Virus onlinegames.rvx et worm.win32.autorun.c

Jerbie -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour,
Je vous met directement le rapport kaspersky...
Hier, j'avais amvo.exe que j'ai essayé de supprimer à l'aide de Hijack et combofix...Visiblement sans succès puisqu'il vient de se remettre quand j'ai inséré mon lecteur MP3 à l'instant...(pourtant, j'avais suivi les manip pour tout désinfecter...)
Je vous mettrai ensuite le rapport hijack...
Merci pour l'aide...

Kaspersky

KASPERSKY ONLINE SCANNER REPORT
Wednesday, March 12, 2008 7:21:37 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/03/2008
Kaspersky Anti-Virus database records: 624774
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics
Total number of scanned objects 72382
Number of viruses found 10
Number of infected objects 30
Number of suspicious objects 0
Duration of the scan process 01:56:46

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Jérémi\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Jérémi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Jérémi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Jérémi\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jérémi\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Jérémi\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jérémi\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Jérémi\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\fppg1.exe Infected: Trojan-PSW.Win32.OnLineGames.skg skipped
C:\oufddh.exe Infected: Trojan-PSW.Win32.OnLineGames.rvx skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{0BDDFCD6-1706-4E46-B11E-99F3EB9B9672}\RP99\A0021492.exe Infected: Trojan-PSW.Win32.OnLineGames.prv skipped
C:\System Volume Information\_restore{0BDDFCD6-1706-4E46-B11E-99F3EB9B9672}\RP99\change.log Object is locked skipped
C:\ta2.cmd Infected: Trojan-PSW.Win32.OnLineGames.sxq skipped
C:\u2.cmd Infected: Trojan-PSW.Win32.OnLineGames.ryx skipped
C:\v.com Infected: Trojan-PSW.Win32.OnLineGames.too skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\Perflib_Perfdata_544.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\x6.bat Infected: Worm.Win32.AutoRun.cvh skipped
D:\antivirus\avast\DATA\log\nshield.log Object is locked skipped
D:\antivirus\avast\DATA\integ\avast.int Object is locked skipped
D:\antivirus\avast\DATA\aswResp.dat Object is locked skipped
D:\antivirus\avast\DATA\Avast4.db Object is locked skipped
D:\System Volume Information\_restore{0BDDFCD6-1706-4E46-B11E-99F3EB9B9672}\RP99\change.log Object is locked skipped
D:\System Volume Information\_restore{0BDDFCD6-1706-4E46-B11E-99F3EB9B9672}\RP99\A0021493.exe Infected: Trojan-PSW.Win32.OnLineGames.prv skipped
D:\Téléchargement\daemon4121-lite.exe/stream/data0050 Infected: not-a-virus:AdWare.Win32.Shopper.r skipped
D:\Téléchargement\daemon4121-lite.exe/stream Infected: not-a-virus:AdWare.Win32.Shopper.r skipped
D:\Téléchargement\daemon4121-lite.exe NSIS: infected - 2 skipped
D:\oufddh.exe Infected: Trojan-PSW.Win32.OnLineGames.rvx skipped
D:\u2.cmd Infected: Trojan-PSW.Win32.OnLineGames.ryx skipped
D:\fppg1.exe Infected: Trojan-PSW.Win32.OnLineGames.skg skipped
D:\x6.bat Infected: Worm.Win32.AutoRun.cvh skipped
D:\ta2.cmd Infected: Trojan-PSW.Win32.OnLineGames.sxq skipped
D:\v.com Infected: Trojan-PSW.Win32.OnLineGames.too skipped
G:\ta2.cmd Infected: Trojan-PSW.Win32.OnLineGames.sxq skipped
H:\oufddh.exe Infected: Trojan-PSW.Win32.OnLineGames.rvx skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\_restore{0BDDFCD6-1706-4E46-B11E-99F3EB9B9672}\RP99\A0021494.exe Infected: Trojan-PSW.Win32.OnLineGames.prv skipped
H:\System Volume Information\_restore{0BDDFCD6-1706-4E46-B11E-99F3EB9B9672}\RP99\change.log Object is locked skipped
H:\System Volume Information\_restore{23F08A26-38FB-4A7A-96A8-388AD6A8D028}\RP231\A0028787.exe Infected: Trojan-PSW.Win32.OnLineGames.ros skipped
H:\System Volume Information\_restore{23F08A26-38FB-4A7A-96A8-388AD6A8D028}\RP231\A0028788.inf Infected: Trojan-PSW.Win32.OnLineGames.rry skipped
H:\System Volume Information\_restore{23F08A26-38FB-4A7A-96A8-388AD6A8D028}\RP232\A0028856.inf Infected: Trojan-PSW.Win32.OnLineGames.rry skipped
H:\u2.cmd Infected: Trojan-PSW.Win32.OnLineGames.ryx skipped
I:\oufddh.exe Infected: Trojan-PSW.Win32.OnLineGames.rvx skipped
I:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
I:\System Volume Information\_restore{0BDDFCD6-1706-4E46-B11E-99F3EB9B9672}\RP99\A0021495.exe Infected: Trojan-PSW.Win32.OnLineGames.prv skipped
I:\System Volume Information\_restore{0BDDFCD6-1706-4E46-B11E-99F3EB9B9672}\RP99\change.log Object is locked skipped
I:\System Volume Information\_restore{23F08A26-38FB-4A7A-96A8-388AD6A8D028}\RP231\A0028789.exe Infected: Trojan-PSW.Win32.OnLineGames.ros skipped
I:\System Volume Information\_restore{23F08A26-38FB-4A7A-96A8-388AD6A8D028}\RP231\A0028790.inf Infected: Trojan-PSW.Win32.OnLineGames.rry skipped
I:\System Volume Information\_restore{23F08A26-38FB-4A7A-96A8-388AD6A8D028}\RP232\A0028857.inf Infected: Trojan-PSW.Win32.OnLineGames.rry skipped
I:\u2.cmd Infected: Trojan-PSW.Win32.OnLineGames.ryx skipped
Scan process completed.

