Infecté par I-worm/brontok.C

Fermé
bonjour,mon pc est infecter par ce virus et je ne sais comment m'en debarasser,j'ai scanner et formater,le disque dur,rien...
j'aimerais connaitre une procédure sur contre ce ver...!
merci à l'avance.
Configuration: windows xp professionnel 2004

8 réponses

  1. Modérateur
    Salut

    suis cette procedure stp :

    virus methode preliminaire de desinfection version fr

    ++
    0
    1. Bonjour,
      J'ai lu le message de braxx, car mon ordi est infecté par worm_rontkbr.gen, j'ai essayé d'appliquer la solution préconisée par green day, mais le probleme est que le PC (ss windows XP pro) ne fait que redemarrer dès que j'essaie une application telle que Hijacthis ou bien procexp.exe (préconisé par trend micro) ou bien m^me AVG anti machin, il m'a aussi mis un message d'erreur comme quoi winlogon.exe devait s'arrêter car il avait rencontré un probleme. Bref j'ai les outils pour éradiquer le virus mais je n'ai pas le temps de les utiliser, le PC s'eteint.

      Merci pour votre aide
      0
      1. Modérateur
        Salut

        essaye de lancer avg en mode sans echec : pour cela redemarre en tapotant sur la touche F8 ( ou F5)

        @+
        0
        1. Hello,

          Je voulais savoir par rapport à ta réponse si on pouvait aller sur internet en mode sans échec, car je l'ai lu qq part sur le net que ce n'était pas possible. Comme je n'ai pas AVG mais F secure qui a été nul sur ce coup là d'ailleurs, je suis obligée de scanner en ligne ou de télécharger.

          Merci pour ta réponse
          0
      2. Modérateur
        re

        télécharge le en mode normal et scan en mode sans echec

        ( oui, en mode sans echec : pas de net ! )

        ++
        0
        1. Bon ben alors cé pas possible ! l'ordi s'éteint et redémarre dès que je vais sur le site d'AVG et pareil pour les autres sites d'antivirus ou d'utilitaires de nettoyage ou de désinfection ! Rien à Faire !

          Je crois que je vais être obligée de formater !!! euhhh tu pourrais m'expliquer comment on fait ?

          J'ai un HP pavilion, et les disques que j'ai créée moi même à partir de l'ordi. Mais on fait comment pour démarrer à partir du CD ?
          0
      3. Modérateur
        Salut

        tu peux pas le télécharger à partir d'un autre PC ???

        sinon, pour booter sur le CD, regarde par là :

        http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/PC/tutoriel-modifier-sequence-sujet_27442_1.htm

        pour formater :

        formatage formater un disque dur

        @+
        0
        1. Hello Green Day et merci bcp pour ton aide. J'ai téléchargé a partir d'un autre PC AVAST, ya que ça qui fonctionnait, et je l'ai executé au démarrage du portable via une clef USB. Et ben je crois que ça a fonctionné. Sauf si je me trompe l'antivirus n'a pas pu supprimé les fichiers infectés par win32 : BRONTOK I, mais les a mis en 40ene
          , ce sont tous des fichiers local setting sauf qq fichiers .exe comme C:\windows\kesenjangansosial.exe. A chaque démarrage, il me le réclame . Ca sert à quoi ce fichier ? Est ce qu'il faut supprimer les fichiers qui sont en 40ene ? J'ai fait un scan avec hijack this, dont voici le résultat, ça dit quoi ? En tout cas merci pour ton aide précieuse je vais éviter le formatage je crois !

