Rzehejf.exe c quoi?

Résolu
bonjour à tous.
voila, g un proces qui tente d'acceder au net (rzehejf.exe) et g po trouvé ce que c'est.
quelqu'un pourrait me répondre ?
merci beaucoup :)
Configuration: Windows XP
Firefox 2.0

21 réponses

  1. Salut,

    Euh... Etant donné que ce sont des lettres aléatoires suivies d'un .exe, il n'est pas à douter que ce soit une infection.

    - Télécharge HiJackThis de Merijn http://www.merijn.org/files/HiJackThis_v2.exe sur ton bureau
    - Renomme "HiJackThis.exe" en "scanner.exe"
    - Double cliques dessus et choisis l'option "Do a scan and Save a logfile"
    - Copie Colle le log généré ci-dessous.

    Cordialement,
    0
    1. voila le log merci

      Logfile of Trend Micro HijackThis v2.0.0 (BETA)
      Scan saved at 13:43:58, on 14/09/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
      C:\Program Files\PowerISO\PWRISOVM.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\oodag.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Notepad++\notepad++.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Sir_ilL\Desktop\scanner.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
      O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
      O4 - Startup: Ubisoft register.lnk = C:\Program Files\Ubisoft\Register\schedule.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
      O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
      O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      0
      1. hmm Y'a quelques chose de bizarre. Je suppose qu'Avast! n'a rien dit...

        Tu possèdes Avast!, tu n'es donc pas, pour moi et beaucoup d'autres helpers, protégé au mieux. Je te recommande d'en changer pour Avira Antivir, qui est beaucoup plus performant et réactif. Le petit défaut est qu'il est en anglais, c'est pourquoi voici quelques liens qui t'aideront à en changer sans problème:

        - Tutoriel: http://forum.malekal.com/ftopic4192.php
        - Comparatif de Malekal: http://forum.malekal.com/ftopic3528.php
        - Comparatif de PC INpact: http://www.pcinpact.com/actu/news/31149-Antivirus-resultats-dun-test-de-performances.htm

        Saches que ce petit défaut de langage n'est rien comparé aux grands apports d'Antivir. Si tu décides d'en changer, désinstalle Avast!

        Fais un scan avec Antivir A JOUR et poste le rapport.
        0
        1. Toute la difficulté c de comprendre ce que signifie ce log.
          Je vous serait très reconnaissant de m'éclairer.

          merci...
          0
          1. merci O VertigO. ta disponibilité est impressionante...
            0
            1. ... Je fais de mon mieux pour aider ;o)
              Pour le log, il faut avoir quelques connaissances en informatique, et puis apprendre pas à pas en suivant des tutoriels très intéressant créés par Malekal_Morte (et d'autres) sur son site: www.Malekal.com
              0
              1. J'ai installé antivir. il a trouvé un cheval de troie durant l'updating.
                g ensuite fait un scan en mode sans echec et lorsque g redémaré et me suis connecter au net, rzehejf.exe x'est activé et antivir un lancé un scan tout seul et a planté sur HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run...
                je ne sait pas ce t'en pense......
                0
                1. Peux tu me poster le scan Antivir ?
                  0
                  1. Voici le log d'antivir et je pense que cette fois ci c gané.
                    merci encore de ton aide et il est clair qu'avast décore plus qu'autre chose.

                    AntiVir PersonalEdition Classic
                    Report file date: vendredi 14 septembre 2007 15:46

                    Scanning for 1070809 virus strains and unwanted programs.

