Virus HACKTOOL

Résolu
Bonjour,

Comme indiqué dans le titre, je suis infecté par le virus Hacktool. Norton me le détecte à chaque démarrage dans le fichier c:\WINDOWS\System32\drivers\klif.sys, mais impossible de le supprimer.
De plus ce virus fait planter norton à chaque détection et il rend mes fichiers cachés invisibles (je suppose que d'autre virus l'accompagne).
J'ai déjà parcouru plusieurs posts à ce sujet, c'est pour ca que je vous joint mon log Hijack mais je suis inccapable de le déchiffrer. Donc j'aurais besoin de votre aide pour résoudre ce problème et supprimer ce fichu virus. Je vous en serais très reconnaissant.

Merci d'avance !

Mon log Hijack en mode de démarrage normal :

Logfile of HijackThis v1.99.1
Scan saved at 22:09:49, on 12/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec\Ghost\ngctw32.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\expiorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Symantec AntiVirus\vpc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\AhnRpta.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Contrôle\Bureau\hijackthis_199\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.univ-lyon1.fr/gogole.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=iutb-proxy:8080;http=iutb-proxy:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = univ-lyon1.fr;<local>;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [NGClient] C:\Program Files\Symantec\Ghost\ngctw32.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [vamsoft] C:\WINDOWS\system32\vamsoft.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=https://iut.univ-lyon1.fr/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://antivirus-france.com/erreur-404/
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{FEC5E937-F2D5-498B-82B4-263AB5F593AC}: NameServer = 192.168.0.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Agent client Symantec Ghost Win32 (NGClient) - Symantec Corporation - C:\Program Files\Symantec\Ghost\ngctw32.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: PURPSPT - Unknown owner - C:\DOCUME~1\CONTRL~1\LOCALS~1\Temp\PURPSPT.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WKXPFAO - Sysinternals - www.sysinternals.com - C:\DOCUME~1\CONTRL~1\LOCALS~1\Temp\WKXPFAO.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: XIUPTRZCPJVSDPN - Sysinternals - www.sysinternals.com - C:\DOCUME~1\CONTRL~1\LOCALS~1\Temp\XIUPTRZCPJVSDPN.exe
O23 - Service: YZZCAH - Unknown owner - C:\DOCUME~1\CONTRL~1\LOCALS~1\Temp\YZZCAH.exe (file missing)

87 réponses

Résumé de la discussion

Une infection par le virus Hacktool est détectée à chaque démarrage dans le fichier c:\WINDOWS\System32\drivers\klif.sys, Norton échoue à le supprimer et les fichiers semblent devenir invisibles, compliquant la remise en ordre. Le log HijackThis fourni illustre une configuration complexe et des éléments persistant, notamment des extensions et services liés à divers logiciels, ce qui rend l’éradication plus délicate. Pour remédier à cela, il est recommandé d’opérer en mode sans échec, mettre à jour et exécuter des analyses avec un antivirus fiable et des outils anti-malware dédiés, puis nettoyer les entrées de démarrage. En cas de détection persistante, envisager une réinstallation propre du système ou l’utilisation d’un outil de récupération du système, tout en sauvegardant les données essentielles sur support externe.

Bobot (l’IA à votre service)
  1. en effet t as la meme merde sur ce pc -;)

    c logique car elle se propage via les clé usb etc :

    branches tes disques et allumes les puis :

    Telecharge UsbFix sur ton bureau

    --> Lance l installation avec les parametres par default

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    --> Double clic sur le raccourci UsbFix sur ton bureau

    -->choisi l option 1 (nettoyage)

    --> Le pc va redémarer

    -->Apres redémarrage post le rapport UsbFix.txt

    Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
    Note :
    "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    1. Contributeur sécurité
      pour les autorun:

      1/ # Télécharge RavAntivirus d'Evosla :
      http://ww25.evosla.com/compteur.php?soft=rav_antivirus

      # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
      # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
      # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
      # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
      # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
      # Retire tes disques amovibles et redémarrez votre ordinateur.
      # Poste le rapport, si infection!

