Hijack analyse for SWS antispyware 2007 pb - Page 2

Précédent
  • 1
  • 2
  1. Megan Fox Messages postés 410 Statut Membre 9
     
    Bonjour,

    Si tu l'as fait sur tous tes disques dur, clef USB .... c'est ok

    Pour vérifier tu pourrais refaire un scan avec kaspersky.

    Bonne journée
    0
  2. douchka11 Messages postés 14 Statut Membre
     
    Bonjour,

    il a un truc tres bizarre, quand j'ai refais l'analyse avec Kaspersky, il a retrouve le fichier c:/ et d:/ autorun.inf mais moi, meme quand j'active l'option fichiers caches et tout, rien de plus ne s'affiche dans c: ou d: et je ne trouve pas ces fichiers....meme en faisant une recherche.

    et puis je ne comprend pas pourquoi j'ai des trucs dans le compte onvite alors qu'il n'est meme pas active.

    desolee d'etre un boulet, et merci pour votre aide!!

    voici les lignes inquieqnte du 2eme rapport:

    C:\Documents and Settings\Invité\Local Settings\Temporary Internet Files\Content.IE5\8D6JGDEV\xpassgenerator.178[1].exe/stream/data0006 Infecté : Trojan-Downloader.Win32.Zlob.amf ignoré

    C:\Documents and Settings\Invité\Local Settings\Temporary Internet Files\Content.IE5\8D6JGDEV\xpassgenerator.178[1].exe/stream/data0007 Infecté : Trojan-Downloader.Win32.Zlob.bbk ignoré

    C:\Documents and Settings\Invité\Local Settings\Temporary Internet Files\Content.IE5\8D6JGDEV\xpassgenerator.178[1].exe/stream Infecté : Trojan-Downloader.Win32.Zlob.bbk ignoré

    C:\Documents and Settings\Invité\Local Settings\Temporary Internet Files\Content.IE5\8D6JGDEV\xpassgenerator.178[1].exe NSIS: infecté - 3 ignoré

    C:\Documents and Settings\Invité\Local Settings\Temporary Internet Files\Content.IE5\8D6JGDEV\xpassgenerator.178[1].exe
    UPX: infecté - 3 ignoré

    C:\AutoRun.inf Infecté : Trojan.Win32.Agent.abt ignoré

    D:\AutoRun.inf Infecté : Trojan.Win32.Agent.abt ignoré
    0
  3. Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 349
     
    Hello

    Tu peux passer combofix?

    A+
    0
  4. douchka11 Messages postés 14 Statut Membre
     
    Bonsoir,

    je veux bien, mais j'ai aucune idee de ce que ca veut dire....

    merci
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Bonsoir,

    ça veut dire faire ça :

    télécharge combofix (par sUBs)ici :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    et enregistre le sur le bureau.

    2 double-clique sur combofix.exe et suis les instructions

    3 à la fin, il va produire un rapport C:\ComboFix.txt

    4 copie/colle ce rapport dans ta prochaine réponse.

    Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.
    0
  7. douchka11 Messages postés 14 Statut Membre
     
    bonsoir,

    merci pour les explications :) cette fois, les autorun.inf ont l'air d'avoir ete supprimes!

    est ce que je peux faire la meme manip (Combofix) avec un autre ordi ou c'est insense?

    merci beaucoup!

    voici le rapport Combofix:

    ComboFix 07-12-09.1 - Fanny 2007-12-09 20:48:47.1 - [color=red][b]FAT32[/b][/color]x86
    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.237 [GMT 0:00]
    Running from: C:\Documents and Settings\Fanny\Bureau\ComboFix.exe
    * Created a new restore point
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Autorun.inf
    C:\Documents and Settings\Invité\Application Data\HbTools
    C:\WINDOWS\svchost.ini
    C:\WINDOWS\system32\Cache
    C:\WINDOWS\system32\isass.exe
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2007-11-09 to 2007-12-09 ))))))))))))))))))))))))))))))))))))
    .

