Infection toxbot par perfhmon.exe
Pat K
-
Pat K -
Pat K -
Bonjour à tous,
J'ai été infecté par un toxbot. Norton me signale que c'est le fichier perfhmon.exe dans System32 qui est infecté. J'ai essayé de suivre les étapes mentionnées dans les autres demandes de ce forum mais les lignes à suppirmer dans Hijackthis n'apparaissent pas. Je suppose que c'est parce que le fichier infecté est différent. Voici mon log Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 18:48:51, on 08/09/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\Perfhmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\GSICON.EXE
C:\WINDOWS\System32\dslagent.exe
C:\PROGRA~1\DAP\DAP.EXE
C:\WINDOWS\System32\lfxss.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\SygateFirewall.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\PK\Local Settings\Temp\Répertoire temporaire 3 pour Hijackthis-1-99-1-et-totoriel.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O1 - Hosts: 70.84.177.197 onlineaccounts2.abbeynational.co.uk
O1 - Hosts: 70.84.177.197 www3.aibgbonline.co.uk
O1 - Hosts: 70.84.177.197 www.bank.alliance-leicester.co.uk
O1 - Hosts: 70.84.177.197 login.iblogin.com
O1 - Hosts: 70.84.177.197 ww2.bankofscotlandhalifax-online.co.uk
O1 - Hosts: 70.84.177.197 inet.barclays.co.uk
O1 - Hosts: 70.84.177.197 iibank.barclays.co.uk
O1 - Hosts: 70.84.177.197 iibank.cahoot.com
O1 - Hosts: 70.84.177.197 www3.coventrybuildingsociety.co.uk
O1 - Hosts: 70.84.177.197 ww.hsbc.co.uk
O1 - Hosts: 70.84.177.197 login.ebank.offshore.hsbc.co.je
O1 - Hosts: 70.84.177.197 ww3.online-offshore.lloydstsb.com
O1 - Hosts: 70.84.177.197 ww3.online-business.lloydstsb.co.uk
O1 - Hosts: 70.84.177.197 ww3.online.lloydstsb.co.uk
O1 - Hosts: 70.84.177.197 ww3.online.lloydstsb.co.uk
O1 - Hosts: 70.84.177.197 ww3.online-business.lloydstsb.co.uk
O1 - Hosts: 70.84.177.197 ob2.nationet.com
O1 - Hosts: 70.84.177.197 ww3.onlinebanking.natwestoffshore.com
O1 - Hosts: 70.84.177.197 ww1.nwolb.com
O1 - Hosts: 70.84.177.197 ww1.onlinebanking.iombank.com
O1 - Hosts: 70.84.177.197 ww1.www.rbsdigital.com
O1 - Hosts: 70.84.177.197 welcome.smile.co.uk
O1 - Hosts: 70.84.177.197 login.365online.com
O1 - Hosts: 70.84.177.197 wvw.citizensbankonline.com
O1 - Hosts: 70.84.177.197 esecure.regionsnet.com
O1 - Hosts: 70.84.177.197 rollb.associatedbank.com
O1 - Hosts: 70.84.177.197 upb.unionplanters.com
O1 - Hosts: 70.84.177.197 www.onlinebanking.huntington.com
O1 - Hosts: 70.84.177.197 inet.southtrustonlinebanking.com
O1 - Hosts: 70.84.177.197 logon.personal.wamu.com
O1 - Hosts: 70.84.177.197 login.compassweb.com
O1 - Hosts: 70.84.177.197 logon.firstmeritib.com
O1 - Hosts: 70.84.177.197 login.ccfcuonline.org
O1 - Hosts: 70.84.177.197 ww3.etimebanker.bankofthewest.com
O1 - Hosts: 70.84.177.197 ww2.onlinebanking.lasallebank.com
O1 - Hosts: 70.84.177.197 wvw.totallyfreebanking.com
O1 - Hosts: 70.84.177.197 www.online.wellsfargo.com
O1 - Hosts: 70.84.177.197 www.onlinebanking.bankofoklahoma.com
O1 - Hosts: 70.84.177.197 accounts4.keybank.com
O1 - Hosts: 70.84.177.197 logon.bankone.com
O1 - Hosts: 70.84.177.197 www.secure.tdbanknorth.com
O1 - Hosts: 70.84.177.197 www.secure.mvnt4.com
O1 - Hosts: 70.84.177.197 ww.mynfbonline.com
O1 - Hosts: 70.84.177.197 login.forumcuonline.com
O1 - Hosts: 70.84.177.197 www.eds.usersonlnet.com
O1 - Hosts: 70.84.177.197 www.onlineid.bankofamerica.com
O1 - Hosts: 70.84.177.197 wvw.e-gold.com