                    Licensed to: Avira AntiVir PersonalEdition Classic
                    Serial number: 0000149996-ADJIE-0001
                    Platform: Windows XP
                    Windows version: (Service Pack 2) [5.1.2600]
                    Username: SYSTEM
                    Computer name: POLO-1FF50BBB79

                    Version information:
                    BUILD.DAT : 268 15604 Bytes 31/08/2007 13:04:00
                    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
                    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
                    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
                    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
                    ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 11:32:40
                    ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 10/07/2007 11:32:46
                    ANTIVIR2.VDF : 6.39.1.120 1918464 Bytes 12/09/2007 12:52:02
                    ANTIVIR3.VDF : 6.39.1.132 107520 Bytes 14/09/2007 12:52:02
                    AVEWIN32.DLL : 7.6.0.10 2789888 Bytes 14/09/2007 12:52:02
                    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
                    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
                    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
                    AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 07:46:00
                    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
                    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
                    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
                    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
                    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
                    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
                    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

                    Configuration settings for the scan:
                    Jobname..........................: Complete system scan
                    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                    Logging..........................: low
                    Primary action...................: interactive
                    Secondary action.................: ignore
                    Scan master boot sector..........: off
                    Scan boot sector.................: on
                    Boot sectors.....................: D:,
                    Scan memory......................: on
                    Process scan.....................: on
                    Scan registry....................: on
                    Search for rootkits..............: on
                    Scan all files...................: Intelligent file selection
                    Scan archives....................: on
                    Recursion depth..................: 20
                    Smart extensions.................: on
                    Macro heuristic..................: on
                    File heuristic...................: medium

                    Start of the scan: vendredi 14 septembre 2007 15:46

                    Starting search for hidden objects.
                    An ARK instance is already running.

                    The scan of running processes will be started
                    Scan process 'avscan.exe' - '1' Module(s) have been scanned
                    Scan process 'firefox.exe' - '1' Module(s) have been scanned
                    Scan process 'avscan.exe' - '1' Module(s) have been scanned
                    Scan process 'msimn.exe' - '1' Module(s) have been scanned
                    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                    Scan process 'Watch.exe' - '1' Module(s) have been scanned
                    Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
                    Scan process 'alg.exe' - '1' Module(s) have been scanned
                    Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
                    Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
                    Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
                    Scan process 'Toaster.exe' - '1' Module(s) have been scanned
                    Scan process 'ComComp.exe' - '1' Module(s) have been scanned
                    Scan process 'oodag.exe' - '1' Module(s) have been scanned
                    Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
                    Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
                    Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
                    Scan process 'sched.exe' - '1' Module(s) have been scanned
                    Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
                    Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
                    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                    Scan process 'PWRISOVM.EXE' - '1' Module(s) have been scanned
                    Scan process 'rzehejf.exe' - '1' Module(s) have been scanned
                    Scan process 'AAWTray.exe' - '1' Module(s) have been scanned
                    Scan process 'jusched.exe' - '1' Module(s) have been scanned
                    Scan process 'realsched.exe' - '1' Module(s) have been scanned
                    Scan process 'zlclient.exe' - '0' Module(s) have been scanned
                    Scan process 'soundman.exe' - '1' Module(s) have been scanned
                    Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                    Scan process 'avguard.exe' - '1' Module(s) have been scanned
                    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                    Scan process 'aawservice.exe' - '1' Module(s) have been scanned
                    Scan process 'explorer.exe' - '1' Module(s) have been scanned
                    Scan process 'vsmon.exe' - '0' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'lsass.exe' - '1' Module(s) have been scanned
                    Scan process 'services.exe' - '1' Module(s) have been scanned
                    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                    Scan process 'csrss.exe' - '1' Module(s) have been scanned
                    Scan process 'smss.exe' - '1' Module(s) have been scanned
                    43 processes with 43 modules were scanned

                    Start scanning boot sectors:
                    Boot sector 'C:\'
                    [NOTE] No virus was found!
                    Boot sector 'D:\'
                    [NOTE] No virus was found!

                    Starting to scan the registry.
                    The registry was scanned ( '31' files ).

