.exe

        Double-clique sur " RSIT.exe " pour le lancer .
        dans la fenêtre qui va s’ouvrir choisis 2 months pour l'option "List files/folders created ..." ,
        cliques ensuite sur " Continue " pour lancer l'analyse ...

        Si la dernière version de HijackThis n'est pas trouvée sur ton PC, RSIT la téléchargera et te demandera d'accepter la licence.

        Attends jusqu’à la fin de l’analyse.
        deux rapports vont être generés.

        Poste le contenu de " log.txt ", ainsi que de " info.txt " ( dans la barre des tâches), pour analyse et attends la suite ...

        Si tu ne les trouves pas,les rapports sont sauvegardés dans le dossier C:\rsit.

        A+
        1. Re,

          C'est ANTIVIR qui n'arrête pas de me le dire, il me signale un TR/Spy.Gén. J'ai été obligé de le désactiver car il ne veut ni le mettre en quarantaine ni le supprimer, et il n'arrete de m'ouvrir des fenêtres.
          En ce qui concerne les rapports, les voici
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 20:48:20, on 07/01/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18241)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
          C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\fxssvc.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\Program Files\Dell\QuickSet\quickset.exe
          C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
          C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
          C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
          C:\Program Files\MessengerPlus! 3\MsgPlus.exe
          C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
          C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
          C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
          C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
          C:\Program Files\Digital Line Detect\DLG.exe
          C:\PROGRA~1\MI3AA1~1\rapimgr.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/en-ca
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - Default URLSearchHook is missing
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
          O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
          O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
          O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
          O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
          O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
          O4 - HKLM\..\Run: [D-Link D-Link Wireless G DWA-110] C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
          O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
          O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Digital Line Detect.lnk = ?
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
          O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O17 - HKLM\System\CCS\Services\Tcpip\..\{1B487E6D-11CA-4970-92FB-C3A4479520A4}: NameServer = 212.27.53.252
          O17 - HKLM\System\CCS\Services\Tcpip\..\{5C8F6EEE-F82A-4ADB-BC59-95672CB12DB2}: NameServer = 212.27.40.241,212.27.40.240
          O17 - HKLM\System\CCS\Services\Tcpip\..\{5DAE992A-F552-419D-9387-E52AFFA5C973}: NameServer = 212.27.53.252,212.27.54.252
          O17 - HKLM\System\CCS\Services\Tcpip\..\{E353B724-DDB3-41ED-BE6A-C20883EDCF94}: NameServer = 212.27.53.252,212.27.54.252
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
          O20 - Winlogon Notify: 34694bd2511 - C:\WINDOWS\System32\ddeml32.dll
          O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
          O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
          O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
          O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          1. Contributeur sécurité
            Tu vas télécharger ComBoFix et enregistre le sur ton bureau ( important pour la suite )
            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

            On va installer la console de récupération pour pouvoir utiliser ComBoFix. IMPORTANT.
            Choisis le lien suivant ta version de XP ( familiale ou professionnelle ) :

            Windows XP Édition familiale :
            http://www.microsoft.com/downloads/details.aspx?FamilyId=15491F07-99F7-4A2D-983D-81C2137FF464&displaylang=fr
            Windows XP Professionnel
            http://www.microsoft.com/downloads/details.aspx?FamilyId=535D248D-5E10-49B5-B80C-0A0205368124&displaylang=fr

            Télécharges la console sur ton bureau ( Important ).

            déconnecte toi du net.
            Désactive les protections résidentes de ton ordinateur ( antivirus, antispyware et parefeu )
            Branche tes différents supports amovibles ( clés USB, disque dur externe ) sans les ouvrir.

            Glisse/Dépose ce fichier sur l'icone de ComBoFix.
            Regarde le lien suivant si tu ne sais pas ce qu'est un Glisser/Déposer
            http://img.bleepingcomputer.com/combofix/usage/rc.gif

            Ceci va lancer combofix et installer la console de récupération.
            Accepte le contrat de licence.
            Tu devrais avoir un message de confirmation de la bonne installation de la console.
            Clique sur Oui pour continuer le scan.

            Poste le rapport que tu auras obtenu.

