par bernie50 » 04 Jan 2005 20:14
bonsoir,
Voilà ce qu'en dit sophos , postes un log hitjackthis afin de voir si tu as bien les clés et puis fix les clés douteuses le reste fait le à la main.
Troj/Haxdoor-Z is a backdoor Trojan that provides remote attackers with access to the infected computer.
The installation executable for Troj/Haxdoor-Z copies itself to the Windows system folder and drops the following files to the system folder:
i.a3d or ps.a3d, draw32.dll, p2.ini, cm.dll, vdnt32.sys, hm.sys, memlow.sys, wd.sys and klogini.dll (not all of these files will be installed under Windows NT/XP).
i.a3d/ps.a3d, p2.ini and klogini.dll are harmless data files for which there is no detection. mode furtif
On NT-based versions of Windows services are created named memlow and vdnt32 (with display names of "LMMngr" and "MemDRV") to run memlow.sys and vdnt32.sys respectively, creating registry entries under:
HKLM\SYSTEM\CurrentControlSet\Services\memlow\
HKLM\SYSTEM\CurrentControlSet\Services\vdnt32\
The new memlow service has a startup type set to automatic, so that it is activated automatically on startup. vdnt32.sys is configured to be loaded automatically on startup as a system driver.
On NT-based versions of Windows sub-keys of the following new registry entry are created to load draw32.dll on startup and run the "MedManager" export:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\draw32\
Under Windows 95/98/ME one of the following sets of registry entries is created, so that draw32.dll is loaded on startup and the "MedManager" export called:
HKLM\System\CurrentControlSet\control\mprser\
Dllname = draw32.dll
HKLM\System\CurrentControlSet\control\mprser\
Entrypoint = "MedManager"
HKLM\System\CurrentControlSet\control\mprser\
StackSize = 0
HKLM\System\currentcontrolset\control\MPRServices\
TestService\Dllname = draw32.dll
HKLM\System\currentcontrolset\control\MPRServices\
TestService\Entrypoint = "MedManager"
HKLM\System\currentcontrolset\control\MPRServices\
TestService\StackSize = 0
(causing the draw32.dll code to be run under the Mprexe system process.)
The following registry entries are also set:
HKLM\SYSTEM\RAdmin\v2.0\Server\Parameters\DisableTrayIcon = 1
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\
Memory Management\EnforceWriteProtection = 0
HKLM\SYSTEM\CurrentControlSet\Control\Impersonate
HKLM\SYSTEM\CurrentControlSet\Control\StackSize
Troj/Haxdoor-Z attempts to disable certain anti-virus and security related programs and may attempt to prevent its registry entries and files from being deleted.
The Trojan then runs continuously in the background listening for instructions from a remote user.
Sophos © 2004 Sophos Plc. All rights reserved. Legal | Privacy
Il faut vivre vite, car la mort vient tôt - james dean (star de cinéma)
James dean est mort a moins de 30 ans sur une route de californie décapité dans un accident de voiture a plus de 200 kmh, il a mis en quelque sorte sa devise en pratique.