Rogue "security servise" rkill ne marche pas
RésoluComme vous pouvez le constater j'ai choppé un rogue. Mon seul navigateur qui marche est firefox (je ne sais pas pourquoi...). Avant de poster je me suis renseigné sur les rogue et j'ai trouvé le moyen de les enlever seulement rkill ne marche pas sur mon pc donc je suis bloqué, que pui-je faire ?
quelqu'un peut-il m'aider? D'avance merci.
34 réponses
Le problème central est l'infection par un rogue sur Windows XP, où seul Firefox reste fonctionnel et où RKill ne semble pas suffisant pour désactiver l'infection. Des réponses proposent des méthodes concrètes: désinstaller puis redémarrer en mode sans échec, désactiver un proxy potentiellement installé, puis lancer RKill renommé et divers outils de désinfection. Les solutions recommandées incluent Malwarebytes Anti-Malware, ZHPDiag et ZHPFix pour diagnostiquer et nettoyer les traces enregistrées et fichiers, avec des rapports à partager ensuite ultérieurement. En cas de doute, des rapports techniques et des vérifications complémentaires sont évoqués, notamment pour vérifier le proxy et l'intégrité des postes avant de poursuivre la désinfection.
-
ContributeurBonjour,
Ok, maintenant :
<|> Pour supprimer tout les outils :
¤ Relancer ZHPDiag et générer un rapport en appuyant sur la loupe en haut à gauche.
¤ A la fin du chargement, cliquer en haut à droite sur l'icône du bouclier vert pour lancer ZHPfix.
¤ Appuyer maintenant sur le A rouge en haut pour lancer la suppression des outils.
¤ Sélectionner tout les outils en appuyant sur "Tous" (tous les outils sont cochés par défaut) et cliquer ensuite sur "Nettoyer".
¤ Redémarrer à la demande.
<|> Un petit coup de Ccleaner :
Utilise ce programme pour optimiser ton ordinateur :
¤ Télécharge CCleaner Slim.
¤ Installe le puis lance le.
¤ Clique sur Nettoyeur > Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s'affiche.
¤ Enfin, clique sur Registre > corrige toutes les erreurs et recommence jusqu'à ce que CCleaner ne trouve plus d'erreurs.
Tu peux garder ce programme et l'utiliser régulièrement (une fois par mois).
<|> La restauration du système a peut être été touchée, le mieux est de la purger (la désactiver et la réactiver) :
¤ Sous XP :
o Aller au menu démarrer et cliquer droit sur "Poste de travail" et sélectionner "Propriétés"
o Dans l'onglet "Restauration du système", cocher "Désactiver la restauration du système sur tout les lecteurs"
o Cliquer sur appliquer et confirmer (tout les points de restauration sont supprimés).
o Décocher la case "Désactiver la restauration du système sur tout les lecteurs" et cliquer sur Appliquer pour réactiver la restauration du système.
¤ Sous Vista/Seven :
o Aller au menu démarrer et cliquer droit sur "Ordinateur" puis sélectionner "Propriétés"
o Cliquer sur "Protection du système"
o Décocher la case du ou des disques pour lesquels on veut désactiver la restauration du système
o Cliquer sur OK et confirmer (tout les points de restauration sont supprimés).
o Recocher la case des disques pour lesquels on veut réactiver la restauration du système et valider.
Créer un point de restauration propre pour finir :
¤ Sous XP :
o Aller au menu demarrer
o Dans "Tous les programmes"
o Dans "Accessoires"
o Dans "outils système"
o Cliquer sur "restauration du système"
o Cocher "Créer un point de restauration" et cliquer sur "Suivant"
o Entrer une description n'importe du point de restauration puis cliquer sur "Créer"
o Le point se crée, cliquer sur fermer pour quitter la restauration du système
¤ Sous Vista :
o Dans le menu démarrer, puis "Rechercher", taper "restauration", puis cliquer sur "Centre de sauvegarde et de restauration"
o Puis sur le volet de gauche, cliquer sur "Créer un point de restauration ou modifier les paramètres"
o L'onglet Protection du système s'ouvre, vérifier que votre disque soit bien coché, puis cliquer sur "Créer"
o Entrer une description pour identifier facilement le point de restauration, puis cliquer sur Créer
o Le point de restauration se crée, un message de réussite apparaît : le point a été créé, refermer les fenêtres.
¤ Sous Seven :
o Dans Démarrer, puis "Rechercher", taper "restauration", puis cliquer sur "Créer un point de restauration"
o L'onglet Protection du système s'ouvre, vérifier que la protection sur votre disque soit bien activée, puis cliquer sur "Créer"
o Entrer une description pour identifier facilement le point de restauration, puis cliquer sur "Créer"
o Le point de restauration se crée, un message de réussite apparaît : le point a été créé, refermer les fenêtres.
<|> Pour garder un PC propre, il faut tout d'abord installer une protection, ce qui veut dire, installer un antivirus, un antispyware et un pare feu, voila quelques conseils :
Antivirus payant -> Kaspersky, Antivirus gratuit -> Avira antivir / Avast
Antispyware payant -> Malwarebytes Antimalware, Antispyware gratuit -> SuperAntispyware
Pare feu payant -> ZoneAlarm, Pare feu gratuit -> COMODO.>>> Tuto COMODO
Toute fois, on est jamais assez prudent, il faut faire attention à son comportement sur le net, les cracks les keygens la P2P sont tous à bannir.
