Analyse HijackThis

louison -  
 Bouclettes34 -
Bonjour a tous, j'y connais pas grand chose dans tout se vocabulaire de la sécurité informatique, mais je suis parvenu à faire une analyse avec HijackThis.
Pourriez vous m'aider à chasser la vilaine petite bete qui m'a gaché ma journée?

Logfile of HijackThis v1.99.1
Scan saved at 17:18:19, on 29/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\inet20099\winlogon.exe
C:\WINDOWS\System32\ati2vid.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\inet20099\socks.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Cacheman\Cacheman.exe
C:\WINDOWS\System32\z11.exe
C:\Program Files\Club-Internet\Lanceur\lanceur.exe
C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = HTTP=proxy.club-internet.fr:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F3 - REG:win.ini: run=C:\WINDOWS\inet20099\winlogon.exe
O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inet20099\3.00.11.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINDOWS\inet20099\socks.exe 20099
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Cacheman] C:\PROGRA~1\Cacheman\Cacheman.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
O4 - HKCU\..\Run: [pro] C:\WINDOWS\System32\z11.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O21 - SSODL: mNRzWY - {10F18BC7-BA5B-216D-6ED6-373E520EC8B5} - C:\WINDOWS\System32\zjf.dll
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Go1iot\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
Configuration: Pentium II, 256mo, XP, connection web à 56k !!!

32 réponses

  • 1
  • 2
  1. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Bonsoir Louison,

    Y a du boulot ! :-)

    Méthode a suivre dans l'ordre...
    ----------------------------------------------------------------------------
    ¤Télécharge ces logiciels:

    1/Spybot S&D 1.4 <<nouvelle version
    http://www.safer-networking.org/fr/index.html

    Démo d utilisation (merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

    Le mettre à jour.

    2/Ad-Aware SE 1.06 <<nouvelle version
    http://www.lavasoftusa.com/software/adaware/
    -Une aide:
    http://www.tutopat.com/viewtopic.php?t=1191
    - installe le patch français, tu pourra le trouver ici:
    http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
    et une petite vidéo ici d'utilisation:(merci a Moe31 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/adawrevid.asf

    Le mettre à jour.

    3/Clean Up 40:
    http://pageperso.aol.fr/balltrap34/CleanUp40.exe
    -aide en image:(merci a Balltrap34)
    http://pageperso.aol.fr/balltrap34/democleanup.htm

    Passes un coup de chacun de ses logiciels

    Puis repost un log Hijackthis.

    Bon courage.

    A+

    0
  2. louison
     
    Un grand merci pour toutes ces infos incognito ;-)
    Je vais tenter de telecharger tout ça avec ma connection 56k ! :-)
    Et je posterai un log Hijackthis
    0
  3. louison
     
    ok! voila ma procedure :
    j'ai installé et fait les mises à jours pour Ad-Aware SE Personal 1.06, Spybot - Search & Destroy 1.4 et CleanUp40...
    Apres avoir désactivé la restauration systeme de windaube, j'ai successivemente executé chacuns de ces programmes en MODE SANS ECHEC.

    Est-ce que ma procedure est bonne? Parce que j'ai tjrs un messsage windows accompagné d'1 croix blanche sur fond rouge dans ma barre de demarrage qui me dit : "your computer is infect"
    Voila mon log HijackThis et un rapport SmitfraudFix

    Logfile of HijackThis v1.99.1
    Scan saved at 23:40:47, on 29/11/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\atievxx.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\inet20099\winlogon.exe
    C:\WINDOWS\System32\ati2vid.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
    C:\WINDOWS\inet20099\socks.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\PROGRA~1\Cacheman\Cacheman.exe
    C:\WINDOWS\System32\z11.exe
    C:\Program Files\Club-Internet\Lanceur\lanceur.exe
    C:\Program Files\Windows NT\Accessoires\WORDPAD.EXE
    C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = HTTP=proxy.club-internet.fr:8080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    F3 - REG:win.ini: run=C:\WINDOWS\inet20099\winlogon.exe
    O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
    O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINDOWS\inet20099\socks.exe 20099
    O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
    O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Cacheman] C:\PROGRA~1\Cacheman\Cacheman.exe
    O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
    O4 - HKCU\..\Run: [pro] C:\WINDOWS\System32\z11.exe
    O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
    O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
    O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
    O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O21 - SSODL: mNRzWY - {10F18BC7-BA5B-216D-6ED6-373E520EC8B5} - C:\WINDOWS\System32\zjf.dll
    O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Go1iot\LOCALS~1\Temp\hpdj.exe (file missing)
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe

    et chez SmitfraudFix

    SmitFraudFix v1.99

    Rapport fait à 23:42:48,81 le 29/11/2005
    Executé à partir de C:\Documents and Settings\Go1iot\Bureau\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

    C:\winstall.exe PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Go1iot\Application Data

    C:\Documents and Settings\Go1iot\Application Data\Install.dat PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

    merci d'avance pour vos reponses
    0
  4. louison
     
    Bonjour, j'ai toujours les memes problemes. Je crois à cause de winstall.exe que je n'arrive pas à virer. Quelqu'un peut-il m'en dire un peu plus?
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Bonsoir Louison,

    Démarre en mode sans échec :
    Pour cela, tu tapotes la touche F8 dès le début de l allumage du pc sans t arrêter
    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
    Une fois sur le bureau si il n y a pas toutes les couleurs et autres c est normal !
    (Si F8 ne marche pas utilise la touche F5)

    Vide tes fichiers temps et tempory internet file:
    utilise ceci pour le faire (tu as télécharger avant)
    http://pageperso.aol.fr/balltrap34/CleanUp40.exe

    Ensuite, tu relances smitfraud et tu choisis l'option 2
    tu sauvegardes le log.

    Tu redemarres en mode normal et tu postes le log ici.

    Bon courage.

    A+

    0
  7. louison
     
    Bonjour,
    Après avoir fait la manip ci dessus, j'ai bien cru que c'était bon. Mais au redémarrage en mode normal l'infection est toujours là !

    Voila mon log Smitfraud EN MODE SANS ECHEC apres avoir utilisé CleanUp :

    SmitFraudFix v1.99

    Rapport fait à 11:44:41,40 le 01/12/2005
    Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

    C:\winstall.exe supprimé
    C:\Documents and Settings\Go1iot\Application Data\Install.dat supprimé

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

    Nettoyage terminé.

    »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

    Et voila mon log Smitfraud EN MODE Normal

    SmitFraudFix v1.99

    Rapport fait à 11:48:05,23 le 01/12/2005
    Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

    C:\winstall.exe PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Go1iot\Application Data

    C:\Documents and Settings\Go1iot\Application Data\Install.dat PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
    0
  8. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Bonsoir Louison,

    Relances un smitfraud en mode normal et fais l'option N°1 uniquement.

    Postes le resultat ici stp.

    Bon courage.

    A+
    0
  9. louison
     
    Bonsoir Incognito, tout d'abord merci pour tes réponses...
    Mais j'ai déjà envoyé un log smitfraud en mode normal... juste au dessus ta réponse. Personne n'est parfait lol ;-)
    Bon, vu que je demarre mon PC en mode selectif grace a msconfig, j'ai viré winstall.exe........ j'espere que ça fonctionnera.... Sinon le pb ne vient pas de install.dat que je retrouve ds le log smitfraud??? J'espere que vous pourrez m'aider

    A+ encore merci
    0
  10. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Bonsoir Louison,

    Je suis un peu perdu, peux tu refaire un log hijackthis stp.

    Bon courage.