      2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe

      Double-clique sur l’icône.
      Les icônes vont disparaître. C’est normal.
      Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
      Redémarre ensuite le PC.
      1. Contributeur sécurité
        il serait préférable que tu crées ton propre message sans aller dans le post d'un autre

        merci
        1. OK jlpjlp
          suis nouveau je n'avais pas encore compris ...maintenant c'est fait

          merci

          BàT
      2. je joint le resulta de usbfix

        -------------- UsbFix V2.414.3 ---------------

        * User : moi moi
        * Outils mis a jours le 15/01/2009 par Chiquitine29 et Chimay8
        * Recherche effectuée à 8:29:43 le ven. 16/01/2009
        * Windows Xp - Internet Explorer 7.0.5730.13

        --------------- [ Processus actifs ] ----------------

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\System32\SCardSvr.exe
        C:\WINDOWS\system32\agrsmsvc.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\WINDOWS\system32\userinit.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\WINDOWS\system32\userinit.exe
        C:\WINDOWS\system32\WgaTray.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

        --------------- [ Informations lecteurs ] ----------------

        C: - Fixed Drive

        --------------- [ Lecteur C ] ----------------

        C: - Fixed Drive

        +- Listing des fichiers présents :

        [22/11/2007 10:14][--a------] C:\AUTOEXEC.BAT
        [04/08/2004 13:00][-rahs----] C:\NTDETECT.COM
        [10/12/2008 17:09][-rahs----] C:\boot.ini
        [10/12/2008 17:09][-rahs----] C:\lmtiviewalarmportnumber.ini
        [10/12/2008 17:09][-rahs----] C:\lmtiviewbinportnumber.ini
        [12/12/2008 14:35][--a------] C:\test.txt
        [12/12/2008 14:35][--a------] C:\UsbFix.txt
        [22/11/2007 10:14][--a------] C:\CONFIG.SYS
        [22/11/2007 10:14][--a------] C:\hiberfil.sys
        [22/11/2007 10:14][--a------] C:\IO.SYS
        [22/11/2007 10:14][--a------] C:\MSDOS.SYS
        [22/11/2007 10:14][--a------] C:\pagefile.sys

        --------------- [ Registre / Startup ] ----------------

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
        CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
        PcSync=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
        swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        drvsyskit=C:\Documents and Settings\f_devits\Application Data\drivers\winupgro.exe
        SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
        IMJPMIG8.1="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        PHIME2002ASync=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        PHIME2002A=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        SoundMAX=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
        IgfxTray=C:\WINDOWS\system32\igfxtray.exe
        HotKeysCmds=C:\WINDOWS\system32\hkcmd.exe
        Persistence=C:\WINDOWS\system32\igfxpers.exe
        SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        QlbCtrl=%ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
        AccelerometerSysTrayApplet=C:\WINDOWS\system32\AccelerometerSt.exe
        ccApp="C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        vptray=C:\PROGRA~1\SYMANT~1\VPTray.exe
        SoundMAXPnP=C:\Program Files\Analog Devices\Core\smax4pnp.exe
        QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
        Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        LmtSysMonitor="C:\HW LMT\tray\bin\ilmt_tray.exe"
        NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
        PCSuiteTrayApplication=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
        DataLayer=C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
        SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
        <NO NAME>=
        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
        Installed=1
        <NO NAME>=
        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
        Installed=1
        NoChange=1
        <NO NAME>=
        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
        Installed=1
        <NO NAME>=

        --------------- [ Registre / Mountpoint2 ] ----------------

        -> Recherche négative.

        --------------- [ Nettoyage des disques ] ----------------

        --------------- [ Resumé ] ----------------

        -> /!\ Le resultat doit etre interprété par un spécialiste /!\

        [22/11/2007 10:14][--a------] C:\AUTOEXEC.BAT
        [04/08/2004 13:00][-rahs----] C:\NTDETECT.COM
        [10/12/2008 17:09][-rahs----] C:\boot.ini
        [10/12/2008 17:09][-rahs----] C:\lmtiviewalarmportnumber.ini
        [10/12/2008 17:09][-rahs----] C:\lmtiviewbinportnumber.ini

        --------------- [ Vaccination ] ----------------

        C:\autorun.inf -> Dossier autorun.inf crée par UsbFix !

        --------------- ! Fin du rapport ! ----------------

        je n'y comprend rien :-)
        1. ok

          ++
          1. Salut chiquitine 29 je crois que je suis aussi infecter par ce virus ,suis un peux novice et aurais certainement besoin d'aide .
            Le pc infecté ne ce conneste plus car wifi bloqué !!

            Que doije faire

            Help me

            merci

            fab
        2. Tout est OK, j'ai installé Antivir

          Je suis repartit pour de nouvelles aventures !

          A bientôt
          1. Contributeur sécurité
            tu passes et récupères "mes" topics quand tu veux :)
            1. t inkiete l amis

              ça fé , on va dire partis de mes "obligations"

              @++ et merci de m avoir laissé le topic

              -;)
              1. Contributeur sécurité
                encore un problème résolu brillamment chiquitine29!

                j'etais completement passé à coté de C:\WINDOWS\AhnRpta.exe

                a bientôt

                et bonne suite
                Fizzy's!
                1. oui ils le sont

                  ils ont tous un dossier autorun.inf

                  tu les verras en affichant les dossier caché

                  ne les supprimes pas ils te protegent
                  1. je vais regarder les liens que tu m'as donné, merci du conseil.

