Infecté par backdoor rbot avq

macajax Messages postés 30 Date d'inscription   Statut Membre -  
^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour je suis nouveau
J'ai demandé un peu d'aide pour un virus ou trojan précédent message
backdoor rbot avq
je réinstalle une 3° fois windows xp...
En espèrant qu'une bonne âme lira ceci
merci

Pour info j'ai attrapé ce truc alors que j'avais avast en antivirus
ainsi que spybot et adaware contre les spyware
je vais télécharger hijackthis pour envoyer événtuellement
un rapport
merci
Configuration: Windows XP
Firefox 1.0.4

4 réponses

  1. Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 349
     
    Salut

    Tu as le rapport?

    A+
    0
  2. macajax Messages postés 30 Date d'inscription   Statut Membre
     
    Merci voici mon rapport

    Logfile of HijackThis v1.99.1
    Scan saved at 17:48:45, on 03/06/2007
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Fichiers communs\Talkway\vmtalk.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Club-Internet\Lanceur\lanceur.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://GLOBAL.ACER.COM/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.bing.com/search?form=MO0035&q=open+dbd+file
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = HTTP=proxy.club-internet.fr:8080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [vmtalk] C:\Program Files\Fichiers communs\Talkway\vmtalk.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
    O8 - Extra context menu item: Easy-WebPrint Ajouter à la Liste à Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
    O17 - HKLM\System\CCS\Services\Tcpip\..\{69F7A09E-8BEC-40B3-808C-F792BD2AD4F2}: NameServer = 194.117.200.10 194.117.200.15
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: dllmgr64 - Unknown owner - C:\WINDOWS\dllmgr64.exe (file missing)
    0
  3. Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 349
     
    DOUBLE POSTE

    Ne crée qu un seul sujet stp

    a+
    0
    1. macajax Messages postés 30 Date d'inscription   Statut Membre
       
      ok
      nouveau sur le forum désolé
      voici réslutat scan de l'antivirus antivir:


      AntiVir PersonalEdition Classic
      Report file date: samedi 2 juin 2007 21:27

      Scanning for 740715 virus strains and unwanted programs.

      Licensed to: Avira AntiVir PersonalEdition Classic
      Serial number: 0000149996-ADJIE-0001
      Platform: Windows XP
      Windows version: (Service Pack 1) [5.1.2600]
      Username: fred
      Computer name: OEM-E4WIYNFC2CU

      Version information:
      BUILD.DAT : 247 14437 Bytes 10/05/2007 11:55:00
      AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:16
      AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:56
      LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:06
      LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:19:00
      ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
      ANTIVIR1.VDF : 6.37.1.151 4303360 Bytes 23/02/2007 13:09:02
      ANTIVIR2.VDF : 6.38.0.214 729600 Bytes 12/04/2007 13:09:02
      ANTIVIR3.VDF : 6.38.0.225 50688 Bytes 16/04/2007 13:09:02
      AVEWIN32.DLL : 7.4.0.12 2404864 Bytes 13/04/2007 13:04:24
      AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:28
      AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:52
      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
      AVPACK32.DLL : 7.3.0.8 360488 Bytes 27/03/2007 07:48:30
      AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:10
      AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:06
      AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:28
      NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:44
      RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:20
      RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:44

      Configuration settings for the scan:
      Jobname..........................: Local Drives
      Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp
      Logging..........................: low
      Primary action...................: interactive
      Secondary action.................: ignore
      Scan master boot sector..........: off
      Scan boot sector.................: on
      Boot sectors.....................: E:,
      Scan memory......................: on
      Process scan.....................: on
      Scan registry....................: on
      Search for rootkits..............: off
      Scan all files...................: All files
      Scan archives....................: on
      Recursion depth..................: 20
      Smart extensions.................: on
      Macro heuristic..................: on
      File heuristic...................: medium

      Start of the scan: samedi 2 juin 2007 21:27

      The scan of running processes will be started
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'ALG.EXE' - '1' Module(s) have been scanned
      Scan process 'LANCEUR.EXE' - '1' Module(s) have been scanned
      Scan process 'CTFMON.EXE' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'VMTALK.EXE' - '1' Module(s) have been scanned
      Scan process 'AGRSMMSG.EXE' - '1' Module(s) have been scanned
      Scan process 'PicasaMediaDetector.exe' - '1' Module(s) have been scanned
      Scan process 'QTTASK.EXE' - '1' Module(s) have been scanned
      Scan process 'JUSCHED.EXE' - '1' Module(s) have been scanned
      Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'EXPLORER.EXE' - '1' Module(s) have been scanned
      Scan process 'SPOOLSV.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
      Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
      Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
      Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
      Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
      26 processes with 26 modules were scanned