          Logfile of HijackThis v1.99.1
          Scan saved at 22:03:31, on 15/11/2006
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\LEXBCES.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\LEXPPS.EXE
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
          C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
          C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
          C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\F-Secure\Common\FSMA32.EXE
          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          C:\Program Files\F-Secure\Common\FSMB32.EXE
          C:\Program Files\F-Secure\Common\FCH32.EXE
          C:\Program Files\F-Secure\Common\FAMEH32.EXE
          C:\Program Files\F-Secure\Common\FNRB32.EXE
          C:\Program Files\F-Secure\Common\FIH32.EXE
          C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.exe
          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\HP\QuickPlay\QPService.exe
          C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
          C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
          C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
          C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
          C:\Program Files\F-Secure\Common\FSM32.EXE
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
          C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
          C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Documents and Settings\BERTHOU Claire\Bureau\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
          O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
          O1 - Hosts: "http://www.w3.org/TR/html4/loose.dtd">
          O1 - Hosts: <html>
          O1 - Hosts: <head>
          O1 - Hosts: <script LANGUAGE="JavaScript">
          O1 - Hosts: <!--
          O1 - Hosts: if (window != top)
          O1 - Hosts: top.location.href = location.href;
          O1 - Hosts: // -->
          O1 - Hosts: </script>
          O1 - Hosts: <title>Site Unavailable</title>
          O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
          O1 - Hosts: <style type="text/css">
          O1 - Hosts: body{text-align:center;}
          O1 - Hosts: .geohead {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;width:750px;margin:10px 0 10px 0;height:35px;}
          O1 - Hosts: .geohead #geologo {width:270px;display:block; float:left; }
          O1 - Hosts: .geohead #rightside {width:480px;display:block; float:right;border-bottom:1px solid #999999; height:27px;}
          O1 - Hosts: .geohead #rightside #welcome {width:50%;display:block; float:left; text-align:left;}
          O1 - Hosts: .geohead #rightside #wlinks {width:50%;display:block; float:right; text-align:right;}
          O1 - Hosts: .ftr { margin:0px; color:#404040; font:x-small Arial,sans-serif; text-align:center; width:750px;}
          O1 - Hosts: .bodywrap{display:block;height:470px;}
          O1 - Hosts: .bodycnt{width:510px; display:block; float:left; background-color:#EEE9F5; height:auto; text-align:left; font-family:Arial, Helvetica, sans-serif;font-size:13px; color:#000000; padding:20px 20px 35px 20px;}
          O1 - Hosts: .title { font-family:Arial, Helvetica, sans-serif; font-weight:bold; font-size:24px; color:#7C56A9}
          O1 - Hosts: .adcnt{width:172px; display:block; float:right; text-align:left;cursor:pointer;cursor:hand;}
          O1 - Hosts: .adcnt td {text-align:left;}
          O1 - Hosts: .adsubt{font-size:10px; font-family:verdana; font-weight:bold; color:#b4b4b4; cursor:default;margin-top:5px;}
          O1 - Hosts: .ybadge { font-family: Verdana, Arial, Helvetica, sans-serif; font-size:10px; color: #666666; margin-top:10px;}
          O1 - Hosts: .ybadge img {margin-top:6px;}
          O1 - Hosts: .adtable {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;border: 1px solid #d6dbe7; background-color:#eff7ff; padding:3px; margin-bottom:10px; width:172px;}
          O1 - Hosts: .adttl{font-weight:bold;margin-bottom:3px;}
          O1 - Hosts: .addescr{color:#6b6b6b; margin-bottom:3px;}
          O1 - Hosts: .adlink a {color:#008200; text-decoration:none;}
          O1 - Hosts: </style>
          O1 - Hosts: </head>
          O1 - Hosts: <body>
          O1 - Hosts: <!-- following code added by server. PLEASE REMOVE -->
          O1 - Hosts: <!-- preceding code added by server. PLEASE REMOVE -->
          O1 - Hosts: <div id="maincnt">
          O1 - Hosts: <div class="geohead"><div id="geologo"><a href="https://smallbusiness.yahoo.com/"><img height=33 alt="Yahoo! GeoCities" src="http://us.i1.yimg.com/us.yimg.com/i/us/nt/ma/ma_geo_1.gif" width=259 border=0></a></div>
          O1 - Hosts: <div id="rightside"><div id="wlinks"><a href="https://smallbusiness.yahoo.com/">GeoCities Home</a> - <a href="https://fr.yahoo.com/?p=us">Yahoo!</a> - <a href="https://help.yahoo.com/kb/account">Help</a></div>
          O1 - Hosts: </div></div>
          O1 - Hosts: <div class="bodywrap">
          O1 - Hosts: <div class="bodycnt">
          O1 - Hosts: <div class="title">Sorry, this GeoCities site is currently unavailable.</div>
          O1 - Hosts: <p>The GeoCities web site you were trying to view has temporarily exceeded its data transfer limit. Please try again later. </p>
          O1 - Hosts: <p>Are you the site owner?
          O1 - Hosts: Avoid service interruptions in the future by increasing your data transfer limit!
          O1 - Hosts: <a href="https://help.yahoo.com/kb/account" target="_blank">Find out how.</a> </p>
          O1 - Hosts: <p><a href="https://help.yahoo.com/kb/account" target="_blank">Learn more about data transfer.</a></p>