                    Starting the file scan:

                    Begin scan in 'C:\'
                    C:\pagefile.sys
                    [WARNING] The file could not be opened!
                    C:\System Volume Information\_restore{5BCA8BC1-B693-4DDC-8DA1-4EA63882438F}\RP84\A0023366.exe
                    [DETECTION] Is the Trojan horse TR/Mailskinner.C.1
                    [INFO] The file was moved to '471a9d5c.qua'!
                    Begin scan in 'D:\' <data>

                    End of the scan: vendredi 14 septembre 2007 16:52
                    Used time: 1:05:51 min

                    The scan has been done completely.

                    3765 Scanning directories
                    206829 Files were scanned
                    1 viruses and/or unwanted programs were found
                    0 Files were classified as suspicious:
                    0 files were deleted
                    0 files were repaired
                    1 files were moved to quarantine
                    0 files were renamed
                    1 Files cannot be scanned
                    206828 Files not concerned
                    1121 Archives were scanned
                    1 Warnings
                    1 Notes
                    0
                    1. En plus je viens de lancer encore un scan (on sait jamais :) ) et antivir à trouvé rzehejf.exe et l'a à priori mis en quarantaine.
                      merci encore ...
                      0
                      1. Ouais.. Fais ceci:
                        - Prends connaissance de ce lien: http://www.f-secure.com/products/license-terms/eult_fra.pdf
                        - Télécharge Navilog: http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe sur ton bureau
                        - Si le programme ne démarre pas tout seul, Double cliques sur Navilog1.bat (le .bat peut ne pas apparaître)
                        - Lorsque tu auras la fenetre noire, choisis ta langue.
                        - Appuie sur une touche pour continuer.
                        - Suis ce qui est indiqué jusqu'au choix d'options. Choisis la 1. Ne touche à RIEN pendant le scan.
                        - fixnavi.txt va alors s'ouvrir. Copie colle le EN ENTIER ici.
                        0
                        1. voila le log merci

                          Search Navipromo version 3.0.3 commencé le 14/09/2007 à 18:12:03,37

                          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                          !!! Poster ce rapport sur le forum pour le faire analyser !!!
                          !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                          Fix lancé depuis C:\Program Files\navilog1
                          Mise a jour le 14.09.2007 a 13h00 by IL-MAFIOSO

                          Microsoft Windows XP [Version 5.1.2600]
                          Internet Explorer : 7.0.5730.11

                          *** Recherche Programmes installes ***

                          WebMediaPlayer

                          *** Recherche dossiers dans C:\WINDOWS ***

                          *** Recherche dossiers dans C:\Program Files ***

                          C:\Program Files\WebMediaPlayer trouvé !

                          *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                          *** Recherche dossiers dans C:\Documents and Settings\Sir_ilL\Application Data ***

                          *** Recherche avec BlackLight Engine/F-secure ***
                          BlackLight Engine est un produit de F-secure, pour + d'infos :
                          https://www.f-secure.com/en

                          Fichier(s) caché(s) dans C:\WINDOWS\system32 :

                          c:\WINDOWS\system32\rzehejf.dat
                          C:\windows\system32\rzehejf.exe
                          c:\WINDOWS\system32\rzehejf_nav.dat
                          c:\WINDOWS\system32\rzehejf_navps.dat

                          Processus caché(s) dans C:\WINDOWS\system32 :

                          C:\windows\system32\rzehejf.exe

                          *** Recherche avec GenericNaviSearch ***
                          !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
                          !!! A verifier impérativement avant toute suppression manuelle !!!

                          * Scan C:\WINDOWS\system32 *

                          Fichiers trouvés :

                          rzehejf.exe trouvé !

                          Fichiers suspects :

                          Aucun Fichier suspect trouvé !

                          *** Recherche fichiers ***

                          C:\WINDOWS\pack.epk trouvé !
                          C:\WINDOWS\system32\nvs2.inf trouvé !

                          *** Recherche cles registre ***

                          HKEY_CURRENT_USER\Software\Lanconfig trouvé !
                          HKEY_USERS\S-1-5-21-1292428093-746137067-682003330-1003\Software\Lanconfig trouvé !