            A+
            1. Re,

              cela fait 2 fois que je te poste le log de combix l'as tu reçu ?
              1. Contributeur sécurité
                Peux-tu analyser les fichiers suivants :

                c:\windows\system32\docprop232.dll
                c:\windows\system32\dlbuma.GID


                sur le site de virus total.
                https://www.virustotal.com/gui/

                Copie successivement le chemin indiqué ci-dessus et le coller dans la zone à analyser.
                Tu cliques ensuite sur envoyer le fichier.
                Tu postes le rapport de l'analyse ( pour cela, tu sélectionnes la zone de résultat --> click droit --> copier )

                Je regarde le rapport et te poste les consignes en fin de matinée.

                A+
                1. Re,

                  Voici les rapports demandés

                  Antivirus Version Dernière mise à jour Résultat
                  a-squared - - Trojan-Downloader.Win32.Tracur!IK
                  AhnLab-V3 - - Win-Trojan/Agent.135168.DV
                  AntiVir - - TR/Spy.Gen
                  Authentium - - W32/Heuristic-KPP!Eldorado
                  Avast - - Win32:Spyware-gen
                  AVG - - PSW.OnlineGames.BIYW
                  BitDefender - - Trojan.Generic.1221950
                  CAT-QuickHeal - - TrojanDownloader.Agent.atko
                  ClamAV - - Trojan.Downloader-62571
                  Comodo - - TrojWare.Win32.TrojanDownloader.Agent.~AVB
                  DrWeb - - Trojan.DownLoader.origin
                  eTrust-Vet - - -
                  Ewido - - -
                  F-Prot - - W32/Heuristic-KPP!Eldorado
                  F-Secure - - Trojan-Downloader.Win32.Agent.atko
                  Fortinet - - W32/Agent.ATKO!tr.dldr
                  GData - - Trojan.Generic.1221950
                  Ikarus - - Trojan-Downloader.Win32.Tracur
                  K7AntiVirus - - Trojan-Downloader.Win32.Agent.atko
                  Kaspersky - - Trojan-Downloader.Win32.Agent.atko
                  McAfee - - Generic Downloader.x
                  McAfee+Artemis - - Generic Downloader.x
                  Microsoft - - TrojanDownloader:Win32/Tracur.A
                  NOD32 - - Win32/Agent.OAF
                  Norman - - -
                  Panda - - Trj/Downloader.VEB
                  PCTools - - Trojan-Downloader.Agent!sd6
                  Prevx1 - - Cloaked Malware
                  Rising - - Trojan.Win32.Undef.upp
                  SecureWeb-Gateway - - Trojan.Spy.Gen
                  Sophos - - Troj/Agent-INP
                  Sunbelt - - -
                  Symantec - - Backdoor.Trojan
                  TheHacker - - Trojan/Downloader.Agent.atko
                  TrendMicro - - -
                  VBA32 - - Trojan-Downloader.Win32.Agent.atko
                  ViRobot - - Trojan.Win32.Downloader.135168.AK
                  VirusBuster - - -
                  Information additionnelle
                  MD5: 48ec15766e87347733c366cd192d2471
                  SHA1: 0d0a070f8fe3848b753ce2d0fcac5be71e1375c8
                  SHA256: 6c591314be69252cf0d40530d5da71b556a0f3af18e7e646a9f9f24f221df042

                  2éme rapport

                  Antivirus Version Dernière mise à jour Résultat
                  a-squared 4.0.0.73 2009.01.07 -
                  AhnLab-V3 2009.1.8.0 2009.01.07 -
                  AntiVir 7.9.0.45 2009.01.07 -
                  Authentium 5.1.0.4 2009.01.07 -
                  Avast 4.8.1281.0 2009.01.07 -
                  AVG 8.0.0.199 2009.01.07 -
                  BitDefender 7.2 2009.01.07 -
                  CAT-QuickHeal 10.00 2009.01.06 -
                  ClamAV 0.94.1 2009.01.07 -
                  Comodo 891 2009.01.07 -
                  DrWeb 4.44.0.09170 2009.01.07 -
                  eSafe 7.0.17.0 2009.01.06 -
                  eTrust-Vet 31.6.6296 2009.01.07 -
                  Ewido 4.0 2008.12.31 -
                  F-Prot 4.4.4.56 2009.01.07 -
                  F-Secure 8.0.14470.0 2009.01.07 -
                  Fortinet 3.117.0.0 2009.01.07 -
                  GData 19 2009.01.07 -
                  Ikarus T3.1.1.45.0 2009.01.07 -
                  K7AntiVirus 7.10.581 2009.01.07 -
                  Kaspersky 7.0.0.125 2009.01.07 -
                  McAfee 5488 2009.01.07 -
                  McAfee+Artemis 5488 2009.01.07 -
                  Microsoft 1.4205 2009.01.07 -
                  NOD32 3749 2009.01.07 -
                  Norman 5.99.02 2009.01.07 -
                  Panda 9.0.0.4 2009.01.07 -
                  PCTools 4.4.2.0 2009.01.07 -
                  Prevx1 V2 2009.01.08 -
                  Rising 21.11.22.00 2009.01.07 -
                  SecureWeb-Gateway 6.7.6 2009.01.07 -
                  Sophos 4.37.0 2009.01.07 -
                  Sunbelt 3.2.1809.2 2008.12.22 -
                  Symantec 10 2009.01.07 -
                  TheHacker 6.3.1.4.211 2009.01.07 -
                  TrendMicro 8.700.0.1004 2009.01.07 -
                  VBA32 3.12.8.10 2009.01.07 -
                  ViRobot 2009.1.7.1548 2009.01.07 -
                  VirusBuster 4.5.11.0 2009.01.07 -
                  Information additionnelle
                  File size: 32387 bytes
                  MD5...: 3f73b28fb6efec6b0f98c1d82a6d817b
                  SHA1..: 8f98d74b37353b4d794ed8c5e4dd5c820ae87534
                  SHA256: 6a95e036b2e04164f68d330402dc0ed090a2a7dcc9228a06d8b6aee4a30bc8ff
                  SHA512: 00a62549fa0c05d2b7be3daa59a63387543469a88abef3d10a8af8bb8288074f
                  261f710fdd7ae0327c32f2ca2cc3b0eaba94011489ad1e8ec660ac658791e43a
                  ssdeep: 768:1+PF+s+c62V662Vkz+H+SgOtyqi/iMykzNi/iMyk:oPFnPSBtyqi/uSNi/u
                  PEiD..: -
                  TrID..: File type identification
                  GID Help index (50.0%)
                  Windows HELP File (49.9%)
                  PEInfo: -

                  Merci pour tes infos
                  Je me reconnecte demain en fin de matinée.
                  Bonsoir
                  1. Contributeur sécurité
                    1) Ouvre le bloc-notes et sélectionne le texte en citation.
                    Copie/colle ce texte dans le bloc-notes.

                    Killall::

                    :File
                    c:\windows\system32\ddeml32.dll
                    c:\windows\system32\15F.tmp
                    c:\windows\system32\docprop232.dll


                    Enregistre le fichier sur le bureau et nomme-le CFScript.txt.

                    2) Vérifie que l'icone de Combofix se trouve également sur le bureau, sinon, tu retélécharges combofix et tu l'enregistres aussi sur le bureau.
                    Glisse/dépose le script sur ComBoFix comme indiqué sur le lien suivant.
                    http://img.photobucket.com/albums/v666/sUBs/CFScript.gif

                    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                    Ton bureau va disparaître à plusieurs reprises. Normal.
                    L'ordinateur va redémarrer et un arrport sera crée.
                    tu enregistres le rapport et tu le postes;
                    Si tu ne le trouves pas, il est en C:\Combofix.txt

                    3) Tu télécharges MalwareBytes.
                    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    Tu l'installes. Choisis les options par défaut.
                    A la fin de l’installation, il te sera demandé de mettre à jour MalwareBytes et de l’éxecuter .
                    Accepte. Après la, mise à jour, le logiciel va s’ouvrir.

                    Dans l’onglet Recherche, sélectionne Exécuter un examen complet.
                    Clique sur recherche. Tu ne sélectionnes que les disques durs de l’ordinateur.
                    Clique sur lancer l’examen.

                    A la fin de la recherche, comme il est demandé, clique sur afficher les résultats.
                    Si des infections sont trouvées, clique sur Supprimer la sélection.
                    Tu postes le rapport dans ton prochain message.

                    Si tu ne retrouves pas le rapport, ouvre MalwareBytes et regarde dans l’onglet Rapport/logs. Il y est. Clique dessus et choisir ouvrir.

                    A+
                    1. Je reprends contact et demande de l'aide
                      Merci pour vos réponses
                      1. Bonsoir,

                        Quelqu'un peut m'aider, cela plus de 2 jours que je suis sur le meme probleme avec des bénévoles différents mais j'ai toujours mon probleme de trojan
                        1. Contributeur sécurité
                          Peux-tu regarder mon post précédent.
                          Je l'ai modifié.

                          Merci.

                          A+
                          • 1
                          • 2
                          • 3
                          • 4
                          • 5
                          • 6