[virus] raport hijack suite infection

Résolu
bonjours a tous, suite a plusieur troyens reperés par mon antivirus (avk 2007) je poste un log hijack à analyser car je n'y comprend pas grand chose. Merci a tous et bon week end de paques.
Configuration: Windows XP
Internet Explorer 7.0

7 réponses

  1. Contributeur
    Re,

    Ok.Poste le log Hijackthis.
    0
    1. Logfile of Trend Micro HijackThis v2.0.0 (BETA)
      Scan saved at 22:57:05, on 08/04/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\G DATA InternetSecurity\AVK\AVKService.exe
      C:\Program Files\G DATA InternetSecurity\AVK\AVKWCtl.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\G DATA\AVKProxy\AVKProxy.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\G DATA InternetSecurity\Firewall\GDFwSvc.exe
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
      C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
      C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe
      C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
      C:\Program Files\G DATA InternetSecurity\AVKTray\AVKTray.exe
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
      C:\Program Files\G DATA InternetSecurity\Firewall\GDFirewallTray.exe
      C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      C:\Program Files\HPQ\shared\hpqwmi.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
      C:\Documents and Settings\Massaccesi Rudy\Mes documents\HiJackThis_v2.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=laptop
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: G DATA WebFilter Class - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G DATA InternetSecurity\Webfilter\AvkWebIE.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O3 - Toolbar: G DATA WebFilter - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G DATA InternetSecurity\Webfilter\AvkWebIE.dll
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
      O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
      O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
      O4 - HKLM\..\Run: [AVKTray] "C:\Program Files\G DATA InternetSecurity\AVKTray\AVKTray.exe"
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
      O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
      O4 - Global Startup: G DATA Firewall Tray.lnk = ?
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://rudyrital.spaces.live.com//PhotoUpload/MsnPUpld.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://www.zebulon.fr/scan8/oscan8.cab
      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
      O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: AVKProxy - G DATA Software AG - C:\Program Files\Fichiers communs\G DATA\AVKProxy\AVKProxy.exe
      O23 - Service: AVK Service (AVKService) - G DATA Software AG - C:\Program Files\G DATA InternetSecurity\AVK\AVKService.exe
      O23 - Service: Gardien d'AVK (AVKWCtl) - Unknown owner - C:\Program Files\G DATA InternetSecurity\AVK\AVKWCtl.exe
      O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
      O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
      O23 - Service: G DATA Personal Firewall (GDFwSvc) - Unknown owner - C:\Program Files\G DATA InternetSecurity\Firewall\GDFwSvc.exe
      O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
      O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
      O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
      O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
      O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
      O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
      O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
      0
  2. Contributeur
    Re,

    Vas sur le site : http://www.virustotal.com/en/indexf.html
    Puis a coter de "select file" met ce fichier :

    C:\WINDOWS\system32\browseui.dll

    et clique sur "send".
    Ensuite attend quelques minutes, un rapport va être généré tu le copie-colleras lors de ton prochain post.
    0
    1. Merci pour ton interet a mon probleme, voici le log de virustotal :

      Complete scanning result of "browseui.dll_", received in VirusTotal at 04.08.2007, 23:22:22 (CET).

      Antivirus Version Update Result
      AhnLab-V3 2007.4.7.0 04.06.2007 no virus found
      AntiVir 7.3.1.48 04.08.2007 no virus found
      Authentium 4.93.8 04.08.2007 no virus found
      Avast 4.7.936.0 04.08.2007 no virus found
      AVG 7.5.0.447 04.08.2007 no virus found
      BitDefender 7.2 04.08.2007 no virus found
      CAT-QuickHeal 9.00 04.06.2007 no virus found
      ClamAV devel-20070312 04.08.2007 no virus found
      DrWeb 4.33 04.08.2007 no virus found
      eSafe 7.0.15.0 04.08.2007 no virus found
      eTrust-Vet 30.7.3549 04.06.2007 no virus found
      Ewido 4.0 04.08.2007 no virus found
      FileAdvisor 1 04.08.2007 No threat detected
      Fortinet 2.85.0.0 04.08.2007 no virus found
      F-Prot 4.3.1.45 04.08.2007 no virus found
      F-Secure 6.70.13030.0 04.08.2007 no virus found
      Ikarus T3.1.1.3 04.08.2007 no virus found
      Kaspersky 4.0.2.24 04.08.2007 no virus found
      McAfee 5003 04.06.2007 no virus found
      Microsoft 1.2405 04.08.2007 no virus found
      NOD32v2 2173 04.07.2007 no virus found
      Norman 5.80.02 04.05.2007 no virus found
      Panda 9.0.0.4 04.08.2007 no virus found
      Prevx1 V2 04.08.2007 no virus found
      Sophos 4.16.0 04.06.2007 no virus found
      Sunbelt 2.2.907.0 04.07.2007 no virus found
      Symantec 10 04.08.2007 no virus found
      TheHacker 6.1.6.085 04.04.2007 no virus found
      VBA32 3.11.3 04.08.2007 no virus found
      VirusBuster 4.3.7:9 04.08.2007 no virus found
      Webwasher-Gateway 6.0.1 04.08.2007 no virus found