      Start scanning boot sectors:
      Boot sector 'C:\'
      [NOTE] No virus was found!
      Boot sector 'D:\'
      [NOTE] No virus was found!
      Boot sector 'F:\'
      [NOTE] In the drive 'F:\' no data medium is inserted!
      Boot sector 'G:\'
      [NOTE] In the drive 'G:\' no data medium is inserted!
      Boot sector 'H:\'
      [NOTE] In the drive 'H:\' no data medium is inserted!
      Boot sector 'I:\'
      [NOTE] In the drive 'I:\' no data medium is inserted!

      Starting to scan the registry.
      The registry was scanned ( '15' files ).


      Starting the file scan:

      Begin scan in 'C:\'
      C:\PAGEFILE.SYS
      [WARNING] The file could not be opened!
      C:\hiberfil.sys
      [WARNING] The file could not be opened!
      C:\mstskmgr.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Ranky.DE.20
      [INFO] The file was moved to '46d5c527.qua'!
      C:\WINDOWS\dllmgr64.exe
      [DETECTION] Contains signature of the worm WORM/SdBot.XD.145
      [INFO] The file was moved to '46cdc6cf.qua'!
      C:\WINDOWS\system32\mstskmgr.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Ranky.DE.20
      [INFO] The file was moved to '46d5c6f1.qua'!
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IP63SH09\mstskmgr[1].exe
      [DETECTION] Is the Trojan horse TR/Proxy.Ranky.DE.20
      [INFO] The file was moved to '46d5c776.qua'!
      C:\System Volume Information\_restore{003FAB1D-F51F-4A1E-9860-81FA76A5A51F}\RP10\A0002998.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Ranky.DE.20
      [INFO] The file was moved to '4691c7aa.qua'!
      C:\System Volume Information\_restore{003FAB1D-F51F-4A1E-9860-81FA76A5A51F}\RP10\A0002999.exe
      [DETECTION] Contains signature of the worm WORM/SdBot.XD.145
      [INFO] The file was moved to '4691c7b2.qua'!
      C:\System Volume Information\_restore{003FAB1D-F51F-4A1E-9860-81FA76A5A51F}\RP10\A0003000.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Ranky.DE.20
      [INFO] The file was moved to '4691c7b5.qua'!
      Begin scan in 'D:\'
      Begin scan in 'F:\'
      Search path F:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'G:\'
      Search path G:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'H:\'
      Search path H:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'I:\'
      Search path I:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'E:\' <antivirus fred>


      End of the scan: samedi 2 juin 2007 21:40
      Used time: 12:22 min

      The scan has been done completely.

      1824 Scanning directories
      95817 Files were scanned
      7 viruses and/or unwanted programs were found
      0 classified as suspicious:
      0 files were deleted
      0 files were repaired
      7 files were moved to quarantine
      0 files were renamed
      2 Files cannot be scanned
      95810 Files not concerned
      5947 Archives were scanned
      2 Warnings
      0 Notes
      0 Hidden objects were found

      ---------------------------------------
      et voici celui de spybot:

      Blue streack
      Double click
      Web Trens live
      Microsoft windows sécurity Center_disable
      Microsoft windows sécurity Center Antivrus disable Notify
      Microsoft windows sécurity Center Antivrus Override
      Microsoft windows sécurity Center Firwall Disabled
      Microsoft windows sécurity Center Firewall Override
      Microsoft windows sécurity CenterSP2 Update
      Microsoft windows sécurity Center Update Disable Notify
      ---------------------------------------
      Pour info antivir viens de me bloqué un"Worm/Sbot.xd.101
      mon PC n'arrête pas de planter
      suite Generic Horst process
      merci et a+
      0
  4. Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 349
     
    Tu as fait ce que je demandais sur l autre poste?

    A+
    0
    1. macajax Messages postés 30 Date d'inscription   Statut Membre
       
      oui j'ai joint les deux rapport que tu avais demandé.
      merci
      0