Une autre précaution à prendre, les mises à jour, celles ci sont contrairement à ce que la plupart des gens pensent très très importantes, les application les plus importantes à mettre à jour sont : Adobe Reader, Java, Flash player et les mises à jour windows, voilà un logiciel très léger et utile pour les mises à jour (éviter les bêtas) > File Hippo Update Cheker
Voilà aussi quelques liens utiles
Les mises à jour Windows
Les mises de Adobe Reader et Java et Flash player
Le danger des cracks
Les toolbars
Comparatif Antivirus
Comparatif Antivirus
Les infections USB
Et bon surf ;)
++
Karel -
voila le scan
Rapport de ZHPFix v1.12.3135 par Nicolas Coolman, Update du 18/08/2010
Fichier d'export Registre : C:\ZHPExportRegistry-21-08-2010-15-52-30.txt
Run by HP_Propriétaire at 21/08/2010 15:52:30
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Contact : nicolascoolman@yahoo.fr
========== Clé(s) du Registre ==========
HKCU\Software\wnxmal => Clé supprimée avec succès
========== Récapitulatif ==========
1 : Clé(s) du Registre
End of the scan -
ContributeurBonjour,
Le rapport est clean, reste seulement une clé du registre récalcitrante que nous devons éliminer :
¤ Lance ZHPFix (soit via le raccourci sur ton Bureau, soit via ZHPDiag) (Sous Vista/Seven, clique droit "Executer en tant qu'administrateur")
¤ Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
¤ Copie/colle les lignes suivantes et place les dans ZHPFix :
______________________________________________
[HKCU\Software\wnxmal]
______________________________________________
¤ Clique sur « Tous », puis sur « Nettoyer »
¤ Copie/colle la totalité du rapport dans ta prochaine réponse
++
Karel -
voici le dernier scan
http://www.cijoint.fr/cjlink.php?file=cj201008/cijuFTNbMZ.txt -
ContributeurBonjour,
Très bien pour OTM.
Pour ZHPfix, je crois que tu as par faute ajouté des lignes du rapport d'OTM, l'outil ne les a pas reconnues, il n'a donc heureusement rien fait, fait plus attention la prochaine fois car tu risque de mettre le bon fonctionnement de ton PC en danger.
Pour MBAM, il a fait du bon travail, il a éliminé le rogue, maintenant, poste un autre rapport ZHPDiag pour voir ;) (n'oublie pas de le mettre sur cijoint)
++
Karel -
visiblement le rogue est parti je te remercie :)
-
voila le rapport
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Version de la base de données: 4450
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11
20/08/2010 02:24:38
mbam-log-2010-08-20 (02-24-38).txt
Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 200409
Temps écoulé: 54 minute(s), 52 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 4
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 4
Fichier(s) infecté(s): 12
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bhgvvtyj (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bhgvvtyj (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wviofgko (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wviofgko (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997} (Adware.ResultDns) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome (Adware.ResultDns) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\defaults (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\defaults\preferences (Adware.ResultDns) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\HP_Propriétaire\Application Data\kahmbiisi\xfaocaoshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\imcmbavkv\xnoijdqshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\kahmbiisi\xfaocaoshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP21\A0003063.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP22\A0003165.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP22\A0003172.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\_OTM\MovedFiles\08202010_005902\C_Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\_OTM\MovedFiles\08202010_005902\C_Program Files\ResultDns\resultdns.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome.manifest (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\install.rdf (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome\resultdns.jar (Adware.ResultDns) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\defaults\preferences\prefs.js (Adware.ResultDns) -> Quarantined and deleted successfully. -
sinon je ne sais pas si il y un rapport mais mon antivirus (avira) m'affiche un message d'alerte comme quoi un fichier contient le cheval de troie
TR/Crypt.XPACK.Gen -
je viens de lancer MBAM ......
-
Rapport de ZHPFix v1.12.3135 par Nicolas Coolman, Update du 18/08/2010
Fichier d'export Registre : C:\ZHPExportRegistry-20-08-2010-01-11-45.txt
Run by HP_Propriétaire at 20/08/2010 01:11:45
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Contact : nicolascoolman@yahoo.fr
========== Processus mémoire ==========
C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe moved successfully. => Fichier absent
C:\Program Files\ResultDns\resultdns.exe moved successfully. => Fichier absent
========== Clé(s) du Registre ==========
O42 - Logiciel: ResultDns 1.0 build 113 - (.Pas de propriétaire.) [HKLM] -- ResultDns => Clé supprimée avec succès
O23 - Service: ResultDns Service (ResultDns Service) . (.Pas de propriétaire - Pas de description.) - C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe => Clé supprimée avec succès
O64 - Services: CurCS - C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe - ResultDns Service (ResultDns Service) .(.Pas de propriétaire - Pas de description.) - LEGACY_RESULTDNS_SERVICE => Clé supprimée avec succès
========== Valeur(s) du Registre ==========
O4 - HKUS\S-1-5-21-1282220339-793324306-1302408614-1007\..\Run: [GabPath] C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath\gabpath.exe (.not file.) => Valeur supprimée avec succès
O4 - HKCU\..\Run: [GabPath] C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath\gabpath.exe (.not file.) => Valeur absente
========== Dossier(s) ==========
C:\Program Files\ResultDns => Supprimé et mis en quarantaine
========== Logiciel(s) ==========
O42 - Logiciel: ResultDns 1.0 build 113 - (.Pas de propriétaire.) [HKLM] -- ResultDns => Logiciel non supprimé