      Aditional Information
      File size: 1022976 bytes
      MD5: 38948cf4f25d717f60a5fb35228ba637
      SHA1: c0db235d0f1f4521929617f14eb6d96099ad9c00
      Bit9 info: http://fileadvisor.bit9.com/services/extinfo.aspx?md5=38948cf4f25d717f60a5fb35228ba637
      0
      1. Contributeur
        Re,

        Ben ton log est propre,

        Prends connaissance du contenu le lien suivant:

        http://www.f-secure.com/products/license-terms/eult_fra.pdf

        Tu as donc pris connaissance et accepté les conditions d'utilisations du programme blacklight qui est inclus dans le dossier compressé navilog1.zip que tu vas télécharger.

        Maintenant fais un clic droit sur ce lien :

        http://perso.orange.fr/il.mafioso/Navifix/navilog1.zip

        Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.

        Fais un clic droit sur navilog1.zip et choisis "tout extraire"

        Ensuite double clique sur navilog1.bat

        Laisses-toi guider.

        Au menu principal, choisis 1 et valides.

        (Ne fais pas le choix 2 sans notre avis/accord)

        Patientes jusqu'au message :

        *** Analyse Termine le ..... ***

        Appuies sur une touche comme demandé, le bloc note va s'ouvrir.

        Copies-colles l'intégralité dans une réponse.

        Refermes le bloc note.

        Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
        0
        1. re, voici le resultat:

          Search Navipromo version 1.1.3 commencé le 08/04/2007 à 23:39:32,95

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Poster ce rapport sur le forum pour le faire analyser !!!
          !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

          Fix lancé depuis C:\Documents and Settings\Massaccesi Rudy\Bureau
          Mise a jour le 31.03.2007 a 08h00 by IL-MAFIOSO

          Executé en mode normal

          *** Recherche Programmes installes ***

          *** Recherche dossiers dans C:\WINDOWS ***

          *** Recherche dossiers dans C:\Program Files ***

          *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

          *** Recherche dossiers dans C:\Documents and Settings\Massaccesi Rudy\Application Data ***

          *** Recherche avec BlackLight Engine/F-secure ***
          BlackLight Engine est un produit de F-secure, pour + d'infos :
          https://www.f-secure.com/en

          F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
          ======================================

          Copyright 2005-2006 F-Secure Corporation. All rights reserved.
          This is a beta version. It will expire on 1st of April, 2007.
          Version information: 2.2.1061.

          [+] Started on 04/08/07 at 23:39:34.
          [+] Initializing ...
          [+] Starting scan, press Ctrl-C to abort.
          [+] Scanning for hidden items .....................................................................................
          [+] Scan complete.
          [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
          [+] Exited on 04/08/07 at 23:48:20 (return code = 0).

          *** Recherche fichiers ***

          *** Recherche cles registre ***

          Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

          Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

          Recherche Clé Magic Control

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche fichiers connus:

          2)Recherche Heuristique :
          *
          **
          ***
          ****
          *****
          ******
          *******
          ********

          *** Analyse Terminé le 08/04/2007 à 23:49:24,93 ***
          0
      2. Contributeur
        Re,

        Donc télécharge clean : http://www.malekal.com/download/clean.zip

        Installe-le sur le bureau et dezippe-le.
        Un dossier clean va être créer double-clique dessus
        Puis double clique sur clean.cmd et choisit l'option 1.Patiente un peu.
        Poste ce rapport dans ton prochain post
        0
        1. re, j'ai recu une alerte de mon antivirus a la fin du telechargement depuis le lien que tu as posté , voici l'alerte :

          Gardien
          Analysé : 10361 (1 infecté)
          Dernière infection: C:\Documents and Settings\Massaccesi Rudy\Local Settings\Temporary Internet Files\Content.IE5\A0ERCTB2\clean[1].zip
          Infecté par: not-a-virus:RiskTool.Win32.PsKill.k

          que dois-je faire ? je l'autorise ou pas ?
          0
      3. Contributeur
        Re,

        Tu 'nas pas a t'inquieter ce n'est pas un virus.
        0
        1. ok, voici le resultat :

          Rapport clean par Malekal_morte - http://www.malekal.com
          Option 1, executee le 09/04/2007 a 0:15:16,29

          *** Recherche de fichiers sur C:

          *** Recherche des fichiers dans C:\WINDOWS\

          *** Recherche des fichiers dans C:\WINDOWS\system32

          *** Fin du rapport !
          0
      4. Contributeur
        Re,

        Aurait-tu le chemin de ton virus ?
        0