    A+

    0
  11. balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
     
    salut
    desinstal tous se qui est du fix smitfraud
    et retelecharge le la version a changer
    salut
    telecharge
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    tu le decompresse tu double clik dessus sur smitfraudfix.cmd et tu choisi l option 1
    cela vas generer un rapport donne nous le
    *******
    redemarre en sans echec

    relance le et choisi cette fois l option 2 et repond oui a tous
    redemarre et donne le nouveau rapport
    *******
    0
  12. louison
     
    bonjour,
    Voila les deux rapport smitfraud

    SmitFraudFix v2.01

    Rapport fait à 12:12:11,52 le 03/12/2005
    Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

    C:\winstall.exe PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

    C:\WINDOWS\system32\ll.exe PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Go1iot\Application Data

    C:\Documents and Settings\Go1iot\Application Data\Install.dat PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

    PUIS EN MODE SANS ECHEC

    SmitFraudFix v2.01

    Rapport fait à 12:18:06,27 le 03/12/2005
    Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

    C:\winstall.exe supprimé
    C:\WINDOWS\system32\ll.exe supprimé
    C:\Documents and Settings\Go1iot\Application Data\Install.dat supprimé

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

    Nettoyage terminé.

    »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

    Mais au redemarrage winstall est tjrs la, voila le 3e rapport sensiblement identique au premier

    SmitFraudFix v2.01

    Rapport fait à 12:27:24,84 le 03/12/2005
    Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

    C:\winstall.exe PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Go1iot\Application Data

    C:\Documents and Settings\Go1iot\Application Data\Install.dat PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
    0
  13. balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
     
    repasse l option 2 en mode normal pour voir
    0
  14. louison
     
    voila le log en mode normal... à priori il y a un souci avec install.dat

    SmitFraudFix v2.01

    Rapport fait à 18:16:54,65 le 03/12/2005
    Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

    C:\winstall.exe supprimé
    Problème suppression C:\Documents and Settings\Go1iot\Application Data\Install.dat

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

    »»»»»»»»»»»»»»»»»»»»»»»» Reboot

    Problème suppression C:\Documents and Settings\Go1iot\Application Data\Install.dat

    »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
    0
  15. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Bonsoir Louison,

    Reposte un log hijackthis stp.

    A+

    0
  16. balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
     
    oui il y a un truc bizzard
    cela est supprimer dans lee premier log et ensuite cela reparait et est insuprimable
    0
  17. louison
     
    Bonjour incognito et Balltrap34
    voila mon dernier log HijackThis

    Logfile of HijackThis v1.99.1
    Scan saved at 16:21:14, on 04/12/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\atievxx.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\inet20099\winlogon.exe
    C:\WINDOWS\System32\ati2vid.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
    C:\WINDOWS\inet20099\socks.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\PROGRA~1\Cacheman\Cacheman.exe
    C:\WINDOWS\System32\z11.exe
    C:\winstall.exe
    C:\Program Files\Club-Internet\Lanceur\lanceur.exe
    C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = HTTP=proxy.club-internet.fr:8080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    F3 - REG:win.ini: run=C:\WINDOWS\inet20099\winlogon.exe
    O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
    O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINDOWS\inet20099\socks.exe 20099
    O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
    O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Cacheman] C:\PROGRA~1\Cacheman\Cacheman.exe
    O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
    O4 - HKCU\..\Run: [pro] C:\WINDOWS\System32\z11.exe
    O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
    O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
    O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
    O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8E5C1E43-BFCC-460A-AEB5-E565231DD5F7}: NameServer = 194.117.200.10 194.117.200.15
    O21 - SSODL: mNRzWY - {10F18BC7-BA5B-216D-6ED6-373E520EC8B5} - C:\WINDOWS\System32\zjf.dll
    O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Go1iot\LOCALS~1\Temp\hpdj.exe (file missing)
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
    0
  18. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Bonsoir Louison,

    Peux tu faire ceci stp
    Rend toi sur ce site :
    http://www.virustotal.com/xhtml/virustotal_en.html
    Clik sur parcourir
    Recherche ceci :
    C:\WINDOWS\inet20099\winlogon.exe

    Clik send et colle le rapport stp

    Idem avec ce fichier :
    C:\WINDOWS\inet20099\socks.exe
    C:\WINDOWS\System32\z11.exe

    ça va nous permettre d'y voir plus clair

    Bon courage.