          O1 - Hosts: </div>
          O1 - Hosts: <div class="adcnt">
          O1 - Hosts: <a target="_top" href="https://smallbusiness.yahoo.com/"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/smbiz/b/geo_mast_small2.gif" alt="Yahoo! GeoCities" border="0" height="15" hspace="0" vspace="0" width="141"></a>
          O1 - Hosts: <div class="adsubt">SPONSORED LINKS</div>
          O1 - Hosts: <!--<table width="172" border="0" bgcolor="#FFFFFF" class="adtable"><tr><td align=left>-->
          O1 - Hosts: <div class="adtable">
          O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27166/*https://smallbusiness.yahoo.com/hosting" target="_blank">Yahoo! Web Hosting<br>
          O1 - Hosts: $25 Setup Waived</a></div>
          O1 - Hosts: <div class="addescr" title="Reliable plans include domain & 24x7 support.">Reliable plans include domain & 24x7 support.</div>
          O1 - Hosts: <div class="adlink" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27166/*https://smallbusiness.yahoo.com/hosting" target="_blank">webhosting.yahoo.com</a></div>
          O1 - Hosts: </div>
          O1 - Hosts: <div class="adtable">
          O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27176/*https://smallbusiness.yahoo.com/domains" target="_blank">Domain Names from Yahoo! only $9.95/yr</a></div>
          O1 - Hosts: <div class="addescr" title="Includes starter web page, email & domain forwarding, 24x7 support.">Includes starter web page, email & domain forwarding, 24x7 support.</div>
          O1 - Hosts: <div class="adlink" title="Includes starter web page, email & domain forwarding, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27176/*https://smallbusiness.yahoo.com/domains" target="_blank">domains.yahoo.com</a></div>
          O1 - Hosts: </div>
          O1 - Hosts: <div class="adtable">
          O1 - Hosts: <div class="adttl" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27184/*https://smallbusiness.yahoo.com/mail" target="_blank">Yahoo! Business Email<br> Domain Included</a></div>
          O1 - Hosts: <div class="addescr" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.">Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.</div>
          O1 - Hosts: <div class="adlink" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27184/*https://smallbusiness.yahoo.com/mail" target="_blank">smallbusiness.yahoo.com</a></div>
          O1 - Hosts: </div>
          O1 - Hosts: <div class="adtable">
          O1 - Hosts: <div class="adttl" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=/27190/*https://smallbusiness.yahoo.com/stores" target="_blank">Ecommerce from Yahoo!<br> 1 Month Free</a></div>
          O1 - Hosts: <div class="addescr" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support.">$50 setup fee waived. A reliable ecommerce plan, 24x7 support.</div>
          O1 - Hosts: <div class="adlink" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=/27190/*https://smallbusiness.yahoo.com/stores" target="_blank">smallbusiness.yahoo.com</a></div>
          O1 - Hosts: </div>
          O1 - Hosts: <div class="ybadge">
          O1 - Hosts: Get your own web site at <br><a target="_top" href="https://smallbusiness.yahoo.com/">Yahoo! GeoCities</a>
          O1 - Hosts: <a href="https://smallbusiness.yahoo.com/hosting" target="_top"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/wh/gr/badge_hostedby_purp_2.gif" alt="Hosted by Yahoo! Web Hosting" align="middle" border="0" height="31" width="88"></a>
          O1 - Hosts: </div>
          O1 - Hosts: </div>
          O1 - Hosts: </div>
          O1 - Hosts: <div class=ftr>
          O1 - Hosts: <hr size=1 width=100%>
          O1 - Hosts: Copyright ©
          O1 - Hosts: 2005 Yahoo! Inc. All rights reserved<br>
          O1 - Hosts: <a href="https://www.verizonmedia.com/policies/">Privacy Policy</a>
          O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Copyright Policy</a>
          O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Guidelines</a>
          O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Terms of Service</a>
          O1 - Hosts: - <a href="https://help.yahoo.com/kb/account">Help</a>
          O1 - Hosts: </div>
          O1 - Hosts: </div>
          O1 - Hosts: </body>
          O1 - Hosts: </html>
          O1 - Hosts: <!-- text below generated by server. PLEASE REMOVE --></object></layer></div></span></style></noscript></table></script></applet>
          O1 - Hosts: <IMG SRC="http://geo.yahoo.com/serv?s=19190039&t=1163319699&f=us-w91" ALT=1 WIDTH=1 HEIGHT=1>
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
          O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
          O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
          O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
          O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
          O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
          O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
          O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
          O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
          O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
          O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
          O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
          O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe
          O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
          O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
          O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
          O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          0
      4. Modérateur
        re