    2007-12-03 21:15 . 2007-12-03 21:15 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
    2007-11-29 18:01 . 2007-11-29 18:01 <REP> d-------- C:\Program Files\CCleaner
    2007-11-29 17:14 . 2007-11-29 17:14 15,105,147 --a------ C:\upload_moi_PORTABLE-ACER.tar.gz
    2007-11-25 01:03 . 2007-11-25 01:03 <REP> d-------- C:\Program Files\Navilog1
    2007-11-24 18:39 . 2007-11-24 18:39 <REP> d-------- C:\HijackThis
    2007-11-24 18:22 . 2007-11-24 18:22 <REP> d-------- C:\Documents and Settings\Fanny\Application Data\Grisoft
    2007-11-24 18:21 . 2007-11-24 18:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
    2007-11-24 18:21 . 2007-05-30 12:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-11-21 19:28 . 2007-11-21 19:28 <REP> d-------- C:\Program Files\SopCast
    2007-11-20 18:53 . 2005-01-14 09:32 53,248 --a------ C:\WINDOWS\system32\PAStiSvc.exe
    2007-11-20 18:47 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
    2007-11-20 18:45 . 2004-05-04 11:53 1,645,320 --a------ C:\WINDOWS\system32\gdiplus.dll
    2007-11-20 18:44 . 2007-11-20 18:44 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
    2007-11-20 18:44 . 2007-11-20 18:44 <REP> d-------- C:\Program Files\ArcSoft
    2007-11-20 18:44 . 2005-06-21 10:29 245,408 --a------ C:\WINDOWS\system32\unicows.dll
    2007-11-20 18:44 . 1995-08-01 04:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
    2007-11-20 18:43 . 2007-11-20 18:43 <REP> d-------- C:\WINDOWS\PixArt
    2007-11-20 18:43 . 2007-11-20 18:43 <REP> d-------- C:\Program Files\Fichiers communs\PCCamera
    2007-11-20 18:43 . 2007-11-20 18:43 <REP> d-------- C:\Program Files\CamMaestro 3.01 DU PC Camera

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-10-28 15:09 --------- d-----w C:\Program Files\Skype
    2007-10-28 15:09 --------- d-----w C:\Program Files\Fichiers communs\Skype
    2007-10-28 15:09 --------- d-----w C:\Documents and Settings\Fanny\Application Data\Skype
    2007-10-28 11:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
    2007-10-25 16:43 8,516,608 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
    2007-10-08 17:06 131,584 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
    2006-11-27 15:44 82,032 ----a-w C:\Documents and Settings\Fanny\Application Data\GDIPFONTCACHEV1.DAT
    2003-01-21 03:00 13,112,456 ----a-r C:\WINDOWS\system32\config\systemprofile\MpSetup.exe
    2003-01-21 03:00 13,112,456 ----a-r C:\Documents and Settings\Invité\MpSetup.exe
    2003-01-21 03:00 13,112,456 ----a-r C:\Documents and Settings\Invité\MpSetup.exe
    2003-01-21 03:00 13,112,456 ----a-r C:\Documents and Settings\Fanny\MpSetup.exe
    2003-01-21 03:00 13,112,456 ----a-r C:\Documents and Settings\Default User\MpSetup.exe
    2007-08-21 13:51 23 --sha-w C:\WINDOWS\system32\cddeccb1_r.dll
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-21 23:21]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LaunchApp"="Alaunch" []
    "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-20 19:57]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-20 19:57]
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:32]
    "MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-04-24 12:00]
    "PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-04-24 12:00]
    "PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-04-24 12:00]
    "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 21:10]
    "LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2004-07-05 18:52]
    "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2006-04-04 11:55]
    "URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2004-01-27 15:58]
    "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-06-26 12:28]
    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-02 00:38]
    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-02 00:32]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09]
    "ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2007-07-06 10:38]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe
    "NAV CfgWiz"=C:\Program Files\Fichiers communs\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

