Analyse HijackThis

Bonjour a tous, j'y connais pas grand chose dans tout se vocabulaire de la sécurité informatique, mais je suis parvenu à faire une analyse avec HijackThis.
Pourriez vous m'aider à chasser la vilaine petite bete qui m'a gaché ma journée?

Logfile of HijackThis v1.99.1
Scan saved at 17:18:19, on 29/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\inet20099\winlogon.exe
C:\WINDOWS\System32\ati2vid.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\inet20099\socks.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Cacheman\Cacheman.exe
C:\WINDOWS\System32\z11.exe
C:\Program Files\Club-Internet\Lanceur\lanceur.exe
C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = HTTP=proxy.club-internet.fr:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F3 - REG:win.ini: run=C:\WINDOWS\inet20099\winlogon.exe
O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inet20099\3.00.11.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINDOWS\inet20099\socks.exe 20099
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Cacheman] C:\PROGRA~1\Cacheman\Cacheman.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
O4 - HKCU\..\Run: [pro] C:\WINDOWS\System32\z11.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O21 - SSODL: mNRzWY - {10F18BC7-BA5B-216D-6ED6-373E520EC8B5} - C:\WINDOWS\System32\zjf.dll
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Go1iot\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
Configuration: Pentium II, 256mo, XP, connection web à 56k !!!

32 réponses

Résumé de la discussion

Une infection malware sous Windows XP SP1 est discutée, avec des éléments suspects repérés dans HijackThis et des rapports SmitFraudFix, notamment winstall.exe et des entrées de démarrage suspectes. Plusieurs intervenants recommandent d’utiliser SmitFraudFix, d’exécuter en mode sans échec, de supprimer les fichiers et entrées infectées, puis de redémarrer et refaire un log pour vérifier la persistance. Cependant, la discussion met en évidence que winstall.exe réapparaît après nettoyage et que des composants tels que des BHO, des services et des paramètres proxy continuent d’être signalés, compliquant l’éradication. En parallèle, certains messages indiquent des liens vers des outils et expliquent des étapes: télécharger SmitFraudFix.zip, lancer smitfraudfix.cmd, choisir l’option 1, puis redémarrer en mode sans échec et relancer le diagnostic.

Bobot (l’IA à votre service)
  1. Contributeur
    Bonsoir Louison,

    Y a du boulot ! :-)

    Méthode a suivre dans l'ordre...
    ----------------------------------------------------------------------------
    ¤Télécharge ces logiciels:

    1/Spybot S&D 1.4 <<nouvelle version
    http://www.safer-networking.org/fr/index.html

    Démo d utilisation (merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

    Le mettre à jour.

    2/Ad-Aware SE 1.06 <<nouvelle version
    http://www.lavasoftusa.com/software/adaware/
    -Une aide:
    http://www.tutopat.com/viewtopic.php?t=1191
    - installe le patch français, tu pourra le trouver ici:
    http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
    et une petite vidéo ici d'utilisation:(merci a Moe31 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/adawrevid.asf

    Le mettre à jour.

    3/Clean Up 40:
    http://pageperso.aol.fr/balltrap34/CleanUp40.exe
    -aide en image:(merci a Balltrap34)
    http://pageperso.aol.fr/balltrap34/democleanup.htm

    Passes un coup de chacun de ses logiciels

    Puis repost un log Hijackthis.

    Bon courage.

    A+

    1. Un grand merci pour toutes ces infos incognito ;-)
      Je vais tenter de telecharger tout ça avec ma connection 56k ! :-)
      Et je posterai un log Hijackthis
      1. ok! voila ma procedure :
        j'ai installé et fait les mises à jours pour Ad-Aware SE Personal 1.06, Spybot - Search & Destroy 1.4 et CleanUp40...
        Apres avoir désactivé la restauration systeme de windaube, j'ai successivemente executé chacuns de ces programmes en MODE SANS ECHEC.