========== Autre ==========
All processes killed => Format Non supporté
========== FILES ========== => Format Non supporté
========== COMMANDS ========== => Format Non supporté
[EMPTYTEMP] => Format Non supporté
User: Administrateur => Format Non supporté
->Temp folder emptied: 70231 bytes => Format Non supporté
->Temporary Internet Files folder emptied: 32902 bytes => Format Non supporté
->FireFox cache emptied: 3355436 bytes => Format Non supporté
User: All Users => Format Non supporté
User: Default User => Format Non supporté
->Temp folder emptied: 70231 bytes => Format Non supporté
->Temporary Internet Files folder emptied: 32768 bytes => Format Non supporté
User: HP_Propriétaire => Format Non supporté
->Temp folder emptied: 38233980 bytes => Format Non supporté
->Temporary Internet Files folder emptied: 113476 bytes => Format Non supporté
->Java cache emptied: 0 bytes => Format Non supporté
->FireFox cache emptied: 40317021 bytes => Format Non supporté
->Google Chrome cache emptied: 0 bytes => Format Non supporté
->Flash cache emptied: 834 bytes => Format Non supporté
User: LocalService => Format Non supporté
->Temp folder emptied: 115616 bytes => Format Non supporté
->Temporary Internet Files folder emptied: 4456833 bytes => Format Non supporté
User: NetworkService => Format Non supporté
->Temp folder emptied: 0 bytes => Format Non supporté
->Temporary Internet Files folder emptied: 33170 bytes => Format Non supporté
%systemdrive% .tmp files removed: 0 bytes => Format Non supporté
%systemroot% .tmp files removed: 0 bytes => Format Non supporté
%systemroot%\System32 .tmp files removed: 3072 bytes => Format Non supporté
%systemroot%\System32\dllcache .tmp files removed: 0 bytes => Format Non supporté
%systemroot%\System32\drivers .tmp files removed: 0 bytes => Format Non supporté
Windows Temp folder emptied: 1328744 bytes => Format Non supporté
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 70231 bytes => Format Non supporté
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes => Format Non supporté
RecycleBin emptied: 0 bytes => Format Non supporté
Total Files Cleaned = 84,00 mb => Format Non supporté
OTM by OldTimer - Version 3.1.15.0 log created on 08202010_005902 => Format Non supporté
Files moved on Reboot... => Format Non supporté
========== Récapitulatif ==========
2 : Processus mémoire
3 : Clé(s) du Registre
2 : Valeur(s) du Registre
1 : Dossier(s)
1 : Logiciel(s)
37 : Autre
End of the scan -
voila le rapport de OTM
All processes killed
========== FILES ==========
C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe moved successfully.
C:\Program Files\ResultDns\resultdns.exe moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrateur
->Temp folder emptied: 70231 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->FireFox cache emptied: 3355436 bytes
User: All Users
User: Default User
->Temp folder emptied: 70231 bytes
->Temporary Internet Files folder emptied: 32768 bytes
User: HP_Propriétaire
->Temp folder emptied: 38233980 bytes
->Temporary Internet Files folder emptied: 113476 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 40317021 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 834 bytes
User: LocalService
->Temp folder emptied: 115616 bytes
->Temporary Internet Files folder emptied: 4456833 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 3072 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1328744 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 70231 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 84,00 mb
OTM by OldTimer - Version 3.1.15.0 log created on 08202010_005902
Files moved on Reboot...
Registry entries deleted on Reboot... -
ContributeurCe n'est pas AD-R
qui devrait éliminer le rogue mais des Adwares, c'est sa specialité, nous allons maintenant nous occuper de notre rogue, comme ceci ;) :
¤ Télécharge OTM (OtmoveIT de Old_Timer) sur ton Bureau
¤ Double-clique sur OTM.exe pour le lancer.
¤ Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTM sous Paste Instructions for Items to be Moved.
-----------------------------
:files
C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe
C:\Program Files\ResultDns\resultdns.exe
:commands
[purity]
[emptytemp]
-----------------------------
¤ Clique sur MoveIt! puis ferme OTM.
¤ Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
¤ Accepte en cliquant sur YES.
¤ Poste le rapport situé dans C:\_OTM\MovedFiles.
¤ Le nom du rapport correspond au moment de sa création : date_heure.log
Ensuite :
¤ Lance ZHPFix (soit via le raccourci sur ton Bureau, soit via ZHPDiag) (Sous Vista/Seven, clique droit "Executer en tant qu'administrateur")
¤ Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
¤ Copie/colle les lignes suivantes et place les dans ZHPFix :
----------------------------------------------------------
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
O4 - HKUS\S-1-5-21-1282220339-793324306-1302408614-1007\..\Run: [GabPath] C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath\gabpath.exe (.not file.)
O4 - HKCU\..\Run: [GabPath] C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath\gabpath.exe (.not file.)
O23 - Service: ResultDns Service (ResultDns Service) . (.Pas de propriétaire - Pas de description.) - C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe
O42 - Logiciel: ResultDns 1.0 build 113 - (.Pas de propriétaire.) [HKLM] -- ResultDns
O43 - CFD:Common File Directory ----D- C:\Program Files\ResultDns
O64 - Services: CurCS - C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe - ResultDns Service (ResultDns Service) .(.Pas de propriétaire - Pas de description.) - LEGACY_RESULTDNS_SERVICE
----------------------------------------------------------
¤ Clique sur « Tous », puis sur « Nettoyer »
¤ Copie/colle la totalité du rapport dans ta prochaine réponse
Après avoir fait tout ceci, essaye d'utiliser Malwarebytes et cette fois, retélécharge le et renomme le par ton nom par exemple avant de l'executer
++
Karel -
j'ai fait nettoyer avec AD-R on m'a conseillé de redémarer l'ordi pour finir le nettoyage je l'ai fait et le rogue était toujours la. du coup j'ai réactivé Rkill. Il est coriace !!
