Tranjan - infécté par clicker.delf.g

Résolu
Peo_o Messages postés 93 Statut Membre -  
duflox Messages postés 2052 Date d'inscription   Statut Membre -
Bonjour, j'ai recuperé un trojan du nom de clicker.delf.g !!! bitdefender l'a trouvé dans fichierscommuns/wizeinstallationwizard.exe
y a t il une manip' pour que je mette un rapport sur le forum??
Je ne suis pas très kalé en informatique!!

En tout cas, il n'à pas l'air très connu comme virus car y a rein sur internet à son sujet...
Configuration: Windows XP
Internet Explorer 7.0

35 réponses

  • 1
  • 2
Résumé de la discussion

Un utilisateur signale la détection par BitDefender d'un Trojan nommé clicker.delf.g dans le fichier fichierscommuns/wizeinstallationwizard.exe et cherche comment signaler l'incident et agir sans connaissances avancées. La meilleure réponse propose d'effectuer un scan en ligne BitDefender et de copier-coller le rapport obtenu afin d'obtenir une évaluation claire et exploitable pour l'assistance. D'autres contributions évoquent l'usage d'outils comme HijackThis pour identifier les éléments résiduels et déterminent s'il faut nettoyer ou supprimer selon les résultats du balayage obtenu. En cas de doute persistant après le balayage, la discussion souligne l'intérêt de documenter les résultats et de vérifier les listes de processus et de services lancés au démarrage.

Bobot (l'IA à votre service)
  1. duflox Messages postés 2052 Date d'inscription   Statut Membre 43
     
    bonjour et bienvenue

    fait un scan ici
    https://www.bitdefender.fr/
    et copie colle le résultat ici
    * En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
    * Dans la nouvelle fenêtre, clique sur I agree
    * La fenêtre change encore, clique sur Click here to scan
    * Les signatures se chargent, etc.

    tuto en image

    http://pageperso.aol.fr/rginformatique/mapage/defender.htm

    copie/colle le rapport sur le forum
    0
  2. helpmee Messages postés 51 Statut Membre
     
    slt ,tu veut metre le raport , je ne sui pas plus calé en informatik que toi mais, j ai lu sur d autre forum q uil faut hijcthis ou evrest qui font un raport sur ton systeme puit copier colé sur le forum.
    0
  3. helpmee Messages postés 51 Statut Membre
     
    slt duflox sait tu lire se genre de raport ?
    0
  4. duflox Messages postés 2052 Date d'inscription   Statut Membre 43
     
    heureusement!!!sinon je ne repondrai pas au topic
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. helpmee Messages postés 51 Statut Membre
     
    peut tu m'aidé a dechifrer le mien stp ,il est pret mais je n arive pas a le metre sur le topic.
    0
    1. duflox Messages postés 2052 Date d'inscription   Statut Membre 43
       
      comment ca tu n arrive pas a le mettre sur le forum?

      tu ouvre un topic et tu copie colle ton rapport dessus!!
      0
  7. Peo_o Messages postés 93 Statut Membre 2
     
    Je lance bitdefender... a tout'
    0
  8. duflox Messages postés 2052 Date d'inscription   Statut Membre 43
     
    ok a tout a l heure!
    0
  9. Peo_o Messages postés 93 Statut Membre 2
     
    Les options par defaut on l'air dangereuses!! il me dit qu'il supprimera le fichier si il n'arrive pas à le nettoyer!!! je fais quoi? je modif les paramètres??
    0
  10. Peo_o Messages postés 93 Statut Membre 2
     
    j'ai mis en deuxieme option "me demander" si en premier lieu il n'arrive pas à le supprimer et je l'ai lancé... mais si il me le demande je fais quoi???
    0
  11. duflox Messages postés 2052 Date d'inscription   Statut Membre 43
     
    il devrai pas te demander!!!

    mais a l origine il fallait mettre nettoyé et en 2eme choix supprimer!!

    si il te demande tu met nettoyé alors
    0
  12. helpmee Messages postés 51 Statut Membre
     
    je viens de m inscrire ojourd'hui sur le forum, je ne sait pas comment faire pr metrre mon raport.
    0
  13. Peo_o Messages postés 93 Statut Membre 2
     
