Security-X

Forum Security-X => Désinfections => Discussion démarrée par: anneb le novembre 10, 2014, 20:54:29

Titre: infection par iTunesHelper.vbe
Posté par: anneb le novembre 10, 2014, 20:54:29
Bonsoir,

Je pense que ma clef usb a été infectée par un virus i-TunesHelper.vbe, c'est en tout cas ce que signale l'antivirus des ordinateurs de mon lycée.
Je l'ai passée à Norton Power Eraser, mais rien n'a été détecté, ce que je trouve étrange.
Des présentations PPT ont disparu de ma clef USB.
Quelqu'un pourrait-il m'indiquer la démarche à suivre?

Je suis sous XP pro, avec Norton comme anti virus.
merci d'avance

Anneb
Titre: Re : infection par iTunesHelper.vbe
Posté par: nicoolas le novembre 11, 2014, 11:03:56
Bonjour,

Nous allons tout d'abord faire un premier diagnostic.


FRST :

Sous IE9, IE10 ou IE11, le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même

---------------------------------------------------------------------------------------------

USBFix - Recherche :

Tutoriel d'utilisation USBFix en images (http://forum.security-x.fr/tutoriels-317/tutoriel-usbfix-11888/)

---------------------------------------------------------------------------------------------

Sont attendus les rapports :
FRST.txt et Addition.txt
USBFix - Recherche

Tous les rapports doivent être hébergés sur ce site d'hébergement de fichiers (http://security-x.fr/up/) et tu indiques les liens obtenus dans ta réponse -> Aide à l'utilisation (http://forum.security-x.fr/cours-et-tutoriels-322/(tutoriel)-impression-d%27ecran-et-hebergement-de-rapport/msg60884/#msg60884)
Titre: Re : infection par iTunesHelper.vbe
Posté par: moulaye le novembre 17, 2014, 18:25:00
############################## | UsbFix V 7.803 | [Recherche]

Utilisateur: moulaye (Administrateur) # MOULAYE-8B08994
Mis à jour le 17/11/2014 par El Desaparecido - SosVirus
Lancé à 01:36:14 | 17/11/2014

Site Web : http://www.usbfix.net/ (http://www.usbfix.net/)
Changelog : http://www.usbfix.net/maj/ (http://www.usbfix.net/maj/)
Assistance : http://www.sosvirus.net/forum-virus-securite.html (http://www.sosvirus.net/forum-virus-securite.html)
Upload Malware : http://www.sosvirus.net/upload_malware.php (http://www.sosvirus.net/upload_malware.php)
Détection en Live : http://comment-supprimer.fr/ (http://comment-supprimer.fr/)
Contact : http://www.usbfix.net/contact/ (http://www.usbfix.net/contact/)

################## | System information |

CPU: Intel(R) Pentium(R) M processor 1.60GHz
RAM -> [Total : 767 Mo | Free : 69 Mo]
Boot: Normal boot

OS: Microsoft Windows XP (5.1.2600 32-Bit) Service Pack 3
WB: Internet Explorer : 6.00.2900.5512

################## | Security Information |

FW: Windows Firewall [(!) Désactivé]
SC: Security Center [Actif]
WU: Windows Update [Actif]

################## | Disk Information |

C:\ (%SystemDrive%) -> Disque fixe # 34 Go (28 Go libre(s) - 83%) [] # NTFS
D:\ -> Disque fixe # 41 Go (33 Go libre(s) - 82%) [] # NTFS
G:\ -> Disque amovible # 4 Go (191 Mo libre(s) - 5%) [BLACKBERRY1] # FAT32