-
tient voila le rapport de ZFPFix
http://www.cijoint.fr/cjlink.php?file=cj201008/cijjTWXbHb.txt -
ContributeurRe,
je crois qu'il n'a rien trouvé d'anormal ... non?
Si, il en a trouvé, tu doit le relancer et cliquer cette fois sur "nettoyer" car tu as fait un scan
Et n'oublie pas le rapport ZHPDiag ;), celui ci nous donnera toute les informations nécessaires pour te désinfecter ;) -
======= RAPPORT D'AD-REMOVER 2.0.0.1,D | UNIQUEMENT XP/VISTA/7 =======
Mis à jour par C_XX le 26/07/10 à 12:00
Contact: AdRemover.contact[AT]gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 22:49:42 le 19/08/2010, Mode normal
Microsoft Windows XP Édition familiale Service Pack 2 (X86)
HP_Propriétaire@NOM-641695C7437 ( )
============== RECHERCHE ==============
0,Dossier trouvé: C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
0,Fichier trouvé: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
0,Dossier trouvé: C:\Program Files\Ask.com
0,Dossier trouvé: C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\AskToolbar
0,Dossier trouvé: C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Conduit
0,Dossier trouvé: C:\Program Files\Conduit
0,Dossier trouvé: C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath
3,Fichier trouvé: C:\WINDOWS\Installer\1bf7b0.msi
-- Fichier ouvert: C:\Documents and Settings\HP_Propriétaire\Application Data\Mozilla\FireFox\Profiles\uj0wmv2q.default\Prefs.js --
Ligne trouvée: user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?SearchSource=10&ctid=CT1750559");
-- Fichier Fermé --
1,Clé trouvée: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
1,Clé trouvée: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
1,Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
1,Clé trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
1,Clé trouvée: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
1,Clé trouvée: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
1,Clé trouvée: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
1,Clé trouvée: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
0,Clé trouvée: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
0,Clé trouvée: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
0,Clé trouvée: HKLM\Software\Classes\Toolbar.CT1750559
0,Clé trouvée: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
1,Clé trouvée: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
0,Clé trouvée: HKLM\Software\Conduit
0,Clé trouvée: HKCU\Software\Ask.com
0,Clé trouvée: HKCU\Software\AskToolbar
0,Clé trouvée: HKCU\Software\Conduit
0,Clé trouvée: HKCU\Software\AppDataLow\AskToolbarInfo
0,Clé trouvée: HKU\.DEFAULT\Software\AskToolbar
0,Clé trouvée: HKU\.DEFAULT\Software\Conduit
0,Clé trouvée: HKU\S-1-5-18\Software\AskToolbar
0,Clé trouvée: HKU\S-1-5-18\Software\Conduit
3,Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
3,Clé trouvée: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
0,Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
0,Valeur trouvée: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{00000000-6E41-4FD3-8538-502F5495E5FC}
0,Valeur trouvée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}
0,Valeur trouvée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}
============== SCAN ADDITIONNEL ==============
** Mozilla Firefox Version [3.5.11 (fr)] **
-- C:\Documents and Settings\HP_Propriétaire\Application Data\Mozilla\FireFox\Profiles\uj0wmv2q.default\Prefs.js --
browser.startup.homepage, hxxp://search.conduit.com/?SearchSource=10&ctid=CT1750559
browser.startup.homepage_override.mstone, rv:1.9.1.11
-- C:\Documents and Settings\Administrateur\Application Data\Mozilla\FireFox\Profiles\c9bogv4y.default\Prefs.js --
browser.startup.homepage_override.mstone, rv:1.9.1.11
========================================
** Internet Explorer Version [7.0.5730.11] **
[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.01net.com/telecharger/
Default_Search_URL: hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
Show_ToolBar: yes
Start Page: hxxp://www.google.com/
Use Search Asst: no
[HKLM\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.01net.com/telecharger/
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://www.01net.com/telecharger/
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
========================================
C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files\Ad-Remover\Backup: 1 Fichier(s)
C:\Ad-Report-SCAN[1].txt - 19/08/2010 (5415 Octet(s))
Fin à: 22:53:13, 19/08/2010
============== E.O.F ==============
je crois qu'il n'a rien trouvé d'anormal ... non? -
ContributeurRe,
a la fin du rapport de ZHPDiag ecrit ceci ---\\ Infection BT - BHO/Toolbar (Possible) R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} . (.Ask.com - Ask.com Toolbar.) (5.6.9.135) -- C:\Program Files\Ask.com\GenericAskToolbar.dll O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Ask.com - Ask.com Toolbar.) -- C:\Program Files\Ask.com\GenericAskToolbar.dll O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Ask.com - Ask.com Toolbar.) -- C:\Program Files\Ask.com\GenericAskToolbar.dll O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- {86D4B82A-ABED-442A-BE86-96357B70F4FE} [HKCU\Software\Ask.com]
Ok, nous avons des infections mais pourquoi est ce que tu n'as pas posté le rapport complet ?? note qu'il est trop long donc tu le met sur cijoint ;)
Pour traiter les infections :
¤ Télécharge AD-Remover (de C_XX) sur ton Bureau.