    ERRATUM : je voulais dire : s'il n'arrive pas à nettoyer le fichier il me demandera quoi faire... voila...
    0
  14. Peo_o Messages postés 93 Statut Membre 2
     
    nettoyer ou supprimer???? en SECOND choix???
    0
  15. helpmee Messages postés 51 Statut Membre
     
    arf,je fait copier coler sur mon message du topic sa marche pas
    0
  16. helpmee Messages postés 51 Statut Membre
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:06:33, on 07/08/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\WINDOWS\system32\cisvc.exe
    D:\Comodo\Firewall\cmdagent.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\system32\ezNTSvc.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    D:\Comodo\Firewall\CPF.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O2 - BHO: (no name) - {353073AA-18D0-45EA-AD50-4B59B8E2E857} - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {7428F943-BC4F-4A39-3B43-AB433C523B34} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "D:\Comodo\Firewall\CPF.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Filter hijack: text/html - {C6F62B7A-5450-4A2F-8687-6CEEC3AEB055} - C:\WINDOWS\system32\controlkids2.dll
    O20 - Winlogon Notify: gebyv - C:\WINDOWS\
    O20 - Winlogon Notify: iifdaax - iifdaax.dll (file missing)
    O20 - Winlogon Notify: winrkp32 - winrkp32.dll (file missing)
    O20 - Winlogon Notify: wvuurpn - wvuurpn.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
    O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - D:\Comodo\Firewall\cmdagent.exe
    O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    0
  17. duflox Messages postés 2052 Date d'inscription   Statut Membre 43
     
    supprimer en second choix
    0
  18. helpmee Messages postés 51 Statut Membre
     
    voila mon raport qu en pense tu?
    0
    1. duflox Messages postés 2052 Date d'inscription   Statut Membre 43
       
      il faut absolument que tu ouvres un topic personnel car il y a un peu de boulot sur ton pc!!

      a+
      0
  19. Peo_o Messages postés 93 Statut Membre 2
     
    EXCUSES MOI Duflox, mais je suis un peu stressé par ce virus... mais je me détend!! je sens le calme revenir en moi... lol
    Voila, maintenant je suis dispo pour toutes tes explications...
    0
  20. helpmee Messages postés 51 Statut Membre
     
    peo_o dsl de prendre un peu de place,j essai pas te volé ta place,jespere que tu m en veux pas d avoir posté mon raport.LOL
    0
  21. Peo_o Messages postés 93 Statut Membre 2
     
    Le voila :

    BitDefender Online Scanner

    Rapport d'analyse généré à: Thu, Aug 09, 2007 - 20:45:59

    Voie d'analyse: A:\;C:\;D:\;

    Statistiques

    Temps

    01:29:17

    Fichiers

    292768

    Directoires

    5183

    Secteurs de boot

    2

    Archives

    7222

    Paquets programmes

    44881

    Résultats

    Virus identifiés

    1

    Fichiers infectés

    1

    Fichiers suspects

    0

    Avertissements

    0

    Désinfectés

    0

    Fichiers effacés

    1

    Info sur les moteurs

    Définition virus

    690451

    Version des moteurs

    AVCORE v1.0 (build 2410) (i386) (Jun 12 2007 21:08:27)

    Analyse des plugins

    14

    Archive des plugins

    38

    Unpack des plugins

    6

    E-mail plugins

    6

    Système plugins

    1

    Paramètres d'analyse

    Première action

    Désinfecté

    Seconde Action

    Supprimé

    Heuristique

    Oui

    Acceptez les avertissements

    Oui

    Extensions analysées

    *;

    Excludez les extensions

    Analyse d'emails

    Oui

    Analyse des Archives

    Oui

    Analyser paquets programmes

    Oui

    Analyse des fichiers

    Oui

    Analyse de boot

    Oui

    Fichier analysé

    Statut

    C:\Program Files\Fichiers communs\Wise Installation Wizard\WIS6E710E826D6748899DCF9D07587628C5_4_1.MSI=>(Embedded CAB)=>Register.exe

    Infecté par: Trojan.Clicker.Delf.G

    C:\Program Files\Fichiers communs\Wise Installation Wizard\WIS6E710E826D6748899DCF9D07587628C5_4_1.MSI=>(Embedded CAB)=>Register.exe

    Echec de la désinfection

    C:\Program Files\Fichiers communs\Wise Installation Wizard\WIS6E710E826D6748899DCF9D07587628C5_4_1.MSI=>(Embedded CAB)=>Register.exe

    Supprimé

    C:\Program Files\Fichiers communs\Wise Installation Wizard\WIS6E710E826D6748899DCF9D07587628C5_4_1.MSI=>(Embedded CAB)

    Echec de la mise à jour
    0
  • 1
  • 2