Security.HiJack[ImageFileExecutionOptions]

Post Reply
martinsouli31
Posts: 215
Joined: 04 Dec 2007, 22:59

Security.HiJack[ImageFileExecutionOptions]

Post by martinsouli31 »

bonjour
je viens de passer superantspyware et il a detecté ca cest quoi merci

Security.HiJack[ImageFileExecutionOptions]

(x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TASKMGR.EXE
(x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TASKMGR.EXE#Debugger
SyLvErFoX
Posts: 2039
Joined: 30 Nov 2006, 00:42
Location: Latitude : 45°28′38″ Nord Longitude : 75°42′05″ Ouest

Re: Security.HiJack[ImageFileExecutionOptions]

Post by SyLvErFoX »

Salut, ça semble contradictoire sur le net face à ça... Certains sites disent que c'est un faux positif et d'autre que c'est une infection...

Passez combofix pour voir:

http://www.geekstogo.com/forum/files/fi ... x-by-subs/

Laissez le aller et n'utilisez pas l'ordi pour autre chose durant son scan. :wink:
Jack!!
martinsouli31
Posts: 215
Joined: 04 Dec 2007, 22:59

Re: Security.HiJack[ImageFileExecutionOptions]

Post by martinsouli31 »

cest que jai regarder sur internet et effectivement cest ce que jai vue

ca et apres jai passe mon anti virus nod32

rien. des outils de kaspersky rien. f secure easy clean a trouvé worm generic 255306 puis je vien de le repasse easy clean je voulais te dire le nom exact et la il a en nettoyé 2 worm generic encore le 255306 et 34821

spybot a trouvé W32/Opaserv-O dans c windows qui se trouve etre scrsvr.exe il fait o octets
martinsouli31
Posts: 215
Joined: 04 Dec 2007, 22:59

Re: Security.HiJack[ImageFileExecutionOptions]

Post by martinsouli31 »

la jai passe combo sur jotti resultat http://virusscan.jotti.org/fr/scanresul ... 6d5e30019d

et visscan

VirSCAN.org Scanned Report :
Scanned time : 2011/01/13 19:23:10 (EST)
Scanner results: 11% (4/36) a trouvé un malware !
File Name : ComboFix.exe
File Size : 4154145 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : fc06dedf8b322f1ddcd8bc11432d7ade
SHA1 : a6c37bd38bcd67dcabe70e9a2e5c41cd2613008a
Online report : http://virscan.org/report/8fc8425bbcf95 ... f87a0.html

ClamAV 0.96.5 12514 2011-01-14 1.55 PUA.Tool.Nirsofer.NirCmd Exact

JiangMin 13.0.900 2011.01.13 2011-01-13 7.82 Trojan/Agent.dwsp Exact

Rising 20.0 22.82.03.04 2011-01-13 Trojan.Script.BAT.Agent.cz exact
11.585

VBA32 3.12.14.2 20110113.1010 2011-01-13 15.45 VBS.StartPage.nam (suspicious) heuristic/Suspicious
SyLvErFoX
Posts: 2039
Joined: 30 Nov 2006, 00:42
Location: Latitude : 45°28′38″ Nord Longitude : 75°42′05″ Ouest

Re: Security.HiJack[ImageFileExecutionOptions]

Post by SyLvErFoX »

Ok, postez nous un log de Hijackthis pour voir,

http://free.antivirus.com/hijackthis/

:wink:
Jack!!
martinsouli31
Posts: 215
Joined: 04 Dec 2007, 22:59

Re: Security.HiJack[ImageFileExecutionOptions]

Post by martinsouli31 »

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:50:32, on 2011-01-13
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda USB Vaccine\USBVaccine.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
C:\Program Files\Fichiers communs\Acronis\CDP\afcdpsrv.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Fichiers communs\Iconix\IconixService.exe
c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\PeerBlock\peerblock.exe
C:\Documents and Settings\Administrateur\Mes documents\windows-kb890830-v3.15.exe
c:\09f63df2803e24a71212\mrtstub.exe
C:\WINDOWS\system32\MRT.exe
C:\Documents and Settings\Administrateur\Bureau\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.search.yahoo.com/search?fr=mcafee&p=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = acer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVGLS\Toolbar\IEToolbar.dll
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_44.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVGLS\Toolbar\IEToolbar.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVGLS\Toolbar\IEToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Service Scheduler2 Acronis] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Ajouter à l'Anti-bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_44.dll
O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_44.dll
O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_44.dll
O9 - Extra 'Tools' menuitem: About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_44.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 1493564000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 5566754218
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} (Java Plug-in 1.6.0_15) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ackpbsc - c:\WINDOWS\system32\ackpbsc.dll
O20 - Winlogon Notify: acunlock - c:\Program Files\ActivIdentity\ActivClient\acunlock.dll
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O23 - Service: McAfee Application Installer Cleanup (0207041294810137) (0207041294810137mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\020704~1.EXE (file missing)
O23 - Service: Service Scheduler2 Acronis (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
O23 - Service: Service Acronis Nonstop Backup (afcdpsrv) - Acronis - C:\Program Files\Fichiers communs\Acronis\CDP\afcdpsrv.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Iconix Update Service (IconixService) - Unknown owner - C:\Program Files\Fichiers communs\Iconix\IconixService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe

--
End of file - 7384 bytes
Last edited by martinsouli31 on 14 Jan 2011, 03:13, edited 1 time in total.
SyLvErFoX
Posts: 2039
Joined: 30 Nov 2006, 00:42
Location: Latitude : 45°28′38″ Nord Longitude : 75°42′05″ Ouest

Re: Security.HiJack[ImageFileExecutionOptions]

Post by SyLvErFoX »

Ouf... y a des choses à suprimer, mais je le trouve bizarre ce log là, attendez, j'aimerais avoir l'avis de rikwar la dessus, il va nous le donner surement dans pas long... :mrgreen:

En passant, la prochaine fois collez le log ici, pas en pièce jointe. :wink:
Jack!!
martinsouli31
Posts: 215
Joined: 04 Dec 2007, 22:59

Re: Security.HiJack[ImageFileExecutionOptions]

Post by martinsouli31 »

ok merci
Post Reply