Bonjour,
J'ai choppé une saloperie qui a infecté l'exe de firefox.
Si quelqu'un pouvait m'aider,je lui en serais reconnaissant!
Cijoint le log bitdefender et le log hijackthis
Merci les amis!
Voici le log bitdefender:
QuickScan Beta 32-bit v0.9.9.52
-------------------------------
Date de l'analyse : Sat Nov 27 11:08:57 2010
ID de la machine : 4A97BAFF
1 fichier infecté a été détecté !
---------------------------------
C:\Windows\System32\sshnas21.dll --> Trojan.Generic.KDV.74327
--> HKCU\Software\Microsoft\Windows\CurrentVersion\Run\"Metropolis"
--> Processus firefox.exe (2628)
Processus
---------
AcroTray - Adobe Acrobat Distiller help 2560 D:\Adobe Acrobat\Acrobat\acrotray.exe
AntiVir Desktop 2424 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
Catalyst Control Centre 2892 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
Catalyst Control Centre 1816 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
Firefox 2628 C:\Program Files\Mozilla Firefox\firefox.exe
Google Update 2836 C:\Users\Nico\AppData\Local\Google\Update\GoogleUpdate.exe
HD Audio Control Panel 1344 C:\Windows\RtHDVCpl.exe
Java(TM) Platform SE Auto Updater 2 0 2568 C:\Program Files\Common Files\Java\Java Update\jusched.exe
Microsoft® Windows® Operating System 2632 C:\Windows\ehome\ehmsas.exe
Microsoft® Windows® Operating System 2576 C:\Windows\ehome\ehtray.exe
Nero Home 2584 C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
Nero Home 2544 C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
PC Tools Firewall Plus 2408 C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
SM56 Helper Win32 Utility 2060 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
Système d'exploitation Microsoft® Windo 2592 C:\Program Files\Windows Sidebar\sidebar.exe
Système d'exploitation Microsoft® Windo 2784 C:\Program Files\Windows Sidebar\sidebar.exe
Système d'exploitation Microsoft® Windo 2044 C:\Windows\explorer.exe
Système d'exploitation Microsoft® Windo 1984 C:\Windows\System32\dwm.exe
Système d'exploitation Microsoft® Windo 676 C:\Windows\System32\taskeng.exe
Windows Defender 1212 C:\Program Files\Windows Defender\MSASCui.exe
Activité du réseau
------------------
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.101
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.56
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.56
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.56
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.56
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.86
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.56
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.56
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 118.215.4.20
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.93
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 74.125.71.113
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.86
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.86
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.86
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 60.254.131.86
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 122.252.61.115
Processus firefox.exe (2628) connecté sur le port 80 (HTTP) --> 91.199.104.31
Fichiers critiques et Autorun
-----------------------------
AcroTray - Adobe Acrobat Distiller help D:\Adobe Acrobat\Acrobat\acrotray.exe
Adobe Acrobat C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
Adobe Acrobat D:\Adobe Acrobat\Acrobat\Acrobat_sl.exe
Adobe Reader and Acrobat Manager C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
AntiVir Desktop C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
CLIStart.exe c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
Google Update C:\Users\Nico\AppData\Local\Google\Update\GoogleUpdate.exe
HD Audio Control Panel C:\Windows\RtHDVCpl.exe
Java(TM) Platform SE Auto Updater 2 0 C:\Program Files\Common Files\Java\Java Update\jusched.exe
Microsoft® Windows® Operating System C:\Windows\ehome\ehtray.exe
Nero AG NeroCheck C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
Nero Home C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
PC Tools Firewall Plus C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
SM56 Helper Win32 Utility C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
sshnas21.dll C:\Windows\System32\sshnas21.dll
Système d'exploitation Microsoft® Windo C:\Program Files\Windows Sidebar\sidebar.exe
Système d'exploitation Microsoft® Windo C:\Windows\System32\browseui.dll
Système d'exploitation Microsoft® Windo c:\windows\system32\userinit.exe
Windows Defender C:\Program Files\Windows Defender\MSASCui.exe
Windows® Internet Explorer C:\Windows\System32\webcheck.dll
Plugins du navigateur
---------------------
2007 Microsoft Office system C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
AcroIEHelper Library c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
AcroIEHelperShim Library c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
Adobe Acrobat C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
Adobe PDF Toolbar for IE c:\program files\common files\adobe\acrobat\activex\acroiefavclient.dll
Adobe® Flash® Player ActiveX C:\Windows\Downloaded Program Files\CONFLICT.1\FP_AX_CAB_INSTALLER.exe
Adobe® Flash® Player ActiveX C:\Windows\Downloaded Program Files\CONFLICT.2\FP_AX_CAB_INSTALLER.exe
Adobe® Flash® Player ActiveX C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
BitDefender QuickScan C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\1tovo3ve.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
BitDefender QuickScan C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\1tovo3ve.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FlashGot.exe C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\1tovo3ve.default\FlashGot.exe
Google Earth Plugin C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
Google Talk Plugin C:\Users\Nico\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
Google Talk Plugin Video Accelerator C:\Users\Nico\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
Google Update C:\Program Files\Google\Update\1.2.183.27\npGoogleOneClick8.dll
Google Update C:\Users\Nico\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
IE Tab Plug-in C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\1tovo3ve.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
Java Deployment Toolkit 6.0.210.7 C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
Java(TM) Platform SE 6 U21 c:\program files\java\jre6\bin\jp2ssv.dll
Java(TM) Platform SE 6 U21 C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
Ma-Config.com plugin C:\Program Files\ma-config.com\nphardwaredetection.dll
Ma-Config.com plugin C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\1tovo3ve.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
maconfsetup.exe C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\1tovo3ve.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\maconfsetup.exe
Microsoft® Windows Media Player Firefox C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
Microsoft® Windows® Operating System C:\Windows\System32\nlaapi.dll
Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll
Mozilla Default Plug-in C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
nppdf32.DEU C:\Program Files\Mozilla Firefox\plugins\nppdf32.DEU
nppdf32.FRA C:\Program Files\Mozilla Firefox\plugins\nppdf32.FRA
NPSWF32.dll C:\Windows\system32\Macromed\Flash\NPSWF32.dll
Silverlight Plug-In c:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
Système d'exploitation Microsoft® Windo C:\Windows\System32\mswsock.dll
Système d'exploitation Microsoft® Windo C:\Windows\System32\NapiNSP.dll
Système d'exploitation Microsoft® Windo C:\Windows\System32\pnrpnsp.dll
VLC Multimedia Plug-in C:\Program Files\VideoLAN\VLC\npvlc.dll
Windows Presentation Foundation c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
Windows® Internet Explorer C:\Windows\System32\ieframe.dll
Analyse
-------
Aucun fichier téléchargé vers le serveur.
Analyse terminée - la communication a duré 19 secondes
Trafic total - 0.06 Mo envoyés, 637.47 Ko reçus
1259 fichiers et modules analysés - 85 seconds
==============================================================================
Voici le log hijacthis:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Adobe Acrobat\Acrobat\acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Nico\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\rundll32.exe
C:\Users\Nico\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "D:\Adobe Acrobat\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "D:\Adobe Acrobat\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\SideBar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Nico\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Metropolis] rundll32.exe C:\Windows\system32\sshnas21.dll,GetHandle
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Ajouter à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service Google Update (gupdate1c98eb0c45c921f) (gupdate1c98eb0c45c921f) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