/!\ Déconnecte toi et ferme toutes les applications en cours /!\
¤ Double-clique sur l'icône AD-Remover
¤ Au menu principal, clique sur "Nettoyer"
¤ Confirme le lancement de l'analyse et laisse l'outil travailler
¤ Poste le rapport qui apparait à la fin (il est aussi sauvegardé sous C:\Ad-report-CLEAN.txt )
(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
++
Karel -
voila le premeier rapport
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
GoogleUpdate.exe
Submission date:
2010-08-19 19:52:10 (UTC)
Current status:
finished
Result:
0 /41 (0.0%)
VT Community
not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2010.08.19.01 2010.08.19 -
AntiVir 8.2.4.38 2010.08.19 -
Antiy-AVL 2.0.3.7 2010.08.16 -
Authentium 5.2.0.5 2010.08.19 -
Avast 4.8.1351.0 2010.08.19 -
Avast5 5.0.332.0 2010.08.19 -
AVG 9.0.0.851 2010.08.19 -
BitDefender 7.2 2010.08.19 -
CAT-QuickHeal 11.00 2010.08.19 -
ClamAV 0.96.2.0-git 2010.08.19 -
Comodo 5786 2010.08.19 -
DrWeb 5.0.2.03300 2010.08.19 -
Emsisoft 5.0.0.37 2010.08.19 -
eSafe 7.0.17.0 2010.08.19 -
eTrust-Vet 36.1.7801 2010.08.19 -
F-Prot 4.6.1.107 2010.08.19 -
F-Secure 9.0.15370.0 2010.08.19 -
Fortinet 4.1.143.0 2010.08.19 -
GData 21 2010.08.19 -
Ikarus T3.1.1.88.0 2010.08.19 -
Jiangmin 13.0.900 2010.08.19 -
Kaspersky 7.0.0.125 2010.08.19 -
McAfee 5.400.0.1158 2010.08.19 -
McAfee-GW-Edition 2010.1B 2010.08.19 -
Microsoft 1.6004 2010.08.19 -
NOD32 5380 2010.08.19 -
Norman 6.05.11 2010.08.19 -
nProtect 2010-08-19.01 2010.08.19 -
Panda 10.0.2.7 2010.08.19 -
PCTools 7.0.3.5 2010.08.19 -
Prevx 3.0 2010.08.19 -
Rising 22.61.03.04 2010.08.19 -
Sophos 4.56.0 2010.08.19 -
Sunbelt 6762 2010.08.19 -
SUPERAntiSpyware 4.40.0.1006 2010.08.19 -
Symantec 20101.1.1.7 2010.08.19 -
TheHacker 6.5.2.1.351 2010.08.19 -
TrendMicro 9.120.0.1004 2010.08.19 -
TrendMicro-HouseCall 9.120.0.1004 2010.08.19 -
ViRobot 2010.8.16.3990 2010.08.19 -
VirusBuster 5.0.27.0 2010.08.19 -
Additional information
Show all
MD5 : 8f0de4fef8201e306f9938b0905ac96a
SHA1 : d2e2915087427be8ea88b4a174c334c578208e78
SHA256: ca7153fe0c037d79fbf7ce0e090d741fb52bccbbbd4ca505ef4849a0c4199f72
ssdeep: 3072:EK5b1edk0bT5ni+lRd4ESGf4Fv5NR2OnCW8DCUck/CJcd+F9UK/r1F2aTwXZg0bQ:EK5bZ
yNi+RS
File size : 135664 bytes
First seen: 2009-10-28 01:12:22
Last seen : 2010-08-19 19:52:10
Magic: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
TrID:
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
sigcheck:
publisher....: Google Inc.
copyright....: Copyright 2007-2009 Google Inc.
product......: Google Update
description..: Google Installer
original name: GoogleUpdate.exe
internal name: Google Update
file version.: 1.2.183.9
comments.....: n/a
signers......: Google Inc
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 12:04 AM 10/14/2009
verified.....: -
PEiD: -
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x50CE
timedatestamp....: 0x4AD50798 (Tue Oct 13 23:04:56 2009)
machinetype......: 0x14C (Intel I386)
[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0xD00B, 0xD200, 6.64, a3b9b6e46995b81015b176e0de2b1fa6
.data, 0xF000, 0x2EA8, 0x1200, 2.41, 23bda919485d01c8e04b1f0f502dcff1
.text_DE, 0x12000, 0x318E, 0x3200, 5.36, 7c96b0385c61b0fee276d13b535c06aa
.rsrc, 0x16000, 0xE0F8, 0xE200, 4.22, 1f2935791db10c014809279836295dbb
[[ 3 import(s) ]]
advapi32.dll: GetTokenInformation, OpenProcessToken, RegOpenKeyExW
kernel32.dll: GetCurrentProcess, GetProcAddress, SizeofResource, lstrlenW, FindResourceExW, FindResourceW, CloseHandle, FreeLibrary, GetCommandLineW, GetModuleFileNameW, RaiseException, LoadResource, GetModuleHandleW, LockResource, GetFileAttributesExW, VerifyVersionInfoW, LoadLibraryExW, VerSetConditionMask, GetLastError, SetLastError, LocalAlloc, SetStdHandle, SetFilePointer, InterlockedExchange, LoadLibraryA, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, GetVersionExA, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, GetCurrentThreadId, InterlockedDecrement, WideCharToMultiByte, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsA, MultiByteToWideChar, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, VirtualAlloc, RtlUnwind, Sleep, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, GetLocaleInfoA, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, GetConsoleCP, GetConsoleMode, FlushFileBuffers, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA
ole32.dll: CoCreateGuid
VT Community
0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!
