APIslice.dll

Bonjour,

Avast me detecte un virus :

Nom du fichier : C:\Windows\System32\APISlice.dll
Nom du logiciel : Win32:Trojan-gen {Other}
Type de logiciel : Virus/Ver

Avast ne peut me le supprimer n'y y avoir acces.

Je ne peut pas non plus le supprimer en allant chercher le fichier manuellement.

Can you help me ???????
Configuration: Windows Vista
Internet Explorer 7.0

11 réponses

  1. Contributeur sécurité
    slt,

    analyse sur virus total le fichier et colle le rapport:
    https://www.virustotal.com/gui/

    C:\Windows\System32\APISlice.dll

    ____________

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :
    http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    0
    1. Antivirus Version Dernière mise à jour Résultat
      AhnLab-V3 2008.6.13.1 2008.06.13 -
      AntiVir 7.8.0.55 2008.06.13 -
      Authentium 5.1.0.4 2008.06.12 -
      Avast 4.8.1195.0 2008.06.13 Win32:Trojan-gen {Other}
      AVG 7.5.0.516 2008.06.13 -
      BitDefender 7.2 2008.06.13 -
      CAT-QuickHeal 9.50 2008.06.12 -
      ClamAV 0.92.1 2008.06.13 -
      DrWeb 4.44.0.09170 2008.06.13 -
      eSafe 7.0.15.0 2008.06.12 -
      eTrust-Vet 31.6.5871 2008.06.13 -
      Ewido 4.0 2008.06.13 -
      F-Prot 4.4.4.56 2008.06.12 -
      F-Secure 6.70.13260.0 2008.06.13 -
      Fortinet 3.14.0.0 2008.06.13 -
      GData 2.0.7306.1023 2008.06.13 Win32:Trojan-gen
      Ikarus T3.1.1.26.0 2008.06.13 -
      Kaspersky 7.0.0.125 2008.06.13 -
      McAfee 5316 2008.06.12 -
      Microsoft 1.3604 2008.06.13 -
      NOD32v2 3184 2008.06.13 -
      Norman 5.80.02 2008.06.12 -
      Panda 9.0.0.4 2008.06.12 -
      Prevx1 V2 2008.06.13 -
      Rising 20.48.40.00 2008.06.13 -
      Sophos 4.30.0 2008.06.13 -
      Sunbelt 3.0.1145.1 2008.06.05 -
      Symantec 10 2008.06.13 -
      TheHacker 6.2.92.346 2008.06.12 -
      VBA32 3.12.6.7 2008.06.12 -
      VirusBuster 4.3.26:9 2008.06.12 -
      Webwasher-Gateway 6.6.2 2008.06.13 -
      Information additionnelle
      File size: 73728 bytes
      MD5...: 5ae09979540864bf2aff6427db5aeabd
      SHA1..: 5ef48f7ccd80a42e173e26f459d3a19b3f22896f
      SHA256: fc3b5e2c9e3338e6b722dacf49bdc819a0f3504ffca43882300e2c356fb2b38c
      SHA512: 217c9fd408f7976d3c5743dc1a4def6d00463d0779ea884a6ec97d8272ec84f7
      1743cdaed20adfe5a2e9755a3ac4fe98a0ca5a5cec176dfb9546d38e92523343
      PEiD..: -
      PEInfo: PE Structure information

      ( base data )
      entrypointaddress.: 0x10003893
      timedatestamp.....: 0x45c8a52b (Tue Feb 06 15:56:27 2007)
      machinetype.......: 0x14c (I386)

      ( 5 sections )
      name viradd virsiz rawdsiz ntrpy md5
      .text 0x1000 0x975a 0xa000 6.37 f31551f7bd1840d50ac8ad92f2465e7a
      .rdata 0xb000 0x2baf 0x3000 5.11 6da87874b7c924e63735419bb92372fe
      .data 0xe000 0x1b00 0x1000 2.35 cbea6855972822f4b1a9f52cad4eb995
      .rsrc 0x10000 0x3d0 0x1000 3.69 4da408703f39707e3a47b084f81a327d
      .reloc 0x11000 0x1538 0x2000 3.05 b6c98efe0d8fc6a5f4b53bf8a5c74a4a