O1 - Hosts: 70.84.177.197 pcbs.peoples.com
O1 - Hosts: 70.84.177.197 www.global1.onlinebank.com
O1 - Hosts: 70.84.177.197 ww2.mybranch.lafcu.com
O1 - Hosts: 70.84.177.197 login.webbanking.comerica.com
O1 - Hosts: 70.84.177.197 web.banking.firsttennessee.com
O1 - Hosts: 70.84.177.197 logon.members1st.org
O1 - Hosts: 70.84.177.197 www.cib.ibanking-services.com
O1 - Hosts: 70.84.177.197 www.miwebbusbank.ebanking-services.com
O1 - Hosts: 70.84.177.197 wvw.paypal.com
O1 - Hosts: 70.84.177.197 www.signin.ebay.com
O1 - Hosts: 70.84.177.197 wvw.etrade.com
O1 - Hosts: 70.84.177.197 ww4.fleethomelink.fleet.com
O1 - Hosts: 70.84.177.197 ww3.connect.skyfi.com
O1 - Hosts: 70.84.177.197 www6.usbank.com
O1 - Hosts: 70.84.177.197 www.bvi.bancodevalencia.es
O1 - Hosts: 70.84.177.197 extrant.banesto.es
O1 - Hosts: 70.84.177.197 banesnt.banesto.es
O1 - Hosts: 70.84.177.197 activia.caixagalicia.es
O1 - Hosts: 70.84.177.197 www.bancae.caixapenedes.com
O1 - Hosts: 70.84.177.197 login.caixasabadell.net
O1 - Hosts: 70.84.177.197 oii.cajamadrid.es
O1 - Hosts: 70.84.177.197 login.cajamar.es
O1 - Hosts: 70.84.177.197 login.ccm.es
O1 - Hosts: 70.84.177.197 ww.unicaja.es
O1 - Hosts: 70.84.177.197 www5.bancopopular.es
O1 - Hosts: 70.84.177.197 ww3.bbvanet.com
O1 - Hosts: 70.84.177.197 ww.bayernlb.de
O1 - Hosts: 70.84.177.197 ww2.berliner-volksbank.de
O1 - Hosts: 70.84.177.197 ww7.homebanking-berlin.de
O1 - Hosts: 70.84.177.197 portal09.commerzbanking.de
O1 - Hosts: 70.84.177.197 www.meine.deutsche-bank.de
O1 - Hosts: 70.84.177.197 ww2.dresdner-privat.de
O1 - Hosts: 70.84.177.197 ww.e-banking.helaba.de
O1 - Hosts: 70.84.177.197 ww.hsh-nordbank.de
O1 - Hosts: 70.84.177.197 www.my.hypovereinsbank.de
O1 - Hosts: 70.84.177.197 ww3.homebanking-berlin.de
O1 - Hosts: 70.84.177.197 ww3.homebanking-berlin.de
O1 - Hosts: 70.84.177.197 www.banking.lbbw.de
O1 - Hosts: 70.84.177.197 lrp.sparkasse-banking.de
O1 - Hosts: 70.84.177.197 ww3.homebanking-niedersachsen.de
O1 - Hosts: 70.84.177.197 www.onlinebanking.norisbank.de
O1 - Hosts: 70.84.177.197 www.banking.postbank.de
O1 - Hosts: 70.84.177.197 wvw.internetbanking.gad.de
O1 - Hosts: 70.84.177.197 ww1.portal.izb.de
O1 - Hosts: 70.84.177.197 wvw.kunden-service.lbs.de
O1 - Hosts: 70.84.177.197 ibanking.seb.de
O1 - Hosts: 70.84.177.197 bw7.sparkasse-banking.de
O1 - Hosts: 70.84.177.197 ww2.homebanking-sparkasse.de
O1 - Hosts: 70.84.177.197 ww2.vr-networld-ebanking.de
O1 - Hosts: 70.84.177.197 ww.bics.fr
O1 - Hosts: 70.84.177.197 www.co.caixabank.fr
O1 - Hosts: 70.84.177.197 ww.creditmutuel.fr
O1 - Hosts: 70.84.177.197 internetbank.intesabci.it
O1 - Hosts: 70.84.177.197 ww.extensive.bancalombarda.it
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Microsoft Java Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINDOWS\System32\dllcache\java.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [BnCtest2] lfxss.exe
O4 - HKLM\..\Run: [Sygate Personal Firewall] SygateFirewall.exe
O4 - HKLM\..\RunServices: [BnCtest2] lfxss.exe
O4 - HKLM\..\RunServices: [Sygate Personal Firewall] SygateFirewall.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Sygate Personal Firewall] SygateFirewall.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Performance Logs (Perfhmon) - Unknown owner - C:\WINDOWS\System32\Perfhmon.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
Quelq'un peux-t-il identifier ce qui ne va pas?