    A+
    0
  19. louison
     
    This is a report processed by VirusTotal on 12/05/2005 at 17:39:12 (CET) after scanning the file "winlogon.exe" file.

    Antivirus Version Update Result
    AntiVir 6.32.1.63 12.05.2005 TR/Dldr.CWS.11776.4
    Avast 4.6.695.0 12.05.2005 no virus found
    AVG 718 12.05.2005 Downloader.Generic.KLR
    Avira 6.32.1.63 12.05.2005 TR/Dldr.CWS.11776.4
    BitDefender 7.2 12.05.2005 Trojan.Downloader.CWS.BP
    CAT-QuickHeal 8.00 12.05.2005 TrojanDownloader.CWS.gen
    ClamAV devel-20051108 12.05.2005 no virus found
    DrWeb 4.33 12.05.2005 Trojan.DownLoader.5443
    eTrust-Iris 7.1.194.0 12.04.2005 Win32/CWS.11776!Trojan
    eTrust-Vet 11.9.1.0 12.05.2005 Win32.Chopenoz.AL
    Fortinet 2.48.0.0 12.05.2005 W32/CWS.ARQ!dldr
    F-Prot 3.16c 12.05.2005 could be infected with an unknown virus
    Ikarus 0.2.59.0 12.05.2005 Trojan-Downloader.Win32.CWS.gen
    Kaspersky 4.0.2.24 12.05.2005 Trojan-Downloader.Win32.CWS.gen
    McAfee 4643 12.05.2005 Downloader-ARQ
    NOD32v2 1.1311 12.02.2005 a variant of Win32/TrojanDownloader.CWS
    Norman 5.70.10 12.05.2005 W32/Malware
    Panda 8.02.00 12.05.2005 Adware/CWS.Yexe
    Sophos 4.00.0 12.05.2005 Troj/Krepper-S
    Symantec 8.0 12.05.2005 no virus found
    TheHacker 5.9.1.049 12.05.2005 no virus found
    VBA32 3.10.5 12.05.2005 Trojan-Downloader.Win32.CWS.gen

    This is a report processed by VirusTotal on 12/05/2005 at 17:43:35 (CET) after scanning the file "socks.exe" file.

    Antivirus Version Update Result
    AntiVir 6.32.1.63 12.05.2005 TR/Proxy.Small.CF.1
    Avast 4.6.695.0 12.05.2005 no virus found
    AVG 718 12.05.2005 BackDoor.Generic.USG
    Avira 6.32.1.63 12.05.2005 TR/Proxy.Small.CF.1
    BitDefender 7.2 12.05.2005 BehavesLike:Win32.Backdoor
    CAT-QuickHeal 8.00 12.05.2005 TrojanProxy.Small.cf
    ClamAV devel-20051108 12.05.2005 no virus found
    DrWeb 4.33 12.05.2005 Trojan.Proxy.556
    eTrust-Iris 7.1.194.0 12.04.2005 Win32/Traff.34304!Trojan
    eTrust-Vet 11.9.1.0 12.05.2005 Win32.Choprox.D
    Fortinet 2.48.0.0 12.05.2005 W32/Small.CF-tr
    F-Prot 3.16c 12.05.2005 no virus found
    Ikarus 0.2.59.0 12.05.2005 no virus found
    Kaspersky 4.0.2.24 12.05.2005 Trojan-Proxy.Win32.Small.cf
    McAfee 4643 12.05.2005 no virus found
    NOD32v2 1.1311 12.02.2005 probably unknown NewHeur_PE virus
    Norman 5.70.10 12.05.2005 W32/Malware
    Panda 8.02.00 12.05.2005 Trj/Moli.L
    Sophos 4.00.0 12.05.2005 no virus found
    Symantec 8.0 12.05.2005 no virus found
    TheHacker 5.9.1.049 12.05.2005 no virus found
    VBA32 3.10.5 12.05.2005 Trojan.Proxy.556

    This is a report processed by VirusTotal on 12/05/2005 at 17:46:32 (CET) after scanning the file "z11.exe" file.