VirusTotal Team
et voila le deuxieme
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
resultdns113.exe
Submission date:
2010-08-19 19:57:19 (UTC)
Current status:
finished
Result:
3 /42 (7.1%)
VT Community
not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2010.08.19.01 2010.08.19 -
AntiVir 8.2.4.38 2010.08.19 -
Antiy-AVL 2.0.3.7 2010.08.16 -
Authentium 5.2.0.5 2010.08.19 -
Avast 4.8.1351.0 2010.08.19 -
Avast5 5.0.332.0 2010.08.19 -
AVG 9.0.0.851 2010.08.19 -
BitDefender 7.2 2010.08.19 -
CAT-QuickHeal 11.00 2010.08.19 -
ClamAV 0.96.2.0-git 2010.08.19 -
Comodo 5786 2010.08.19 -
DrWeb 5.0.2.03300 2010.08.19 -
Emsisoft 5.0.0.37 2010.08.19 -
eSafe 7.0.17.0 2010.08.19 -
eTrust-Vet 36.1.7801 2010.08.19 -
F-Prot 4.6.1.107 2010.08.19 -
F-Secure 9.0.15370.0 2010.08.19 -
Fortinet 4.1.143.0 2010.08.19 -
GData 21 2010.08.19 -
Ikarus T3.1.1.88.0 2010.08.19 -
Jiangmin 13.0.900 2010.08.19 -
Kaspersky 7.0.0.125 2010.08.19 -
McAfee 5.400.0.1158 2010.08.19 -
McAfee-GW-Edition 2010.1B 2010.08.19 -
Microsoft 1.6004 2010.08.19 BrowserModifier:Win32/Zwangi
NOD32 5380 2010.08.19 -
Norman 6.05.11 2010.08.19 -
nProtect 2010-08-19.01 2010.08.19 -
Panda 10.0.2.7 2010.08.19 Suspicious file
PCTools 7.0.3.5 2010.08.19 -
Prevx 3.0 2010.08.19 Low Risk Adware
Rising 22.61.03.04 2010.08.19 -
Sophos 4.56.0 2010.08.19 -
Sunbelt 6762 2010.08.19 -
SUPERAntiSpyware 4.40.0.1006 2010.08.19 -
Symantec 20101.1.1.7 2010.08.19 -
TheHacker 6.5.2.1.351 2010.08.19 -
TrendMicro 9.120.0.1004 2010.08.19 -
TrendMicro-HouseCall 9.120.0.1004 2010.08.19 -
VBA32 3.12.14.0 2010.08.19 -
ViRobot 2010.8.16.3990 2010.08.19 -
VirusBuster 5.0.27.0 2010.08.19 -
Additional information
Show all
MD5 : c60fd7fd11cbd84ad592303431814cb4
SHA1 : 65f190e0d14794508c42f7661af3d880bab5f6c7
SHA256: 3b8b1bb34733a7bacd99f9bbaaa4155f5792de3b6febafe9671c84cf92ca0418
ssdeep: 1536:+3gqKITX5yi+0MERmFph6WYpm5SmlUBCYSVDNycn:DyJy10YC9HMDN7
File size : 57608 bytes
First seen: 2010-08-19 19:57:19
Last seen : 2010-08-19 19:57:19
Magic: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
TrID:
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: ResultDns.com
UTN-USERFirst-Object
signing date.: 7:06 AM 8/19/2010
verified.....: -
PEiD: -
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x5E62
timedatestamp....: 0x4C6CBBBC (Thu Aug 19 05:06:04 2010)
machinetype......: 0x14C (Intel I386)
[[ 3 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x8F46, 0x9000, 6.55, ecdf81b181b2dd1feb9b08b7a7d5642e
.rdata, 0xA000, 0x18DE, 0x2000, 3.96, 65388aa02a36b3b86519fa522c727ebd
.data, 0xC000, 0x958, 0x1000, 1.03, 342e1f4d3bcbc47ffeaee0a3b118ae25
[[ 1 import(s) ]]
kernel32.dll: GetProcAddress, LoadLibraryExA, lstrcmpA, CreateFileA, lstrcpyA, lstrlenA, RtlUnwind, RaiseException, GetSystemTimeAsFileTime, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersionExA, HeapAlloc, SetUnhandledExceptionFilter, HeapFree, ExitProcess, TerminateProcess, GetCurrentProcess, WriteFile, GetStdHandle, GetModuleFileNameA, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetLastError, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, IsBadWritePtr, HeapSize, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, GetACP, GetOEMCP, GetCPInfo, IsBadReadPtr, IsBadCodePtr, LoadLibraryA, InterlockedExchange, VirtualQuery, GetLocaleInfoA, VirtualProtect, GetSystemInfo, LCMapStringA, LCMapStringW, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId
Prevx Info:
http://info.prevx.com/aboutprogramtext.asp?PX5=9EFE9CA4087C3A35E13B004CEC656900E46FBE4F
Symantec reputation:Suspicious.Insight
VT Community
0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!