        ok, c'est pas mal infecté tout ça !

        Ouvre le fichier "C:\WINDOWS\system32\drivers\etc\hosts" avec le bloc note, effaces tout son contenu et colles à la place le texte suivant (en gras) :

        # Copyright (c) 1993-1999 Microsoft Corp.
        #
        # Ceci est un exemple de fichier HOSTS utilisé par Microsoft TCP/IP
        # pour Windows.
        #
        # Ce fichier contient les correspondances des adresses IP aux noms d'hôtes.
        # Chaque entrée doit être sur une ligne propre. L'adresse IP doit être placée
        # dans la première colonne, suivie par le nom d'hôte correspondant. L'adresse
        # IP et le nom d'hôte doivent être séparés par au moins un espace.
        #
        # De plus, des commentaires (tels que celui-ci) peuvent être insérés sur des
        # lignes propres ou après le nom d'ordinateur. Ils sont indiqué par le
        # symbole '#'.
        #
        # Par exemple :
        #
        # 102.54.94.97 rhino.acme.com # serveur source
        # 38.25.63.10 x.acme.com # hôte client x

        127.0.0.1 localhost


        fais "fichier" > "enregistrer", fermes tout et redémarres ton pc
        refais un "hijackthis" et postes le nv rapport avec le résultat pour ton pb initial

        ensuite, esseye de télécharge avg, et lance le scan en mode sans echec

        tiens nous au courant, bon courage,@+

        **En vérité, le chemin importe peu, la volonté d'arriver suffit à tout ( A.Camus ) **
        0
        1. Contributeur sécurité
          bonsoir bertha, green day,

          pour avancer un peu,

          Télécharge Hoster

          http://www.funkytoad.com/download/hoster.zip

          Ensuite, tu le dézippes sur ton bureau.

          Lance Hoster - Toadbee et clique sur " Restore original Hosts"

          a+
          0
          1. Modérateur
            Salut Did ;-)

            on a changé de poste !

            infecte par i worm brontok c#2006 11 15%2023%3A35%3A16

            ton aide est la bienvenue !

            @+
            0
            1. Bonjour Green Day,
              Hier j'ai résolu le problème
              grace à toi et did, mais il parait qu'il reste qq infections, voici mon dernier post. Peux tu m'éclairer ?
              Merci mille fois.

              Logfile of HijackThis v1.99.1
              Scan saved at 00:31:06, on 16/11/2006
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\LEXBCES.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\LEXPPS.EXE
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
              C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
              C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
              C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.exe
              C:\Program Files\F-Secure\Common\FSMA32.EXE
              C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
              C:\Program Files\F-Secure\Common\FSMB32.EXE
              C:\Program Files\F-Secure\Common\FCH32.EXE
              C:\Program Files\F-Secure\Common\FAMEH32.EXE
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\F-Secure\Common\FNRB32.EXE
              C:\Program Files\F-Secure\Common\FIH32.EXE
              C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
              C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Program Files\HP\QuickPlay\QPService.exe
              C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
              C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
              C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
              C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
              C:\Program Files\F-Secure\Common\FSM32.EXE
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
              C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
              C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
              C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Documents and Settings\BERTHOU Claire\Bureau\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
              O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
              O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
              O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
              O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
              O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
              O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
              O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
              O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
              O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
              O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
              O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
              O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
              O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
              O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
              O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
              O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
              O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe
              O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
              O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
              O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
              O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              [ Continuer la discussion ][ Répondre à bertha ][ Autres messages de bertha ]

              < 5 > did71 (16/11/2006 à 00:44)

              re,

              oui c'est mieux!

              il reste des infections!

              green va les virer!

              a+
              0