Smitfraud + hijackthis

Bonjour,

Je pense avoir une infection, certains programmes ne fonctionnent plus, fenêtres intempestives que je ne sais pas désactiver.

j'ai fait un spyboot, adware, un smifraudfix en mode sans échec et un log hijacthis, j'ai cherché sur internet pour avoir une vérification automatique du log mais j'ai quelques doutes, pourriez-vous m'aider ?

O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" –start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe –startup
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickSet.lnk = ?

reste-t-il un virus planqué ?

Merci beaucoup
Configuration: Windows Vista
Firefox 2.0.0.12

7 réponses

  1. pour les fenetres intempestives telecharge navilog c est genial pour les bebettes
    1. Bonjour et merci pour l'aide,

      Pour les lignes NvSvc; NvCplDaemon et NvHotkey.... j'ai trouvé merci, il s'agit de modules de cartes graphiques et autres.

      Il semblerait donc qu'il n'y ait pas de virus pourtant j'ai constamment des fenêtres sur mon outlook qui indique qu'un programme tente d'entrer dans ma liste de contact et qui bloque tout, impossible même de fermer le logiciel sans éteindre l'ordi.... il y a donc quelque chose qui ne tourne pas rond mais quoi ???

      Qu'en pensez-vous, dois-je faire tourner combofix ou télécharger vundofix ou vitumundo ? Encore merci pour votre aide.

      Voici le rapport du fix

      Fix run in safe mode

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\Windows\system32\csrss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\Explorer.EXE
      C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\Program Files\McAfee\MSC\mcuimgr.exe
      C:\Program Files\Glary Utilities\Integrator.exe
      C:\Windows\system32\cmd.exe
      C:\Windows\system32\cmd.exe
      C:\Windows\system32\cmd.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\egide patrimoine

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\egide patrimoine\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\EGIDEP~1\FAVORI~1

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, following keys are not inevitably infected!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, following keys are not inevitably infected!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

      »»»»»»»»»»»»»»»»»»»»»»»» Rustock

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{49F8BA0C-8066-48ED-A941-92878F2710D9}: DhcpNameServer=212.27.53.252 212.27.54.252
      HKLM\SYSTEM\CCS\Services\Tcpip\..\{87F18A64-AA5B-4F22-9401-CEFE61B11E23}: DhcpNameServer=163.244.4.254 163.244.76.254
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{49F8BA0C-8066-48ED-A941-92878F2710D9}: DhcpNameServer=212.27.53.252 212.27.54.252
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{87F18A64-AA5B-4F22-9401-CEFE61B11E23}: DhcpNameServer=163.244.4.254 163.244.76.254
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{49F8BA0C-8066-48ED-A941-92878F2710D9}: DhcpNameServer=212.27.53.252 212.27.54.252
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{87F18A64-AA5B-4F22-9401-CEFE61B11E23}: DhcpNameServer=163.244.4.254 163.244.76.254
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.53.252 212.27.54.252
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.53.252 212.27.54.252
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.53.252 212.27.54.252

      »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

      »»»»»»»»»»»»»»»»»»»»»»»» End
      1. tu n as pas lancè navilog?
        1. Bonjour martine03

          Je viens d'essayer de télécharger navilog mais il indique qu'il ne fonctionne que sous xp/2000 pour vista.... lire l'article qui mène à un http ... inexistant. Puis-je quand même télécharger ce programme sous vista ?

          Merci beaucoup.
      2. Désactive le contrôle des comptes utilisateurs :

        - Va dans démarrer puis panneau de configuration
        - Double Clique sur l'icône "Comptes d'utilisateurs"
        - Clique ensuite sur désactiver et valide.

        Télécharge sur le bureau hijackthis.

        ftp://ftp.commentcamarche.com/download/HJTInstall.exe
        Fait un clic droit sur l'icone hijackthis.

        /!\Renome hijackthis en skim.exe ( a le place de hijacktihs.exe) c'est important!!/!\

        *Après avoir fais ca double-clic dessus.

        *Clic sur Do a system scan and save the log

        *A la fin de l'analyse un rapport va etre générer colle le ici.

        Une démo d'hijackthis :
        http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

        puis,

        Télécharge Navilog:

        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        -Choisis Enregistrer et enregistre-le sur ton bureau.

        - Ensuite double clique sur navilog1.exe pour lancer l'installation.
        Une fois l'installation terminée, le fix s'exécutera automatiquement.
        (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

        -Laisse-toi guider. Au menu principal, choisis 1 et valides.
        (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
        Patiente jusqu'au message " Analyse Termine le ....."

        -Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
        Copie/colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
        Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

        -Si ton antivirus detecte un virus ou un cheval de troie durant l'analyse ignore le.
        1. Bonjour et merci beaucoup à nouveau pour ton aide,

          J'ai suivi les instructions, ci-dessous les rapports hijackthis (question : pq faut-il modifier le nom de l'exécutable ?) et navilog.

          Hier, avant d'avoir ton mail, j'ai fait tourner des scans online (panda, bitdefender et même kaspersky)... mais sans succès, ils ont tous les 3 plantés... panda m'a indiqué la présence d'un troyen et de plusieurs logiciels espions (pourtant j'avais nettoyé avec spyboot et adware) mais impossible de désinfecter.

          ci-dessous rapport skim.exe (hijackthis)

          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
          O4 - HKLM\..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
          O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
          O4 - Global Startup: BTTray.lnk = ?
          O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
          O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
          O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
          O4 - Global Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
          O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
          O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
          O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
          O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
          O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
          O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
          O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
          O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
          O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
          O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

          Ici, rapport navilog :

          Microsoft Windows Vista 6.0.6000
          Internet Explorer : 7.0.6000.16609
          Système de fichiers : NTFS

          Executé en mode normal

          *** Recherche Programmes installés ***

          *** Recherche dossiers dans C:\Windows ***

          *** Recherche dossiers dans C:\Program Files ***

          *** Recherche dossiers dans C:\ProgramData ***

          *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

          *** Recherche dossiers dans c:\users\egide patrimoine\appdata\roaming\microsoft\windows\start menu\programs ***

          *** Recherche dossiers dans C:\Users\egide patrimoine\AppData\Local\virtualstore\Program Files ***

          *** Recherche dossiers dans C:\Users\egide patrimoine\AppData\Roaming ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          Aucun Fichier trouvé

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans C:\Windows\system32 *

          * Recherche dans C:\Users\egide patrimoine\AppData\Local\Microsoft *

          * Recherche dans C:\Users\egide patrimoine\AppData\Local *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans C:\Windows\system32 :

          * Dans C:\Users\egide patrimoine\AppData\Local\Microsoft :

          * Dans C:\Users\egide patrimoine\AppData\Local :

          3)Recherche Certificats :

          Certificat Egroup absent !
          Certificat Electronic-Group absent !
          Certificat OOO-Favorit absent !

          4)Recherche fichiers connus :

          *** Analyse terminée le 2008-03-18 à 10:08:32.81 ***

          Voilà, ....