VirusTotal Team
celui la a l'aire plus suspect... -
a la fin du rapport de ZHPDiag ecrit ceci
---\\ Infection BT - BHO/Toolbar (Possible)
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} . (.Ask.com - Ask.com Toolbar.) (5.6.9.135) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Ask.com - Ask.com Toolbar.) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Ask.com - Ask.com Toolbar.) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- {86D4B82A-ABED-442A-BE86-96357B70F4FE}
[HKCU\Software\Ask.com]
pour le premier fichier avec virus total
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
GoogleUpdate.exe
Submission date:
2010-08-19 19:52:10 (UTC)
Current status:
queued queued analysing finished
Result:
0/ 41 (0.0%)
VT Community
not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2010.08.19.01 2010.08.19 -
AntiVir 8.2.4.38 2010.08.19 -
Antiy-AVL 2.0.3.7 2010.08.16 -
Authentium 5.2.0.5 2010.08.19 -
Avast 4.8.1351.0 2010.08.19 -
Avast5 5.0.332.0 2010.08.19 -
AVG 9.0.0.851 2010.08.19 -
BitDefender 7.2 2010.08.19 -
CAT-QuickHeal 11.00 2010.08.19 -
ClamAV 0.96.2.0-git 2010.08.19 -
Comodo 5786 2010.08.19 -
DrWeb 5.0.2.03300 2010.08.19 -
Emsisoft 5.0.0.37 2010.08.19 -
eSafe 7.0.17.0 2010.08.19 -
eTrust-Vet 36.1.7801 2010.08.19 -
F-Prot 4.6.1.107 2010.08.19 -
F-Secure 9.0.15370.0 2010.08.19 -
Fortinet 4.1.143.0 2010.08.19 -
GData 21 2010.08.19 -
Ikarus T3.1.1.88.0 2010.08.19 -
Jiangmin 13.0.900 2010.08.19 -
Kaspersky 7.0.0.125 2010.08.19 -
McAfee 5.400.0.1158 2010.08.19 -
McAfee-GW-Edition 2010.1B 2010.08.19 -
Microsoft 1.6004 2010.08.19 -
NOD32 5380 2010.08.19 -
Norman 6.05.11 2010.08.19 -
nProtect 2010-08-19.01 2010.08.19 -
Panda 10.0.2.7 2010.08.19 -
PCTools 7.0.3.5 2010.08.19 -
Prevx 3.0 2010.08.19 -
Rising 22.61.03.04 2010.08.19 -
Sophos 4.56.0 2010.08.19 -
Sunbelt 6762 2010.08.19 -
SUPERAntiSpyware 4.40.0.1006 2010.08.19 -
Symantec 20101.1.1.7 2010.08.19 -
TheHacker 6.5.2.1.351 2010.08.19 -
TrendMicro 9.120.0.1004 2010.08.19 -
TrendMicro-HouseCall 9.120.0.1004 2010.08.19 -
ViRobot 2010.8.16.3990 2010.08.19 -
VirusBuster 5.0.27.0 2010.08.19 -
Additional information
Show all
MD5 : 8f0de4fef8201e306f9938b0905ac96a
SHA1 : d2e2915087427be8ea88b4a174c334c578208e78
SHA256: ca7153fe0c037d79fbf7ce0e090d741fb52bccbbbd4ca505ef4849a0c4199f72
ssdeep: 3072:EK5b1edk0bT5ni+lRd4ESGf4Fv5NR2OnCW8DCUck/CJcd+F9UK/r1F2aTwXZg0bQ:EK5bZ
yNi+RS
File size : 135664 bytes
First seen: 2009-10-28 01:12:22
Last seen : 2010-08-19 19:52:10
TrID:
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
sigcheck:
publisher....: Google Inc.
copyright....: Copyright 2007-2009 Google Inc.
product......: Google Update
description..: Google Installer
original name: GoogleUpdate.exe
internal name: Google Update
file version.: 1.2.183.9
comments.....: n/a
signers......: Google Inc
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 1:04 AM 10/14/2009
verified.....: -
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x50CE
timedatestamp....: 0x4AD50798 (Tue Oct 13 23:04:56 2009)
machinetype......: 0x14c (I386)
[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0xD00B, 0xD200, 6.64, a3b9b6e46995b81015b176e0de2b1fa6
.data, 0xF000, 0x2EA8, 0x1200, 2.41, 23bda919485d01c8e04b1f0f502dcff1
.text_DE, 0x12000, 0x318E, 0x3200, 5.36, 7c96b0385c61b0fee276d13b535c06aa
.rsrc, 0x16000, 0xE0F8, 0xE200, 4.22, 1f2935791db10c014809279836295dbb
[[ 3 import(s) ]]
ADVAPI32.dll: GetTokenInformation, OpenProcessToken, RegOpenKeyExW
KERNEL32.dll: GetCurrentProcess, GetProcAddress, SizeofResource, lstrlenW, FindResourceExW, FindResourceW, CloseHandle, FreeLibrary, GetCommandLineW, GetModuleFileNameW, RaiseException, LoadResource, GetModuleHandleW, LockResource, GetFileAttributesExW, VerifyVersionInfoW, LoadLibraryExW, VerSetConditionMask, GetLastError, SetLastError, LocalAlloc, SetStdHandle, SetFilePointer, InterlockedExchange, LoadLibraryA, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, GetVersionExA, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, GetCurrentThreadId, InterlockedDecrement, WideCharToMultiByte, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsA, MultiByteToWideChar, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, VirtualAlloc, RtlUnwind, Sleep, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, GetLocaleInfoA, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, GetConsoleCP, GetConsoleMode, FlushFileBuffers, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA
ole32.dll: CoCreateGuid
VT Community
0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!