                          *** Module de Recherche complémentaire ***
                          (Recherche fichiers spécifiques)

                          1)Recherche fichiers connus:

                          2)Recherche Heuristique :

                          C:\WINDOWS\system32\rzehejf.dat trouvé !

                          3)Recherche Certificats :

                          Certificat Egroup trouvé !

                          *** Analyse Terminé le 14/09/2007 à 18:14:44,00 ***
                          0
                          1. ça n'a po l'air résolu :(
                            je me suis un peu trop embalé
                            0
                            1. O VertigO, g l'impression que t pas mal solicité...
                              On trouve vraiment de tout sur internet:
                              -des gens mal intentionnés qui balancent des virus (g toujours pas compri pourquoi...)
                              -des gens qui apportent sans contre parti une aide précieuse.
                              Franchement merci...
                              0
                              1. Et bien, tu as raison, on trouve de tout sur internet...

                                En fait, ceux qui font les virus sont (à part quelques hackers qui veulent juste embêter les gens) des personnes qui cherchent à se faire de l'argent, soit en faisant apparaitre des pubs (sponsors) soit en volant des informations (comptes bancaire, données personnelles...), soit encore en espionnant les activités de l'utilisateur internet pour transmettre ces informations, moyennant finance, à des sociétés de marketing... donc toujours argent argent argent.

                                Pour en revenir à ton problème, il va être vite réglé. Tu as installé un programme piégé: WebMediaPlayer qui embarque avec lui un adware appelé Magic.Control qui a pour mission de faire de la publicité (tiens tiens...) à ton insu.

                                Donc, relance Navilog cette fois avec l'option 2, laisse toi guider et poste le rapport, accompagné d'un nouveau log HiJackThis.
                                0
                                1. voici le log navilog

                                  Clean Navipromo version 3.0.3 commencé le 14/09/2007 à 19:22:40,50

                                  Fix lancé depuis C:\Program Files\navilog1
                                  Mise a jour le 14.09.2007 a 13h00 by IL-MAFIOSO

                                  Microsoft Windows XP [Version 5.1.2600]
                                  Internet Explorer : 7.0.5730.11

                                  Mode suppression automatique

                                  *** Creation backups fichiers trouvés par Blacklight ***

                                  Copie vers "C:\Program Files\navilog1\Backupnavi"

                                  *** Suppression des fichiers trouvés avec Blacklight ***

                                  c:\WINDOWS\system32\rzehejf.dat supprimé !
                                  C:\windows\system32\rzehejf.exe supprimé !
                                  c:\WINDOWS\system32\rzehejf_nav.dat supprimé !
                                  c:\WINDOWS\system32\rzehejf_navps.dat supprimé !

                                  ** 2ème passage **

                                  C:\WINDOWS\system32\rzehejf.exe absent !
                                  C:\WINDOWS\system32\rzehejf.dat absent !
                                  C:\WINDOWS\system32\rzehejf_nav.dat absent !
                                  C:\WINDOWS\system32\rzehejf_navps.dat absent !
                                  C:\WINDOWS\system32\rzehejf_navup.dat absent !
                                  C:\WINDOWS\system32\rzehejf_navtmp.dat absent !
                                  C:\WINDOWS\system32\rzehejf_m2s.xml absent !

                                  C:\WINDOWS\prefetch\rzehejf*.pf trouvé !
                                  Copie C:\WINDOWS\prefetch\rzehejf*.pf réalise avec succes !
                                  C:\WINDOWS\prefetch\rzehejf*.pf supprimé !

                                  *** Suppression avec Backups résultats GenericNaviSearch ***

                                  * Scan C:\WINDOWS\system32 *

                                  *** Suppression dossiers dans C:\WINDOWS ***

                                  *** Suppression dossiers dans C:\Program Files ***

                                  C:\Program Files\WebMediaPlayer ...suppression...
                                  C:\Program Files\WebMediaPlayer supprimé !