        Est-ce que ma procedure est bonne? Parce que j'ai tjrs un messsage windows accompagné d'1 croix blanche sur fond rouge dans ma barre de demarrage qui me dit : "your computer is infect"
        Voila mon log HijackThis et un rapport SmitfraudFix

        Logfile of HijackThis v1.99.1
        Scan saved at 23:40:47, on 29/11/2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\System32\atievxx.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\inet20099\winlogon.exe
        C:\WINDOWS\System32\ati2vid.exe
        C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
        C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
        C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
        C:\WINDOWS\inet20099\socks.exe
        C:\WINDOWS\System32\ctfmon.exe
        C:\PROGRA~1\Cacheman\Cacheman.exe
        C:\WINDOWS\System32\z11.exe
        C:\Program Files\Club-Internet\Lanceur\lanceur.exe
        C:\Program Files\Windows NT\Accessoires\WORDPAD.EXE
        C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = HTTP=proxy.club-internet.fr:8080
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        F3 - REG:win.ini: run=C:\WINDOWS\inet20099\winlogon.exe
        O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
        O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
        O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
        O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINDOWS\inet20099\socks.exe 20099
        O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
        O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
        O4 - HKCU\..\Run: [Cacheman] C:\PROGRA~1\Cacheman\Cacheman.exe
        O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
        O4 - HKCU\..\Run: [pro] C:\WINDOWS\System32\z11.exe
        O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
        O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
        O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
        O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
        O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
        O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
        O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
        O21 - SSODL: mNRzWY - {10F18BC7-BA5B-216D-6ED6-373E520EC8B5} - C:\WINDOWS\System32\zjf.dll
        O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Go1iot\LOCALS~1\Temp\hpdj.exe (file missing)
        O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe

        et chez SmitfraudFix

        SmitFraudFix v1.99

        Rapport fait à 23:42:48,81 le 29/11/2005
        Executé à partir de C:\Documents and Settings\Go1iot\Bureau\SmitfraudFix
        OS: Microsoft Windows XP [version 5.1.2600]

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

        C:\winstall.exe PRESENT !

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Go1iot\Application Data

        C:\Documents and Settings\Go1iot\Application Data\Install.dat PRESENT !

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

        merci d'avance pour vos reponses
        1. Bonjour, j'ai toujours les memes problemes. Je crois à cause de winstall.exe que je n'arrive pas à virer. Quelqu'un peut-il m'en dire un peu plus?
          1. Contributeur
            Bonsoir Louison,

            Démarre en mode sans échec :
            Pour cela, tu tapotes la touche F8 dès le début de l allumage du pc sans t arrêter
            Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
            Une fois sur le bureau si il n y a pas toutes les couleurs et autres c est normal !
            (Si F8 ne marche pas utilise la touche F5)

            Vide tes fichiers temps et tempory internet file:
            utilise ceci pour le faire (tu as télécharger avant)
            http://pageperso.aol.fr/balltrap34/CleanUp40.exe

            Ensuite, tu relances smitfraud et tu choisis l'option 2
            tu sauvegardes le log.

            Tu redemarres en mode normal et tu postes le log ici.

            Bon courage.

            A+

            1. Bonjour,
              Après avoir fait la manip ci dessus, j'ai bien cru que c'était bon. Mais au redémarrage en mode normal l'infection est toujours là !

              Voila mon log Smitfraud EN MODE SANS ECHEC apres avoir utilisé CleanUp :

              SmitFraudFix v1.99

              Rapport fait à 11:44:41,40 le 01/12/2005
              Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600]

              »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

              »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

              C:\winstall.exe supprimé
              C:\Documents and Settings\Go1iot\Application Data\Install.dat supprimé

              »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

              Nettoyage terminé.

              »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

              Et voila mon log Smitfraud EN MODE Normal

              SmitFraudFix v1.99

              Rapport fait à 11:48:05,23 le 01/12/2005
              Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600]

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

              C:\winstall.exe PRESENT !

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Go1iot\Application Data

              C:\Documents and Settings\Go1iot\Application Data\Install.dat PRESENT !

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

              »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
              1. Contributeur
                Bonsoir Louison,

                Relances un smitfraud en mode normal et fais l'option N°1 uniquement.

                Postes le resultat ici stp.

                Bon courage.

                A+
                1. Bonsoir Incognito, tout d'abord merci pour tes réponses...
                  Mais j'ai déjà envoyé un log smitfraud en mode normal... juste au dessus ta réponse. Personne n'est parfait lol ;-)
                  Bon, vu que je demarre mon PC en mode selectif grace a msconfig, j'ai viré winstall.exe........ j'espere que ça fonctionnera.... Sinon le pb ne vient pas de install.dat que je retrouve ds le log smitfraud??? J'espere que vous pourrez m'aider

                  A+ encore merci
                  1. Contributeur
                    Bonsoir Louison,

                    Je suis un peu perdu, peux tu refaire un log hijackthis stp.

                    Bon courage.