################## | Regedit Run |

F2 - HKLM\..\Winlogon : [Shell] Explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] C:\WINDOWS\system32\userinit.exe,
04 - HKCU\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
04 - HKCU\..\Run : [DrvUpdater] C:\Documents and Settings\moulaye\Application Data\DRPSu\DrvUpdater.exe
04 - HKCU\..\Run : [uTorrent] "C:\Documents and Settings\moulaye\Application Data\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKCU\..\Run : [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
04 - HKCU\..\Run : [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
04 - HKCU\..\Run : [bin_16347694874825 (3)] wscript.exe //B "C:\Documents and Settings\moulaye\Application Data\bin_16347694874825 (3).vbe"
04 - HKLM\..\Run : [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe"
04 - HKLM\..\Run : [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
04 - HKLM\..\Run : [bin_16347694874825 (3)] wscript.exe //B "C:\Documents and Settings\moulaye\Application Data\bin_16347694874825 (3).vbe"
04 - HKU\S-1-5-19\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-20\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-21-343818398-920026266-1060284298-1003\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
04 - HKU\S-1-5-21-343818398-920026266-1060284298-1003\..\Run : [DrvUpdater] C:\Documents and Settings\moulaye\Application Data\DRPSu\DrvUpdater.exe
04 - HKU\S-1-5-21-343818398-920026266-1060284298-1003\..\Run : [uTorrent] "C:\Documents and Settings\moulaye\Application Data\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKU\S-1-5-21-343818398-920026266-1060284298-1003\..\Run : [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-21-343818398-920026266-1060284298-1003\..\Run : [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
04 - HKU\S-1-5-21-343818398-920026266-1060284298-1003\..\Run : [bin_16347694874825 (3)] wscript.exe //B "C:\Documents and Settings\moulaye\Application Data\bin_16347694874825 (3).vbe"
04 - HKU\S-1-5-18\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

################## | Recherche générique |

Présent! C:\Documents and Settings\moulaye\Application Data\bin_16347694874825 (3).vbe
Présent! C:\Documents and Settings\moulaye\Menu Démarrer\Programmes\Démarrage\bin_16347694874825 (3).vbe
Présent! G:\bin_16347694874825 (3).vbe
Présent! G:\gossip.lnk
Présent! G:\Resident Evil 2-Apocalypse.lnk
Présent! G:\applications.lnk
Présent! G:\dev.lnk
Présent! G:\system.lnk
Présent! G:\appdata.lnk
Présent! G:\tmp.lnk
Présent! G:\home.lnk
Présent! G:\BlackBerry.lnk
Présent! G:\BBThumbs.lnk

################## | Registre |

Présent! HKU\S-1-5-21-343818398-920026266-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Run|bin_16347694874825 (3)
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|bin_16347694874825 (3)
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|bin_16347694874825 (3)

################## | UsbFix - Information |

Info : Comment supprimer l'infection des raccourcis sur USB ? (Video) (https://www.youtube.com/watch?v=vUZYYASd7FE)
Info : L'infection des raccourcis USB, c'est quoi ? (http://www.usbfix.net/2014/10/supprimer-virus-raccourcis-usb/)
Détection en Live : http://comment-supprimer.fr/ (http://comment-supprimer.fr/)

################## | Hijack |

Hijacked! [SHD] G:\applications
Hijacked! [SHD] G:\dev
Hijacked! [SHD] G:\appdata
Hijacked! [SHD] G:\tmp
Hijacked! [SHD] G:\home
Hijacked! [SHD] G:\BlackBerry
Hijacked! [SH] G:\BBThumbs.dat
Hijacked! [SH] G:\gossip.girl.S05E08.retour.aux.sources.avi
Hijacked! [SH] G:\Gossip.Girl.S05E06.FRENCH.LD.DVDRip.XviD-MiND.avi
Hijacked! [SH] G:\Gossip.girl.S05E07.la.mascarade.avi
Hijacked! [SH] G:\Resident Evil 2-Apocalypse.avi
Hijacked! [SH] G:\bin_16347694874825 (3).vbe

################## | E.O.F | http://www.sosvirus.net/ (http://www.sosvirus.net/) | http://www.usbfix.net/ (http://www.usbfix.net/) |
Titre: Re : infection par iTunesHelper.vbe
Posté par: chantal11 le novembre 17, 2014, 19:00:45
Bonjour,

@ moulaye : Pour une prise en charge, merci d'ouvrir ton propre sujet.
Un seul sujet par utilisateur et par PC, comme stipulé dans les règles du forum.

D'autre part les règles élémentaires de courtoisie sont appréciées sur notre forum  ;)