Merci d'avance.
J'ai été infecté par un toxbot. Norton me signale que c'est le fichier perfhmon.exe dans System32 qui est infecté. J'ai essayé de suivre les étapes mentionnées dans les autres demandes de ce forum mais les lignes à suppirmer dans Hijackthis n'apparaissent pas. Je suppose que c'est parce que le fichier infecté est différent. Voici mon log Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 18:48:51, on 08/09/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\Perfhmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\GSICON.EXE
C:\WINDOWS\System32\dslagent.exe
C:\PROGRA~1\DAP\DAP.EXE
C:\WINDOWS\System32\lfxss.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\SygateFirewall.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\PK\Local Settings\Temp\Répertoire temporaire 3 pour Hijackthis-1-99-1-et-totoriel.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O1 - Hosts: 70.84.177.197 onlineaccounts2.abbeynational.co.uk
O1 - Hosts: 70.84.177.197 www3.aibgbonline.co.uk
O1 - Hosts: 70.84.177.197 www.bank.alliance-leicester.co.uk
O1 - Hosts: 70.84.177.197 login.iblogin.com
O1 - Hosts: 70.84.177.197 ww2.bankofscotlandhalifax-online.co.uk
O1 - Hosts: 70.84.177.197 inet.barclays.co.uk
O1 - Hosts: 70.84.177.197 iibank.barclays.co.uk
O1 - Hosts: 70.84.177.197 iibank.cahoot.com
O1 - Hosts: 70.84.177.197 www3.coventrybuildingsociety.co.uk
O1 - Hosts: 70.84.177.197 ww.hsbc.co.uk
O1 - Hosts: 70.84.177.197 login.ebank.offshore.hsbc.co.je
O1 - Hosts: 70.84.177.197 ww3.online-offshore.lloydstsb.com
O1 - Hosts: 70.84.177.197 ww3.online-business.lloydstsb.co.uk
O1 - Hosts: 70.84.177.197 ww3.online.lloydstsb.co.uk
O1 - Hosts: 70.84.177.197 ww3.online.lloydstsb.co.uk
O1 - Hosts: 70.84.177.197 ww3.online-business.lloydstsb.co.uk
O1 - Hosts: 70.84.177.197 ob2.nationet.com
O1 - Hosts: 70.84.177.197 ww3.onlinebanking.natwestoffshore.com
O1 - Hosts: 70.84.177.197 ww1.nwolb.com
O1 - Hosts: 70.84.177.197 ww1.onlinebanking.iombank.com
O1 - Hosts: 70.84.177.197 ww1.www.rbsdigital.com
O1 - Hosts: 70.84.177.197 welcome.smile.co.uk
O1 - Hosts: 70.84.177.197 login.365online.com
O1 - Hosts: 70.84.177.197 wvw.citizensbankonline.com
O1 - Hosts: 70.84.177.197 esecure.regionsnet.com
O1 - Hosts: 70.84.177.197 rollb.associatedbank.com
O1 - Hosts: 70.84.177.197 upb.unionplanters.com
O1 - Hosts: 70.84.177.197 www.onlinebanking.huntington.com
O1 - Hosts: 70.84.177.197 inet.southtrustonlinebanking.com
O1 - Hosts: 70.84.177.197 logon.personal.wamu.com
O1 - Hosts: 70.84.177.197 login.compassweb.com
O1 - Hosts: 70.84.177.197 logon.firstmeritib.com
O1 - Hosts: 70.84.177.197 login.ccfcuonline.org
O1 - Hosts: 70.84.177.197 ww3.etimebanker.bankofthewest.com
O1 - Hosts: 70.84.177.197 ww2.onlinebanking.lasallebank.com
O1 - Hosts: 70.84.177.197 wvw.totallyfreebanking.com
O1 - Hosts: 70.84.177.197 www.online.wellsfargo.com
O1 - Hosts: 70.84.177.197 www.onlinebanking.bankofoklahoma.com
O1 - Hosts: 70.84.177.197 accounts4.keybank.com
O1 - Hosts: 70.84.177.197 logon.bankone.com
O1 - Hosts: 70.84.177.197 www.secure.tdbanknorth.com
O1 - Hosts: 70.84.177.197 www.secure.mvnt4.com
O1 - Hosts: 70.84.177.197 ww.mynfbonline.com
O1 - Hosts: 70.84.177.197 login.forumcuonline.com
O1 - Hosts: 70.84.177.197 www.eds.usersonlnet.com
O1 - Hosts: 70.84.177.197 www.onlineid.bankofamerica.com
O1 - Hosts: 70.84.177.197 wvw.e-gold.com