      ( 3 imports )
      > KERNEL32.dll: LoadLibraryA, GetLastError, GetModuleHandleA, FreeLibrary, VirtualProtect, VirtualQuery, WideCharToMultiByte, CreateProcessW, CreateProcessA, GetModuleFileNameA, GetProcAddress, SetLastError, WriteProfileStringA, GetProfileStringA, LeaveCriticalSection, VirtualFreeEx, WaitForSingleObject, CreateRemoteThread, WriteProcessMemory, VirtualAllocEx, OpenProcess, GetCurrentProcessId, GetCurrentProcess, Sleep, CreateThread, FormatMessageA, EnterCriticalSection, DeleteCriticalSection, CloseHandle, InitializeCriticalSection, HeapAlloc, HeapFree, RtlUnwind, GetCurrentThreadId, GetCommandLineA, GetVersionExA, GetProcessHeap, VirtualFree, VirtualAlloc, HeapReAlloc, HeapDestroy, HeapCreate, ExitProcess, WriteFile, GetStdHandle, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, InterlockedDecrement, HeapSize, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, GetCPInfo, GetACP, GetOEMCP, RaiseException, MultiByteToWideChar, GetLocaleInfoA, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW
      > USER32.dll: wsprintfA, SendMessageA
      > ADVAPI32.dll: LookupPrivilegeValueA, AdjustTokenPrivileges, OpenProcessToken

      ( 6 exports )
      SliceAPIByProcess, SliceAPIByProcessEx, SliceAPIGlobalProcess, UnSliceAPIByProcess, UnSliceAPIByProcessEx, UnSliceAPIGlobalProcess
      0
      1. Contributeur sécurité
        ok il n'y a que avast qui le considere come infectieux (gdata contient avast aussi)

        colle hijakchits
        0
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 16:31:50, on 13/06/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16681)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\RtHDVCpl.exe
          C:\Acer\Empowering Technology\SysMonitor.exe
          C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Logitech\Video\LogiTray.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Logitech\SetPoint\SetPoint.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
          C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
          C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
          C:\Program Files\Logitech\Video\FxSvr2.exe
          C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
          C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
          C:\Program Files\Internet Explorer\ieuser.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
          C:\Windows\system32\taskeng.exe
          C:\Hijackthis\HijackThis.exe
          C:\Windows\system32\SearchFilterHost.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
          O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
          O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
          O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
          O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
          O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
          O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
          O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
          O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: GigaTribe.lnk = C:\Program Files\GigaTribe\gigatribe.exe
          O4 - Global Startup: Empowering Technology Launcher.lnk = ?
          O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
          O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O13 - Gopher Prefix:
          O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
          O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
          O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
          O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
          O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
          0
          1. Contributeur sécurité
            si tu as norton antivirus et avast vire un des deux

            ________

            télécharge OTMoveIt
            http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
            double-clique sur OTMoveIt.exe pour le lancer.
            copie la liste qui se trouve en citation ci-dessous,
            et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

            Citation :

            C:\Windows\System32\APISlice.dll

            clique sur MoveIt! pour lancer la suppression.
            le résultat apparaitra dans le cadre "Results".
            clique sur Exit pour fermer.
            poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

            il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
            0
            1. Avast de met en branle et m'indique que un virus a été trouvé.

              Je le supprime, le met en quarantaine ?

              OTMoveiT est marqué (ne répond pas) car c'est avast qui doit etre sur le fichier.
              0
              1. Contributeur sécurité
                supprime avec avast
                puis desactive avast et fais otmovit pour voir
                0
                1. LoadLibrary failed for C:\Windows\System32\APISlice.dll
                  C:\Windows\System32\APISlice.dll NOT unregistered.
                  File move failed. C:\Windows\System32\APISlice.dll scheduled to be moved on reboot.

                  OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06132008_164039

                  Files moved on Reboot...
                  File C:\Windows\System32\APISlice.dll not found!
                  0
                  1. Contributeur sécurité
                    ok c'est bon
                    0
                    1. Merci beaucoup a toi ^^

                      Virus éradiqué >_<
                      0
                      1. Contributeur sécurité
                        ok tu peux virer otmovit
                        0