Trojan navipromo af et aa

Bonjour,
je suis infecté depuis quelques semaines par un trojan dénommé navipromo af et aa.
J'ai regardé et étudié avec attention les sujets identiques sur votre forum. Je comprends la marche à suivre mais pouvez vous me guider car à un moment donné je dois vous poster l'analyse du programme de nettoyage.

Config système :
XP Pro, firefox3
antivirus : avg free
outils de nettyage installé : cccleaner, spybot
Merci de votre retour.
Configuration: Windows XP
Firefox 3.0.10

3 réponses

  1. Salut

    Télécharge SmitfraudFix
    Utilitaire de S!Ri: Moe et balltrap34
    http://siri.urz.free.fr/Fix/SmitfraudFix.php

    http://www.malekal.com/tutorial_SmitFraudfix.php
    et télécharge SmitfraudFix.exe.

    Regarde le tuto

    Exécute le en choisissant l’option 1,
    il va générer un rapport
    Copie/colle le sur le poste stp.

    process.exe
    est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    http://www.beyondlogic.org/consulting/processutil/processutil.htm


    Bon courage
    A++

    0
    1. Merci,
      ci dessous le analyses
      1- fichier log
      2 - fichier info
      Dois je attendre votre réponse pour passer à l'étape suivante et lancer le navilog ?

      1 - Log
      Logfile of random's system information tool 1.06 (written by random/random)
      Run by pmq at 2009-05-16 11:10:17
      Microsoft Windows XP Professionnel Service Pack 2
      System drive C: has 28 GB (37%) free of 76 GB
      Total RAM: 703 MB (20% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:10:34, on 16/05/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\BroadJump\Client Foundation\CFD.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\Program Files\Logitech\ImageStudio\LogiTray.exe
      C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\WINDOWS\system32\LVComS.exe
      C:\documents and settings\pmq\local settings\application data\oagia.exe
      C:\Program Files\palmOne\Hotsync.exe
      C:\Program Files\AVG\AVG8\avgcsrvx.exe
      C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
      C:\WINDOWS\system32\WgaTray.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Java\jre6\bin\jucheck.exe
      C:\Program Files\Mozilla Thunderbird\thunderbird.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
      C:\WINDOWS\system32\taskmgr.exe
      C:\Documents and Settings\pmq\Bureau\RSIT.exe
      C:\Program Files\trend micro\pmq.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
      O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
      O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
      O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
      O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [\YUR158.exe] C:\Windows\system32\YUR158.exe
      O4 - HKLM\..\Run: [\YUR159.exe] C:\Windows\system32\YUR159.exe
      O4 - HKLM\..\Run: [\YUR15A.exe] C:\Windows\system32\YUR15A.exe
      O4 - HKLM\..\Run: [\YUR15B.exe] C:\Windows\system32\YUR15B.exe
      O4 - HKLM\..\Run: [\YUR15E.exe] C:\Windows\system32\YUR15E.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [\YUR158.exe] C:\Windows\system32\YUR158.exe
      O4 - HKCU\..\Run: [\YUR159.exe] C:\Windows\system32\YUR159.exe
      O4 - HKCU\..\Run: [\YUR15A.exe] C:\Windows\system32\YUR15A.exe
      O4 - HKCU\..\Run: [\YUR15B.exe] C:\Windows\system32\YUR15B.exe
      O4 - HKCU\..\Run: [\YUR15E.exe] C:\Windows\system32\YUR15E.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [oagia] "c:\documents and settings\pmq\local settings\application data\oagia.exe" oagia
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
      O4 - Global Startup: Docteur Club Internet.lnk = C:\Program Files\Club-Internet\Dr Club Internet\bin\matcli.exe
      O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\palmOne\Hotsync.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Ouvrir l'image dans &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~2\Office\1036\phdintl.dll/phdContext.htm
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
      O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
      O23 - Service: hpdj - HP - C:\DOCUME~1\pmq\LOCALS~1\Temp\hpdj.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      0
      1. Bonjour