O1 - Hosts: 70.84.177.197 pcbs.peoples.com
O1 - Hosts: 70.84.177.197 www.global1.onlinebank.com
O1 - Hosts: 70.84.177.197 ww2.mybranch.lafcu.com
O1 - Hosts: 70.84.177.197 login.webbanking.comerica.com
O1 - Hosts: 70.84.177.197 web.banking.firsttennessee.com
O1 - Hosts: 70.84.177.197 logon.members1st.org
O1 - Hosts: 70.84.177.197 www.cib.ibanking-services.com
O1 - Hosts: 70.84.177.197 www.miwebbusbank.ebanking-services.com
O1 - Hosts: 70.84.177.197 wvw.paypal.com
O1 - Hosts: 70.84.177.197 www.signin.ebay.com
O1 - Hosts: 70.84.177.197 wvw.etrade.com
O1 - Hosts: 70.84.177.197 ww4.fleethomelink.fleet.com
O1 - Hosts: 70.84.177.197 ww3.connect.skyfi.com
O1 - Hosts: 70.84.177.197 www6.usbank.com
O1 - Hosts: 70.84.177.197 www.bvi.bancodevalencia.es
O1 - Hosts: 70.84.177.197 extrant.banesto.es
O1 - Hosts: 70.84.177.197 banesnt.banesto.es
O1 - Hosts: 70.84.177.197 activia.caixagalicia.es
O1 - Hosts: 70.84.177.197 www.bancae.caixapenedes.com
O1 - Hosts: 70.84.177.197 login.caixasabadell.net
O1 - Hosts: 70.84.177.197 oii.cajamadrid.es
O1 - Hosts: 70.84.177.197 login.cajamar.es
O1 - Hosts: 70.84.177.197 login.ccm.es
O1 - Hosts: 70.84.177.197 ww.unicaja.es
O1 - Hosts: 70.84.177.197 www5.bancopopular.es
O1 - Hosts: 70.84.177.197 ww3.bbvanet.com
O1 - Hosts: 70.84.177.197 ww.bayernlb.de
O1 - Hosts: 70.84.177.197 ww2.berliner-volksbank.de
O1 - Hosts: 70.84.177.197 ww7.homebanking-berlin.de
O1 - Hosts: 70.84.177.197 portal09.commerzbanking.de
O1 - Hosts: 70.84.177.197 www.meine.deutsche-bank.de
O1 - Hosts: 70.84.177.197 ww2.dresdner-privat.de
O1 - Hosts: 70.84.177.197 ww.e-banking.helaba.de
O1 - Hosts: 70.84.177.197 ww.hsh-nordbank.de
O1 - Hosts: 70.84.177.197 www.my.hypovereinsbank.de
O1 - Hosts: 70.84.177.197 ww3.homebanking-berlin.de
O1 - Hosts: 70.84.177.197 ww3.homebanking-berlin.de
O1 - Hosts: 70.84.177.197 www.banking.lbbw.de
O1 - Hosts: 70.84.177.197 lrp.sparkasse-banking.de
O1 - Hosts: 70.84.177.197 ww3.homebanking-niedersachsen.de
O1 - Hosts: 70.84.177.197 www.onlinebanking.norisbank.de
O1 - Hosts: 70.84.177.197 www.banking.postbank.de
O1 - Hosts: 70.84.177.197 wvw.internetbanking.gad.de
O1 - Hosts: 70.84.177.197 ww1.portal.izb.de
O1 - Hosts: 70.84.177.197 wvw.kunden-service.lbs.de
O1 - Hosts: 70.84.177.197 ibanking.seb.de
O1 - Hosts: 70.84.177.197 bw7.sparkasse-banking.de
O1 - Hosts: 70.84.177.197 ww2.homebanking-sparkasse.de
O1 - Hosts: 70.84.177.197 ww2.vr-networld-ebanking.de
O1 - Hosts: 70.84.177.197 ww.bics.fr
O1 - Hosts: 70.84.177.197 www.co.caixabank.fr
O1 - Hosts: 70.84.177.197 ww.creditmutuel.fr
O1 - Hosts: 70.84.177.197 internetbank.intesabci.it
O1 - Hosts: 70.84.177.197 ww.extensive.bancalombarda.it
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Microsoft Java Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINDOWS\System32\dllcache\java.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [BnCtest2] lfxss.exe
O4 - HKLM\..\Run: [Sygate Personal Firewall] SygateFirewall.exe
O4 - HKLM\..\RunServices: [BnCtest2] lfxss.exe
O4 - HKLM\..\RunServices: [Sygate Personal Firewall] SygateFirewall.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Sygate Personal Firewall] SygateFirewall.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Performance Logs (Perfhmon) - Unknown owner - C:\WINDOWS\System32\Perfhmon.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
Quelq'un peux-t-il identifier ce qui ne va pas?