                    A+

                    1. Contributeur sécurité
                      salut
                      desinstal tous se qui est du fix smitfraud
                      et retelecharge le la version a changer
                      salut
                      telecharge
                      http://siri.urz.free.fr/Fix/SmitfraudFix.zip
                      tu le decompresse tu double clik dessus sur smitfraudfix.cmd et tu choisi l option 1
                      cela vas generer un rapport donne nous le
                      *******
                      redemarre en sans echec

                      relance le et choisi cette fois l option 2 et repond oui a tous
                      redemarre et donne le nouveau rapport
                      *******
                      1. bonjour,
                        Voila les deux rapport smitfraud

                        SmitFraudFix v2.01

                        Rapport fait à 12:12:11,52 le 03/12/2005
                        Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600]

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                        C:\winstall.exe PRESENT !

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

                        C:\WINDOWS\system32\ll.exe PRESENT !

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Go1iot\Application Data

                        C:\Documents and Settings\Go1iot\Application Data\Install.dat PRESENT !

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                        "Source"="About:Home"
                        "SubscribedURL"="About:Home"
                        "FriendlyName"="Ma page d'accueil"

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
                        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                        PUIS EN MODE SANS ECHEC

                        SmitFraudFix v2.01

                        Rapport fait à 12:18:06,27 le 03/12/2005
                        Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600]

                        »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                        »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                        C:\winstall.exe supprimé
                        C:\WINDOWS\system32\ll.exe supprimé
                        C:\Documents and Settings\Go1iot\Application Data\Install.dat supprimé

                        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                        Nettoyage terminé.

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                        Mais au redemarrage winstall est tjrs la, voila le 3e rapport sensiblement identique au premier

                        SmitFraudFix v2.01

                        Rapport fait à 12:27:24,84 le 03/12/2005
                        Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600]

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                        C:\winstall.exe PRESENT !

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Go1iot\Application Data

                        C:\Documents and Settings\Go1iot\Application Data\Install.dat PRESENT !

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
                        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
                        1. voila le log en mode normal... à priori il y a un souci avec install.dat

                          SmitFraudFix v2.01

                          Rapport fait à 18:16:54,65 le 03/12/2005
                          Executé à partir de C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600]

                          »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                          »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                          C:\winstall.exe supprimé
                          Problème suppression C:\Documents and Settings\Go1iot\Application Data\Install.dat

                          »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                          »»»»»»»»»»»»»»»»»»»»»»»» Reboot

                          Problème suppression C:\Documents and Settings\Go1iot\Application Data\Install.dat

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
                          1. Contributeur sécurité
                            oui il y a un truc bizzard
                            cela est supprimer dans lee premier log et ensuite cela reparait et est insuprimable
                            1. Bonjour incognito et Balltrap34
                              voila mon dernier log HijackThis

                              Logfile of HijackThis v1.99.1
                              Scan saved at 16:21:14, on 04/12/2005
                              Platform: Windows XP SP1 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\System32\atievxx.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\inet20099\winlogon.exe
                              C:\WINDOWS\System32\ati2vid.exe
                              C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                              C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
                              C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
                              C:\WINDOWS\inet20099\socks.exe
                              C:\WINDOWS\System32\ctfmon.exe
                              C:\PROGRA~1\Cacheman\Cacheman.exe
                              C:\WINDOWS\System32\z11.exe
                              C:\winstall.exe
                              C:\Program Files\Club-Internet\Lanceur\lanceur.exe
                              C:\Documents and Settings\Go1iot\Mes documents\1 desinfection\HijackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = HTTP=proxy.club-internet.fr:8080
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              F3 - REG:win.ini: run=C:\WINDOWS\inet20099\winlogon.exe
                              O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
                              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                              O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                              O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
                              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
                              O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
                              O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINDOWS\inet20099\socks.exe 20099
                              O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
                              O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                              O4 - HKCU\..\Run: [Cacheman] C:\PROGRA~1\Cacheman\Cacheman.exe
                              O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
                              O4 - HKCU\..\Run: [pro] C:\WINDOWS\System32\z11.exe
                              O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20099\winlogon.exe
                              O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
                              O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
                              O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                              O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                              O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                              O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                              O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{8E5C1E43-BFCC-460A-AEB5-E565231DD5F7}: NameServer = 194.117.200.10 194.117.200.15
                              O21 - SSODL: mNRzWY - {10F18BC7-BA5B-216D-6ED6-373E520EC8B5} - C:\WINDOWS\System32\zjf.dll
                              O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Go1iot\LOCALS~1\Temp\hpdj.exe (file missing)
                              O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
                              O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
                              1. Contributeur
                                Bonsoir Louison,

                                Peux tu faire ceci stp
                                Rend toi sur ce site :
                                http://www.virustotal.com/xhtml/virustotal_en.html
                                Clik sur parcourir
                                Recherche ceci :
                                C:\WINDOWS\inet20099\winlogon.exe

                                Clik send et colle le rapport stp

                                Idem avec ce fichier :
                                C:\WINDOWS\inet20099\socks.exe
                                C:\WINDOWS\System32\z11.exe

                                ça va nous permettre d'y voir plus clair

                                Bon courage.