    R0 NIPALK;NIPALK;C:\WINDOWS\system32\drivers\NIPALK.sys
    R1 SMBHC;Pilote de contrôleur hôte du bus de gestion du système Microsoft;C:\WINDOWS\system32\DRIVERS\SMBHC.sys
    R2 ArtiosLM;Artios License Manager;C:\WINDOWS\System32\artioslm.exe
    R2 niarbk;niarbk;C:\WINDOWS\system32\drivers\niarbk.dll
    R2 nibffrk;nibffrk;C:\WINDOWS\system32\drivers\nibffrk.dll
    R2 Nidaq32k;Nidaq32k;C:\WINDOWS\system32\drivers\Nidaq32k.sys
    R2 nidmmk;NI DMM and Data Logger Kernel Driver;C:\WINDOWS\system32\drivers\nidmmk.dll
    R2 nimdsk;nimdsk;C:\WINDOWS\system32\drivers\nimdsk.dll
    R2 nistck;nistck;C:\WINDOWS\system32\drivers\nistck.dll
    R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
    R3 SMBBATT;Pilote de batterie intelligente Microsoft;C:\WINDOWS\system32\DRIVERS\SMBBATT.sys
    S2 NatMotion;NatMotion;C:\WINDOWS\system32\drivers\NatMotion.sys
    S3 gpibclsb;GPIB Board Class Driver;C:\WINDOWS\system32\Drivers\gpibclsb.sys
    S3 gpibclsd;GPIB Device Class Driver;C:\WINDOWS\system32\Drivers\gpibclsd.sys
    S3 HCW77BDA;Hauppauge Nova-T Stick DVB-T Tuner;C:\WINDOWS\system32\Drivers\hcw70bda.sys
    S3 hcw99rc;Hauppauge Nova-DT IR Driver;C:\WINDOWS\system32\Drivers\hcw99rc.sys
    S3 PAC207;CamMaestro 3.01 DU PC Camera;C:\WINDOWS\system32\DRIVERS\pfc027.sys
    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a39f6f0-f726-11db-99fb-000e3548d58f}]
    \Shell\AutoRun\command - G:\RavMon.exe
    \Shell\explore\Command - G:\RavMon.exe -e
    \Shell\open\Command - G:\RavMon.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2eb04e30-d2f9-11db-99bb-000e3548d58f}]
    \Shell\AutoRun\command - RavMon.exe
    \Shell\explore\Command - RavMon.exe -e
    \Shell\open\Command - RavMon.exe

    *Newly Created Service* - PROCEXP90
    .
    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
    "2007-11-30 20:39:32 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur.job"
    - C:\PROGRA~1\NORTON~1\Navw32.exe
    "2007-04-01 12:54:08 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur - Fanny.job"
    - C:\PROGRA~1\NORTON~1\NAVW32.EXE
    .
    **************************************************************************

    catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-09 20:51:25
    Windows 5.1.2600 Service Pack 2 FAT NTAPI

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-12-09 20:52:06
    .
    --- E O F ---
    0
  8. Megan Fox Messages postés 410 Statut Membre 9
     
    Salut tout le monde,

    Je pense que c'est pas trop mal.

    Télécharge « clean.zip »
    http://www.malekal.com/download/clean.zip
    •- Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier dénommé "clean ".

    •- Redémarre en mode sans échec. ( note bien ce que tu as à faire ).
    •- Ouvre le dossier « clean » qui se trouve sur ton bureau.
    •- Double-clic sur « clean.cmd ».
    Une fenêtre noire va apparaître, choisis l’option 2.

    Clean va travailler.
    •- Redémarre normalement
    •- Poste qui se trouve ici C:\rapport_clean.txt.

    A+
    0
  9. Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 349
     
    est ce que je peux faire la meme manip (Combofix) avec un autre ordi ou c'est insense? 


    LOL Qu'as l'autre PC?
    Vaut mieux être guidé pour éviter d'avoir de mauvaises surprise ;-)

    Salut Vincent et Jimmy au passage ;-)
    0
Précédent
  • 1
  • 2