VirusTotal Team
et pout le deuxieme
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
resultdns113.exe
Submission date:
2010-08-19 19:57:19 (UTC)
Current status:
queued queued analysing finished
Result:
3/ 42 (7.1%)
VT Community
not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2010.08.19.01 2010.08.19 -
AntiVir 8.2.4.38 2010.08.19 -
Antiy-AVL 2.0.3.7 2010.08.16 -
Authentium 5.2.0.5 2010.08.19 -
Avast 4.8.1351.0 2010.08.19 -
Avast5 5.0.332.0 2010.08.19 -
AVG 9.0.0.851 2010.08.19 -
BitDefender 7.2 2010.08.19 -
CAT-QuickHeal 11.00 2010.08.19 -
ClamAV 0.96.2.0-git 2010.08.19 -
Comodo 5786 2010.08.19 -
DrWeb 5.0.2.03300 2010.08.19 -
Emsisoft 5.0.0.37 2010.08.19 -
eSafe 7.0.17.0 2010.08.19 -
eTrust-Vet 36.1.7801 2010.08.19 -
F-Prot 4.6.1.107 2010.08.19 -
F-Secure 9.0.15370.0 2010.08.19 -
Fortinet 4.1.143.0 2010.08.19 -
GData 21 2010.08.19 -
Ikarus T3.1.1.88.0 2010.08.19 -
Jiangmin 13.0.900 2010.08.19 -
Kaspersky 7.0.0.125 2010.08.19 -
McAfee 5.400.0.1158 2010.08.19 -
McAfee-GW-Edition 2010.1B 2010.08.19 -
Microsoft 1.6004 2010.08.19 BrowserModifier:Win32/Zwangi
NOD32 5380 2010.08.19 -
Norman 6.05.11 2010.08.19 -
nProtect 2010-08-19.01 2010.08.19 -
Panda 10.0.2.7 2010.08.19 Suspicious file
PCTools 7.0.3.5 2010.08.19 -
Prevx 3.0 2010.08.19 Low Risk Adware
Rising 22.61.03.04 2010.08.19 -
Sophos 4.56.0 2010.08.19 -
Sunbelt 6762 2010.08.19 -
SUPERAntiSpyware 4.40.0.1006 2010.08.19 -
Symantec 20101.1.1.7 2010.08.19 -
TheHacker 6.5.2.1.351 2010.08.19 -
TrendMicro 9.120.0.1004 2010.08.19 -
TrendMicro-HouseCall 9.120.0.1004 2010.08.19 -
VBA32 3.12.14.0 2010.08.19 -
ViRobot 2010.8.16.3990 2010.08.19 -
VirusBuster 5.0.27.0 2010.08.19 -
Additional information
Show all
MD5 : c60fd7fd11cbd84ad592303431814cb4
SHA1 : 65f190e0d14794508c42f7661af3d880bab5f6c7
SHA256: 3b8b1bb34733a7bacd99f9bbaaa4155f5792de3b6febafe9671c84cf92ca0418
ssdeep: 1536:+3gqKITX5yi+0MERmFph6WYpm5SmlUBCYSVDNycn:DyJy10YC9HMDN7
File size : 57608 bytes
First seen: 2010-08-19 19:57:19
Last seen : 2010-08-19 19:57:19
TrID:
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: ResultDns.com
UTN-USERFirst-Object
signing date.: 7:06 AM 8/19/2010
verified.....: -
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x5E62
timedatestamp....: 0x4C6CBBBC (Thu Aug 19 05:06:04 2010)
machinetype......: 0x14c (I386)
[[ 3 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x8F46, 0x9000, 6.55, ecdf81b181b2dd1feb9b08b7a7d5642e
.rdata, 0xA000, 0x18DE, 0x2000, 3.96, 65388aa02a36b3b86519fa522c727ebd
.data, 0xC000, 0x958, 0x1000, 1.03, 342e1f4d3bcbc47ffeaee0a3b118ae25
[[ 1 import(s) ]]
KERNEL32.dll: GetProcAddress, LoadLibraryExA, lstrcmpA, CreateFileA, lstrcpyA, lstrlenA, RtlUnwind, RaiseException, GetSystemTimeAsFileTime, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersionExA, HeapAlloc, SetUnhandledExceptionFilter, HeapFree, ExitProcess, TerminateProcess, GetCurrentProcess, WriteFile, GetStdHandle, GetModuleFileNameA, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetLastError, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, IsBadWritePtr, HeapSize, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, GetACP, GetOEMCP, GetCPInfo, IsBadReadPtr, IsBadCodePtr, LoadLibraryA, InterlockedExchange, VirtualQuery, GetLocaleInfoA, VirtualProtect, GetSystemInfo, LCMapStringA, LCMapStringW, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId
Prevx Info:
http://info.prevx.com/aboutprogramtext.asp?PX5=9EFE9CA4087C3A35E13B004CEC656900E46FBE4F
Symantec reputation:Suspicious.Insight
VT Community
0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!
VirusTotal Team
voila les rapports -
ContributeurOk, passons a autre chose, essaye d'utiliser ZHPDiag comme indiqué dans mon premier message mais utilise ce lien pour le telecharger car l'autre ne fonctionne pas (au cas où ZHPDiag ne fonctionne pas aussi essaye le mode sans echec ou OTH)
Ensuite :
¤ Rend toi sur Virus Total
¤ Clique sur "Parcourir..."
¤ Dans la nouvelle fenêtre, dans le champ "Nom du Fichier", copie/colle ceci >>> C:\Program Files\Google\Update\GoogleUpdate.exe <<<
¤ Clique sur "Ouvrir"
¤ De retour sur Virus Total, clique sur "Envoyer le fichier"
¤ Un scan du fichier se fera et les résultat seront proposés sous forme de tableau, copie/colle l'adresse de la page des résultats dans ta prochaine réponse
Et fait de même pour ceci >>> C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe <<<
++
Karel
- 1
- 2