                                A+
                                1. This is a report processed by VirusTotal on 12/05/2005 at 17:39:12 (CET) after scanning the file "winlogon.exe" file.

                                  Antivirus Version Update Result
                                  AntiVir 6.32.1.63 12.05.2005 TR/Dldr.CWS.11776.4
                                  Avast 4.6.695.0 12.05.2005 no virus found
                                  AVG 718 12.05.2005 Downloader.Generic.KLR
                                  Avira 6.32.1.63 12.05.2005 TR/Dldr.CWS.11776.4
                                  BitDefender 7.2 12.05.2005 Trojan.Downloader.CWS.BP
                                  CAT-QuickHeal 8.00 12.05.2005 TrojanDownloader.CWS.gen
                                  ClamAV devel-20051108 12.05.2005 no virus found
                                  DrWeb 4.33 12.05.2005 Trojan.DownLoader.5443
                                  eTrust-Iris 7.1.194.0 12.04.2005 Win32/CWS.11776!Trojan
                                  eTrust-Vet 11.9.1.0 12.05.2005 Win32.Chopenoz.AL
                                  Fortinet 2.48.0.0 12.05.2005 W32/CWS.ARQ!dldr
                                  F-Prot 3.16c 12.05.2005 could be infected with an unknown virus
                                  Ikarus 0.2.59.0 12.05.2005 Trojan-Downloader.Win32.CWS.gen
                                  Kaspersky 4.0.2.24 12.05.2005 Trojan-Downloader.Win32.CWS.gen
                                  McAfee 4643 12.05.2005 Downloader-ARQ
                                  NOD32v2 1.1311 12.02.2005 a variant of Win32/TrojanDownloader.CWS
                                  Norman 5.70.10 12.05.2005 W32/Malware
                                  Panda 8.02.00 12.05.2005 Adware/CWS.Yexe
                                  Sophos 4.00.0 12.05.2005 Troj/Krepper-S
                                  Symantec 8.0 12.05.2005 no virus found
                                  TheHacker 5.9.1.049 12.05.2005 no virus found
                                  VBA32 3.10.5 12.05.2005 Trojan-Downloader.Win32.CWS.gen

                                  This is a report processed by VirusTotal on 12/05/2005 at 17:43:35 (CET) after scanning the file "socks.exe" file.

                                  Antivirus Version Update Result
                                  AntiVir 6.32.1.63 12.05.2005 TR/Proxy.Small.CF.1
                                  Avast 4.6.695.0 12.05.2005 no virus found
                                  AVG 718 12.05.2005 BackDoor.Generic.USG
                                  Avira 6.32.1.63 12.05.2005 TR/Proxy.Small.CF.1
                                  BitDefender 7.2 12.05.2005 BehavesLike:Win32.Backdoor
                                  CAT-QuickHeal 8.00 12.05.2005 TrojanProxy.Small.cf
                                  ClamAV devel-20051108 12.05.2005 no virus found
                                  DrWeb 4.33 12.05.2005 Trojan.Proxy.556
                                  eTrust-Iris 7.1.194.0 12.04.2005 Win32/Traff.34304!Trojan
                                  eTrust-Vet 11.9.1.0 12.05.2005 Win32.Choprox.D
                                  Fortinet 2.48.0.0 12.05.2005 W32/Small.CF-tr
                                  F-Prot 3.16c 12.05.2005 no virus found
                                  Ikarus 0.2.59.0 12.05.2005 no virus found
                                  Kaspersky 4.0.2.24 12.05.2005 Trojan-Proxy.Win32.Small.cf
                                  McAfee 4643 12.05.2005 no virus found
                                  NOD32v2 1.1311 12.02.2005 probably unknown NewHeur_PE virus
                                  Norman 5.70.10 12.05.2005 W32/Malware
                                  Panda 8.02.00 12.05.2005 Trj/Moli.L
                                  Sophos 4.00.0 12.05.2005 no virus found
                                  Symantec 8.0 12.05.2005 no virus found
                                  TheHacker 5.9.1.049 12.05.2005 no virus found
                                  VBA32 3.10.5 12.05.2005 Trojan.Proxy.556

                                  This is a report processed by VirusTotal on 12/05/2005 at 17:46:32 (CET) after scanning the file "z11.exe" file.