Hijack

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:49:04, on 12/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\antivirus\avast\aswUpdSv.exe
D:\antivirus\avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
D:\antivirus\a-squared Free\a2service.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
D:\ANTIVI~1\avast\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Applications\imprimante\HP\Digital Imaging\bin\hpohmr08.exe
D:\Applications\imprimante\HP\Digital Imaging\bin\hpotdd01.exe
D:\Applications\imprimante\HP\Digital Imaging\bin\hpoevm08.exe
D:\Applications\imprimante\HP\Digital Imaging\Bin\hpoSTS08.exe
D:\antivirus\avast\ashMaiSv.exe
D:\antivirus\avast\ashWebSv.exe
D:\antivirus\avast\ashSimpl.exe
D:\Applications\Firefox\firefox.exe
D:\Applications\Thunderbird\thunderbird.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Applications\acrobatreader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] D:\ANTIVI~1\avast\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "D:\Applications\quicktime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\APPLIC~1\office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\APPLIC~1\office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - D:\antivirus\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\antivirus\avast\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\antivirus\avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\antivirus\avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\antivirus\avast\ashWebSv.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
A voir également:

25 réponses

Jerbie
 
Euh non : c'est un gars qui se fait passer pour moi qui t'as posé la dernière question...sinon c'est qu'il s'est trompé sur le pseudo...
Si tu confirmes le rapport kaspersky, pour moi tout est OK et je crois que le sujet peut-être clos...
Encore merci pour tout...
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
ok je confirme tu peux mettre résolu
0
Jerbie
 
Hello !
N'étant pas membre, je crois que je ne peux pas clore la discussion...j'ai regardé mais je ne trouve pas...
Si quelqu'un peut le faire pour moi...
Merci jlpjlp
@++
0
hicham13tlm
 
Bonjour,svp j'ai besoin d'1 aide tres vite car j'ai trouver ds mon pc un virus bisard qui s'appelle v.com il desinstale les pilotes de son et de usb et quand je active l'anti virus je perdre l'ecran cad l'ecran devien noir svp aider moi et tres vite svp
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
cré ton propre post merci
0