Juste pour signaler la présence du fichier C:\WINDOWS\system32\smss32.exe
Process:
Path: C:\Documents and Settings\Malekal_morte\Local Settings\Temporary Internet Files\Content.IE5\MK0Z9QK6\install_flash_player[1].exe
PID: 888
Information: KFBTW JDktyWAAAa (JDktyWAAAa)
Registry Group: Machine AutoRun
Object:
Registry key: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Registry value: smss32.exe
Type: REG_SZ
Value: C:\WINDOWS\system32\smss32.exe
C:\WINDOWS\system32\smss32.exe charge le fichier HTML qui Hijack le fond d'écran
Process:
Path: C:\WINDOWS\system32\smss32.exe
PID: 1192
Information: KFBTW JDktyWAAAa (JDktyWAAAa)
Registry Group: IE Settings
Object:
Registry key: HKCU\Software\Microsoft\Internet Explorer\Desktop\General
Registry value: Wallpaper
New value:
Type: REG_EXPAND_SZ
Value: %SystemRoot%\system32\warning.html
Previous value:
Type: REG_SZ
Value:
smss32.exe C:\WINDOWS\system32\IS15.exe qui lance Internet Security 2010 :
Parent process:
Path: C:\WINDOWS\system32\IS15.exe
PID: 928
Information: Internet Security (Internet Security)
Child process:
Path: C:\Program Files\InternetSecurity2010\IS2010.exe
Information: Internet Security (Internet Security)
Command line:"C:\Program Files\InternetSecurity2010\IS2010.exe" DELC:\WINDOWS\system32\IS15.exe
Fichiers ajoutés :
c:\WINDOWS\system32\41.exe
Date: 1/20/2010 3:28 AM
Size: 0 bytes
c:\WINDOWS\system32\helper32.dll
Date: 1/20/2010 3:28 AM
Size: 19 968 bytes
c:\WINDOWS\system32\smss32.exe
Date: 1/20/2010 3:27 AM
Size: 25 600 bytes
c:\WINDOWS\system32\warning.html
Date: 1/20/2010 3:27 AM
Size: 2 931 bytes
c:\WINDOWS\system32\winlogon32.exe
Date: 1/20/2010 3:27 AM
Size: 25 600 bytes
c:\Program Files\InternetSecurity2010\IS2010.exe
Date: 1/20/2010 3:28 AM
Size: 1 383 936 bytes
Les lignes HiJackThis :
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon32.exe
O4 - HKLM\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe
O4 - HKCU\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll