Renseignements sur win32-horst:IJ

bonjour

je vous ecrit pour savoir si l'un d'entre vous a quelques renseignements sur un trojan virulant, le dénommé "win32-horst :IJ " je m'en suis débarrassé hier en eradiquant dans les clés de registre s'es interventions, grace à un programe facilement trouvable, mais je voudrai en savoir un peu plus sur ce trojan. en effet, je me suis rendu en faisant des tours sur les differents forums que celui etait récent, et que les symptomes sont toujours les mêmes ( apparition malgré éradication, localisation dans les fichiers temp, creation d'application inconnues ). si l'un d'entre vous à donc quelques renseignements, j'aimerais m'endormir moins bête ce soir :-).

merci à vous tous

5 réponses

  1. Salut Vincent,
    J'ai moi meme etait infecté par se cheval de troie.
    J'ai eu beaucoup de mal a l'eradiquer....je pense que c'est bon pour le moment...
    Quel programme as-tu utilié ????
    Application smss.exe dans le répertoire systeme que j'ai supprimé..
    Si tu as d'autres info cela m'interesse.....
    Bon courage....
    0
    1. salut

      bon alrs visiblement toi aussi tu as subi ce trojan, que tu supprimes et qui revient, je suppose, dans les fichiers temp du local setting...

      donc pour info, je te file le lien où tout etstexpliqué :

      http://www.infos-du-net.com/forum/271688-11-resolu-infecte-win32-horst

      pour faire bref, et pour pas flipper en voyant la longueur du post, sache qu'il te suffit donc de telecharcher "SDFIX", qui va scruter tes clés de registre.

      en tout l operation dure un quart d heure, par contre suis bien les instructions (redemarrer mode sans echec etc)

      perso comme antivirus j ai avast pro, qui supprimait à chaque fois, mais comme c ets un trojan qui se dupplique, il ne pouvait faire grand chose.

      tchao tchao.

      par contre, si t as des infos, n hesite pas.
      0
      1. Salut,
        Merci pour le lien, mais j'ai VISTA prenium et je ne sais pas si SDFIX est compatible ???
        J'ai fix les lignes conseil par l'analyse de mon log Hijack This en ligne...
        Puis supprimez Smss.exe qui se trouve dans c:\user\<nom du repertoire perso>\AppData\Roaming...
        Ad-aware, Ccleaner et plus rein maintenant...Je pense que c'est bon.
        0
        1. Je viens de refaire un full scan Ad-aware 2007 et il me trouve de merde....

          Scan mode: Full
          Scan time: 00:14:34
          Number of objects scanned: 174950
          Number of infections found: 2
          Critical: 0
          Privacy Objects: 2
          Infections deleted: 0
          Total infections quarantined: 0
          Total infections ignored by scanner: 0

          peut-on me dire si cela est en rapport avec win32:horst-IJ ??????

          Merci a tous.....
          0
          1. Voici un nouveau rapport Hijack This qui me semble normale..!!!!!!

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 15:17:48, on 24/08/2007
            Platform: Windows Vista (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16512)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
            C:\Windows\vVX1000.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\MSN Messenger\msnmsgr.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Logitech\SetPoint\SetPoint.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Program Files\Internet Explorer\ieuser.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Windows Mail\WinMail.exe
            C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe
            C:\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
            O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
            O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
            O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - Global Startup: Logitech SetPoint.lnk = ?
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O13 - Gopher Prefix:
            O17 - HKLM\System\CCS\Services\Tcpip\..\{7E136B03-6DF8-49F3-BCFE-7D3930E32920}: NameServer = 212.216.172.62,213.36.80.1
            O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Ad-Aware 2007\aawservice.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: StarWind iSCSI Service (StarWindService) - Unknown owner - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (file missing)
            0