Merci d'avance.
A voir également:
- Infection toxbot par perfhmon.exe
- Infection par smidfaufix ! ✓ - Forum Virus
- L'ordinateur de simon a été infecté par un virus répertorié récemment - Forum Jeux vidéo
- Infection - Forum Virus
- L'ordinateur d'arthur a été infecté par un virus répertorié récemment ✓ - Forum Virus
- Possible infection par PnkBstrA.exe ✓ - Forum Virus
2 réponses
salut,
avant nettoyage, quelques verif de principe:
va sur
http://virusscan.jotti.org
et teste le fichier:
C:\WINDOWS\System32\lfxss.exe
copie et colle le log.
avant nettoyage, quelques verif de principe:
va sur
http://virusscan.jotti.org
et teste le fichier:
C:\WINDOWS\System32\lfxss.exe
copie et colle le log.
excuse j'ai oublié celui-ci a tester.
C:\WINDOWS\System32\SygateFirewall.exe
C:\WINDOWS\System32\SygateFirewall.exe
Voici le log de lfxss.exe:
File: lfxss.exe Status:
INFECTED/MALWARE MD5 d3319aeebaaf6cdc458842f869073940 Packers detected:
POLYCRYPT, ASPACK
Scanner results AntiVir
Found Worm/RBot.105472.8 ArcaVir
Found nothing Avast
Found Win32:Rbot-AFJ AVG Antivirus
Found IRC/BackDoor.SdBot.JGS BitDefender
Found nothing ClamAV
Found nothing Dr.Web
Found Win32.HLLW.MyBot F-Prot Antivirus
Found W32/Sdbot.LYG Fortinet
Found nothing Kaspersky Anti-Virus
Found Backdoor.Win32.Rbot.gen NOD32
Found Win32/Rbot Norman Virus Control
Found nothing UNA
Found Backdoor.Rbot VBA32
Found nothing
Et voici le deuxième:
File: SygateFirewall.exe_
Status: INFECTED/MALWARE
MD5 afd3e7fde6e9c6d12b1523580f3d239e
Packers detected: MOLEBOX
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Backdoor.Win32.Rbot.gen
NOD32 Found probably a variant of Win32/Rbot (probable variant)
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found Worm.Mytob.2 (probable variant)
File: lfxss.exe Status:
INFECTED/MALWARE MD5 d3319aeebaaf6cdc458842f869073940 Packers detected:
POLYCRYPT, ASPACK
Scanner results AntiVir
Found Worm/RBot.105472.8 ArcaVir
Found nothing Avast
Found Win32:Rbot-AFJ AVG Antivirus
Found IRC/BackDoor.SdBot.JGS BitDefender
Found nothing ClamAV
Found nothing Dr.Web
Found Win32.HLLW.MyBot F-Prot Antivirus
Found W32/Sdbot.LYG Fortinet
Found nothing Kaspersky Anti-Virus
Found Backdoor.Win32.Rbot.gen NOD32
Found Win32/Rbot Norman Virus Control
Found nothing UNA
Found Backdoor.Rbot VBA32
Found nothing
Et voici le deuxième:
File: SygateFirewall.exe_
Status: INFECTED/MALWARE
MD5 afd3e7fde6e9c6d12b1523580f3d239e
Packers detected: MOLEBOX
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Backdoor.Win32.Rbot.gen
NOD32 Found probably a variant of Win32/Rbot (probable variant)
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found Worm.Mytob.2 (probable variant)