voici le résultat du scan kaprsky :
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Monday, August 22, 2005 15:04:50
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 22/08/2005
Kaspersky Anti-Virus database records: 136487
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - Folders:
C:\WINDOWS\system32\
Scan Statistics:
Total number of scanned objects: 5256
Number of viruses found: 4
Number of infected objects: 39
Number of suspicious objects: 0
Duration of the scan process: 300 sec
Infected Object Name - Virus Name
C:\WINDOWS\system32\drivers\etc\hosts Infected: Trojan.Win32.Qhost
C:\WINDOWS\system32\hpdriver.V00sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V01sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V02sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V03sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V04sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V05sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V06sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V07sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V08sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V09sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V10sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V11sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V14sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V16sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V18sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V19sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V20sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V21sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V22sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V23sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V24sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V25sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V26sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V27sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V28sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.V32sys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\hpdriver.Vsys Infected: Rootkit.Win32.Agent.ae
C:\WINDOWS\system32\i Infected: Trojan-Downloader.BAT.Ftp.ab
C:\WINDOWS\system32\o Infected: Trojan-Downloader.BAT.Ftp.ab
C:\WINDOWS\system32\setup_01828.exe Infected: Backdoor.Win32.SdBot.aad
C:\WINDOWS\system32\setup_01837.exe Infected: Backdoor.Win32.SdBot.aad
C:\WINDOWS\system32\setup_07086.exe Infected: Backdoor.Win32.SdBot.aad
C:\WINDOWS\system32\setup_37803.exe Infected: Backdoor.Win32.SdBot.aad
C:\WINDOWS\system32\setup_50772.exe Infected: Backdoor.Win32.SdBot.aad
C:\WINDOWS\system32\setup_71213.exe Infected: Backdoor.Win32.SdBot.aad
C:\WINDOWS\system32\setup_78267.exe Infected: Backdoor.Win32.SdBot.aad
C:\WINDOWS\system32\setup_81351.exe Infected: Backdoor.Win32.SdBot.aad
C:\WINDOWS\system32\setup_84852.exe Infected: Backdoor.Win32.SdBot.aad
Scan process completed.
et voila le contenu de hijacthis :
Logfile of HijackThis v1.99.1
Scan saved at 15:08:38, on 22/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\System32\carpserv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Media Gateway\MediaGateway.exe
C:\windows\msbb.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_SICN03.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Propriétaire\Local Settings\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe
C:\WINDOWS\ntfsprotect.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = France Télécom Câble
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\windows\msbbhook.dll
O2 - BHO: SponsorAdulto Class - {511F9316-771B-4953-A268-1C36DA667FE9} - C:\WINDOWS\Downloaded Program Files\sponsoradulto.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Removecpl] removecpl.exe
O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [msbb] c:\windows\msbb.exe
O4 - HKLM\..\Run: [ufar] C:\WINDOWS\ufar.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_file.php?bt=ie&p=d8a71c41b1417e6bc8076faef53b88227c2b7c1f1eda8bc15ef2ddf450c61f2b25b5b75615e0f8348ae2dc877d0b70fc9051e923601f7e3f0663710745773b53:391c802b39acc695ee676fd4c28c535f
O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} (SponsorAdulto Class) -
http://ip.sponsoradulto.com/cab/3/fr/SysWebTelecomInt.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124554031743
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NTFSprotect (ntfsdiscman) - Unknown owner - C:\WINDOWS\ntfsprotect.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
c'est plus grave que je pensais
J'ai vu que tu as su répondre pour un cheval de troie un peu similaire au mien donc je te sollicite.
J'ai été infecté par un rootkit : processus cachés malware: win32:DNS changer.UX. est ce que tu peux me conseiller quelques choses. merci par avance.
VIrginie