                    Au final mes DD externes sont hors de danger ?
                    1. ok

                      coole antivir etc

                      purge la resto

                      et puis passe javara sur l autre pc
                      1. JavaRa 1.12 Removal Log.

                        Report follows after line.

                        ------------------------------------

                        The JavaRa removal process was started on Thu Jan 15 21:43:44 2009

                        Found and removed: C:\Program Files\Java\jre1.6.0_03

                        Found and removed: C:\Program Files\Java\jre1.6.0_05

                        JavaRa 1.12 Removal Log.

                        Report follows after line.

                        ------------------------------------

                        The JavaRa removal process was started on Thu Jan 15 21:44:19 2009

                        Found and removed: C:\Program Files\Java\jre1.6.0_07

                        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

                        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

                        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

                        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

                        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

                        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

                        Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003

                        Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003

                        Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

                        Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

                        Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

                        Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

                        Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

                        Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

                        Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

                        Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

                        Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030}

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

                        Found and removed: Software\Classes\JavaPlugin.160_03

                        Found and removed: Software\Classes\JavaPlugin.160_05

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

                        Found and removed: Software\JavaSoft\Java2D\1.6.0_03

                        Found and removed: Software\JavaSoft\Java2D\1.6.0_05

                        Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03

                        Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

                        ------------------------------------

                        Finished reporting.
                        1. c'est bon pour tools cleaner :

                          [ Rapport ToolsCleaner version 2.3.0 (par A.Rothstein & dj QUIOU) ]

                          -->- Recherche:

                          C:\Combofix.txt: trouvé !
                          C:\UsbFix.txt: trouvé !
                          C:\Qoobox: trouvé !
                          C:\_OtMoveIt: trouvé !
                          C:\Rsit: trouvé !
                          C:\Documents and Settings\Antoine\Bureau\ComboFix.exe: trouvé !
                          C:\Documents and Settings\Antoine\Bureau\UsbFix.exe: trouvé !
                          C:\Documents and Settings\Antoine\Bureau\UsbFix.lnk: trouvé !
                          C:\Documents and Settings\Antoine\Bureau\Rsit.exe: trouvé !
                          C:\Documents and Settings\Antoine\Bureau\hijackthis_199\HijackThis.exe: trouvé !
                          C:\Documents and Settings\Antoine\Bureau\hijackthis_199\hijackthis.log: trouvé !
                          C:\Documents and Settings\Antoine\Menu Démarrer\Programmes\UsbFix: trouvé !
                          C:\Documents and Settings\Antoine\Menu Démarrer\Programmes\UsbFix\UsbFix.lnk: trouvé !
                          C:\Program Files\UsbFix: trouvé !
                          C:\Program Files\trend micro\HijackThis.exe: trouvé !
                          C:\Program Files\trend micro\hijackthis.log: trouvé !

                          ---------------------------------
                          -->- Suppression:

                          C:\Documents and Settings\Antoine\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
                          C:\Documents and Settings\Antoine\Bureau\hijackthis_199\HijackThis.exe: supprimé !
                          C:\Program Files\trend micro\HijackThis.exe: supprimé !
                          C:\Combofix.txt: supprimé !
                          C:\UsbFix.txt: supprimé !
                          C:\Documents and Settings\Antoine\Bureau\UsbFix.exe: supprimé !
                          C:\Documents and Settings\Antoine\Bureau\UsbFix.lnk: supprimé !
                          C:\Documents and Settings\Antoine\Bureau\Rsit.exe: supprimé !
                          C:\Documents and Settings\Antoine\Bureau\hijackthis_199\hijackthis.log: supprimé !
                          C:\Documents and Settings\Antoine\Menu Démarrer\Programmes\UsbFix\UsbFix.lnk: supprimé !
                          C:\Program Files\trend micro\hijackthis.log: supprimé !
                          C:\Qoobox: supprimé !
                          C:\_OtMoveIt: supprimé !
                          C:\Rsit: supprimé !
                          C:\Documents and Settings\Antoine\Menu Démarrer\Programmes\UsbFix: supprimé !
                          C:\Program Files\UsbFix: supprimé !

                          Fichiers temporaires nettoyés !
                          Corbeille vidée!
                          • 1
                          • 2
                          • 3
                          • 4
                          • 5