                                  *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

                                  *** Suppression dossiers dans C:\Documents and Settings\Sir_ilL\Application Data ***

                                  *** Suppression fichiers ***

                                  C:\WINDOWS\pack.epk supprimé !
                                  C:\WINDOWS\system32\nvs2.inf supprimé !

                                  *** Suppression fichiers temporaires ***

                                  Nettoyage contenu C:\WINDOWS\Temp effectué !
                                  Nettoyage contenu C:\Documents and Settings\Sir_ilL\Local Settings\Temp effectué !

                                  *** Traitement Recherche complémentaire ***
                                  (Recherche fichiers spécifiques)

                                  1)Recherche fichiers connus:

                                  2)Recherche et Suppression Heuristique :

                                  *** Sauvegarde du registre vers dossier Backupnavi ***

                                  sauvegarde du registre réalise avec succes !

                                  *** Nettoyage registre ***

                                  Nettoyage registre Ok

                                  *** Certificats ***

                                  Certificat Egroup supprimé !

                                  *** Nettoyage termine le 14/09/2007 à 19:29:02,82 ***
                                  0
                                  1. et le log HiJackThis.... merci j'espère que c bon :)

                                    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                                    Scan saved at 19:32:59, on 14/09/2007
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    C:\WINDOWS\System32\FTRTSVC.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\WINDOWS\system32\oodag.exe
                                    C:\WINDOWS\system32\wscntfy.exe
                                    C:\WINDOWS\NOTEPAD.EXE
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\WINDOWS\system32\RUNDLL32.EXE
                                    C:\WINDOWS\SOUNDMAN.EXE
                                    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                                    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                                    C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
                                    C:\Program Files\PowerISO\PWRISOVM.EXE
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                                    C:\PROGRA~1\Wanadoo\ComComp.exe
                                    C:\PROGRA~1\Wanadoo\Toaster.exe
                                    C:\PROGRA~1\Wanadoo\Inactivity.exe
                                    C:\PROGRA~1\Wanadoo\PollingModule.exe
                                    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                    C:\PROGRA~1\Wanadoo\Watch.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\Documents and Settings\Sir_ilL\Desktop\scanner.exe

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                    O1 - Hosts: 62.146.66.181 dl1.avgate.net
                                    O1 - Hosts: 62.146.66.182 dl2.avgate.net
                                    O1 - Hosts: 62.146.66.183 dl3.avgate.net
                                    O1 - Hosts: 62.146.66.184 dl4.avgate.net
                                    O1 - Hosts: 80.190.143.235 dl5.avgate.net
                                    O1 - Hosts: 62.146.66.178 dl7.avgate.net
                                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
                                    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                                    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
                                    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
                                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
                                    O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
                                    O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
                                    O4 - Startup: Ubisoft register.lnk = C:\Program Files\Ubisoft\Register\schedule.exe
                                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                                    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                    O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
                                    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                                    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
                                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    0
                                    1. Ok, reposte un log HiJackThis stp

                                      EDIT: J'ai rien dit, t'ai trop rapide ^^
                                      0
                                      1. C'est bon, tout est clean ! Tu devrais plus avoir de problèmes...

                                        Peux tu faire ceci si tu as le temps:
                                        - Rends toi sur ce site pour rapporter ton infection pour lutter vers un internet plus propre: Malware Complaints: https://malwarecomplaints.info/
                                        Pour savoir comment faire pour rapporter ton infection, regarde ici: http://www.malekal.com/malwarecomplaints.html
                                        Ton infection était: Magic.Control
                                        - Mettre "résolu" à ton sujet.

                                        Bonne soirée,
                                        0
                                        1. encore merci et bonne soirée à toi aussi :)
                                          0
                                          • 1
                                          • 2