        Fais ce qui suit dans l'ordre -- stp

        C - Ccleaner :
        (nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc.)
        * Télécharge CCleaner.
        (attention à l'installation penser à DECOCHER l'installation de Yahoo toolbar discrètement proposé en plus de CCleaner).

        https://www.pcastuces.com/logitheque/ccleaner.htm
        http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner
        Installe le dans un répertoire dédié.
        Décoche pendant l'installation
        --- les deux cases "Ajouter l'option ... "
        --- Contrôler les mises à jour
        * Lance Ccleaner pour un nettoyage complet.
        Tutorial ici:
        https://kerio.probb.fr/t242-tuto-ccleaner-v-2
        https://www.malekal.com/tutoriel-ccleaner/
        ET
        http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

        ============================

        > Télécharge random's system information tool (RSIT) : http://images.malwareremoval.com/random/RSIT.exe
        - Enregistre le programme sur ton bureau.
        - Double clique sur RSIT.exe
        - A l'écran "Disclaimer" choisis "1 months" dans le menu déroulant puis clique sur <continue>.
        - Si HiJackThis n'est pas détecté sur ton PC, RSIT le téléchargera ; accepte alors la licence.
        - Une fois le scanne terminé tu obtiendras un rapport log.txt. Poste le sur le forum.
        NB : Il se peut que tu obtiennes un second rapport nommé info.txt. Dans ce cas poste le aussi.

        =========================================

        Important : Désactive TeaTimer, le résident de Spybot, il va gêner la désinfection en empêchant la modification des BHO. (SI PRESENT)
        # Lancez Spybot > Mode avancé > Outils >> Résident
        # Décochez la case résident "tea timer" et refermez Spybot

        Fais un clic droit sur ce lien :
        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
        Fais un clic droit sur navilog1.zip et choisis "tout extraire"
        Ensuite double clique sur navilog1.exe pour lancer l'installation.
        Une fois l'installation terminée, le fix s'exécutera automatiquement.
        (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

        Laisse-toi guider. Au menu principal, choisis 1 et valides.
        (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
        Patiente jusqu'au message :
        *** Analyse Termine le ..... ***
        Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
        Copie-colle l'intégralité dans une réponse. Referme le blocnote.
        Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
        TUTO :: http://www.malekal.com/Adware.Magic_Control.php

        Bon courage
        A++
        0
        1. J'ai lancé navilog voici le rapport fixnavi

          que dois en conclure ? Merci

          Search Navipromo version 3.7.7 commencé le 16/05/2009 à 11:42:02,34

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1

          Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO

          Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
          X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2200+ )
          BIOS : Phoenix - AwardBIOS v6.00PG
          USER : pmq ( Administrator )
          BOOT : Normal boot

          Antivirus : AVG Anti-Virus Free 8.0 (Activated)

          A:\ (USB)
          C:\ (Local Disk) - NTFS - Total:74 Go (Free:27 Go)
          D:\ (CD or DVD)

          Recherche executé en mode normal

          *** Recherche dossiers dans "C:\WINDOWS" ***

          *** Recherche dossiers dans "C:\Program Files" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

          *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\pmq\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\pmq\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\pmq\menudm~1\progra~1" ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans "C:\WINDOWS\system32" *

          * Recherche dans "C:\Documents and Settings\pmq\locals~1\applic~1" *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***
          !! Les clés trouvées ne sont pas forcément infectées !!

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "oagia"="\"c:\\documents and settings\\pmq\\local settings\\application data\\oagia.exe\" oagia"

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans "C:\WINDOWS\system32" :

          * Dans "C:\Documents and Settings\pmq\locals~1\applic~1" :

          oagia.exe trouvé !
          oagia.dat trouvé !
          oagia_nav.dat trouvé !
          oagia_navps.dat trouvé !

          3)Recherche Certificats :

          Certificat Egroup absent !
          Certificat Electronic-Group absent !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit absent !
          Certificat Sunny-Day-Design-Ltd absent !

          4)Recherche autres dossiers et fichiers connus :

          *** Analyse terminée le 16/05/2009 à 11:47:30,00 ***
          0