                                  Antivirus Version Update Result
                                  AntiVir 6.32.1.63 12.05.2005 Joke/Renos.W
                                  Avast 4.6.695.0 12.05.2005 Win32:Hoaxalarm-K
                                  AVG 718 12.05.2005 Adware Generic.IDO
                                  Avira 6.32.1.63 12.05.2005 Joke/Renos.W
                                  BitDefender 7.2 12.05.2005 Trojan.FakeAlert.G
                                  CAT-QuickHeal 8.00 12.05.2005 Hoax.Renos.ac (Not a Virus)
                                  ClamAV devel-20051108 12.05.2005 no virus found
                                  DrWeb 4.33 12.05.2005 Trojan.Fakealert
                                  eTrust-Iris 7.1.194.0 12.04.2005 Win32/Oneraw.S!Trojan
                                  eTrust-Vet 11.9.1.0 12.05.2005 Win32.Oneraw.S
                                  Fortinet 2.48.0.0 12.05.2005 W32/Dloader
                                  F-Prot 3.16c 12.05.2005 could be infected with an unknown virus
                                  Ikarus 0.2.59.0 12.05.2005 no virus found
                                  Kaspersky 4.0.2.24 12.05.2005 not-virus:Hoax.Win32.Renos.ac
                                  McAfee 4643 12.05.2005 Downloader-AFH
                                  NOD32v2 1.1311 12.02.2005 a variant of Win32/Adware.SpySheriff
                                  Norman 5.70.10 12.05.2005 no virus found
                                  Panda 8.02.00 12.05.2005 Adware/SpySheriff
                                  Sophos 4.00.0 12.05.2005 no virus found
                                  Symantec 8.0 12.05.2005 no virus found
                                  TheHacker 5.9.1.049 12.05.2005 no virus found
                                  VBA32 3.10.5 12.05.2005 Trojan.Fakealert

                                  NB: J'ai aussi z12.exe z13.exe z14.exe z15.exe z16.exe
                                  This is a report processed by VirusTotal on 12/05/2005 at 17:49:28 (CET) after scanning the file "z12.exe" file.

                                  Antivirus Version Update Result
                                  AntiVir 6.32.1.63 12.05.2005 TR/Dldr.Small.awa.70
                                  Avast 4.6.695.0 12.05.2005 no virus found
                                  AVG 718 12.05.2005 Downloader.Generic.KPC
                                  Avira 6.32.1.63 12.05.2005 TR/Dldr.Small.awa.70
                                  BitDefender 7.2 12.05.2005 Trojan.Downloader.Small.AWA
                                  CAT-QuickHeal 8.00 12.05.2005 TrojanDownloader.Small.awa
                                  ClamAV devel-20051108 12.05.2005 Trojan.Downloader.Small-811
                                  DrWeb 4.33 12.05.2005 Trojan.DownLoader.5653
                                  eTrust-Iris 7.1.194.0 12.04.2005 no virus found
                                  eTrust-Vet 11.9.1.0 12.05.2005 no virus found
                                  Fortinet 2.48.0.0 12.05.2005 W32/Vixup.AWA!dldr
                                  F-Prot 3.16c 12.05.2005 no virus found
                                  Ikarus 0.2.59.0 12.05.2005 no virus found
                                  Kaspersky 4.0.2.24 12.05.2005 Trojan-Downloader.Win32.Small.awa
                                  McAfee 4643 12.05.2005 no virus found
                                  NOD32v2 1.1311 12.02.2005 a variant of Win32/TrojanDownloader.Small.AWA
                                  Norman 5.70.10 12.05.2005 no virus found
                                  Panda 8.02.00 12.05.2005 Adware/CWS.Yexe
                                  Sophos 4.00.0 12.05.2005 Troj/Vixup-Gen
                                  Symantec 8.0 12.05.2005 no virus found
                                  TheHacker 5.9.1.049 12.05.2005 Trojan/Downloader.Small.awa
                                  VBA32 3.10.5 12.05.2005 MalwareScope.Downloader.Small.1
                                  1. Contributeur
                                    salut,

                                    fait la manip de balltrap avec smitfraud tu vas gagner du temps.

                                    Jean
                                    • 1
                                    • 2