    Antivirus Version Update Result
    AntiVir 6.32.1.63 12.05.2005 Joke/Renos.W
    Avast 4.6.695.0 12.05.2005 Win32:Hoaxalarm-K
    AVG 718 12.05.2005 Adware Generic.IDO
    Avira 6.32.1.63 12.05.2005 Joke/Renos.W
    BitDefender 7.2 12.05.2005 Trojan.FakeAlert.G
    CAT-QuickHeal 8.00 12.05.2005 Hoax.Renos.ac (Not a Virus)
    ClamAV devel-20051108 12.05.2005 no virus found
    DrWeb 4.33 12.05.2005 Trojan.Fakealert
    eTrust-Iris 7.1.194.0 12.04.2005 Win32/Oneraw.S!Trojan
    eTrust-Vet 11.9.1.0 12.05.2005 Win32.Oneraw.S
    Fortinet 2.48.0.0 12.05.2005 W32/Dloader
    F-Prot 3.16c 12.05.2005 could be infected with an unknown virus
    Ikarus 0.2.59.0 12.05.2005 no virus found
    Kaspersky 4.0.2.24 12.05.2005 not-virus:Hoax.Win32.Renos.ac
    McAfee 4643 12.05.2005 Downloader-AFH
    NOD32v2 1.1311 12.02.2005 a variant of Win32/Adware.SpySheriff
    Norman 5.70.10 12.05.2005 no virus found
    Panda 8.02.00 12.05.2005 Adware/SpySheriff
    Sophos 4.00.0 12.05.2005 no virus found
    Symantec 8.0 12.05.2005 no virus found
    TheHacker 5.9.1.049 12.05.2005 no virus found
    VBA32 3.10.5 12.05.2005 Trojan.Fakealert

    NB: J'ai aussi z12.exe z13.exe z14.exe z15.exe z16.exe
    This is a report processed by VirusTotal on 12/05/2005 at 17:49:28 (CET) after scanning the file "z12.exe" file.

    Antivirus Version Update Result
    AntiVir 6.32.1.63 12.05.2005 TR/Dldr.Small.awa.70
    Avast 4.6.695.0 12.05.2005 no virus found
    AVG 718 12.05.2005 Downloader.Generic.KPC
    Avira 6.32.1.63 12.05.2005 TR/Dldr.Small.awa.70
    BitDefender 7.2 12.05.2005 Trojan.Downloader.Small.AWA
    CAT-QuickHeal 8.00 12.05.2005 TrojanDownloader.Small.awa
    ClamAV devel-20051108 12.05.2005 Trojan.Downloader.Small-811
    DrWeb 4.33 12.05.2005 Trojan.DownLoader.5653
    eTrust-Iris 7.1.194.0 12.04.2005 no virus found
    eTrust-Vet 11.9.1.0 12.05.2005 no virus found
    Fortinet 2.48.0.0 12.05.2005 W32/Vixup.AWA!dldr
    F-Prot 3.16c 12.05.2005 no virus found
    Ikarus 0.2.59.0 12.05.2005 no virus found
    Kaspersky 4.0.2.24 12.05.2005 Trojan-Downloader.Win32.Small.awa
    McAfee 4643 12.05.2005 no virus found
    NOD32v2 1.1311 12.02.2005 a variant of Win32/TrojanDownloader.Small.AWA
    Norman 5.70.10 12.05.2005 no virus found
    Panda 8.02.00 12.05.2005 Adware/CWS.Yexe
    Sophos 4.00.0 12.05.2005 Troj/Vixup-Gen
    Symantec 8.0 12.05.2005 no virus found
    TheHacker 5.9.1.049 12.05.2005 Trojan/Downloader.Small.awa
    VBA32 3.10.5 12.05.2005 MalwareScope.Downloader.Small.1
    0
  20. jean38 Messages postés 2534 Date d'inscription   Statut Contributeur Dernière intervention   47
     
    salut,

    fait la manip de balltrap avec smitfraud tu vas gagner du temps.

    Jean
    0
  • 1
  • 2