Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés


Bonjour à tous,


Alors comme pour changer, j'ai encore des virus maléfiques sur mon laptop.

1) Les fichiers cachés ne s'affichent plus, même en faisant "appliquer" et "ok".

2) On doit se transmettre les virus par flasher car même si je fais attention, j'en chope quand même. J'ai "flash desinfector" mais ça ne fondtionne pas assez bien.

3) Voici mon rapport Hijack, merci d'avance!!!


Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:55:00, on 07/03/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal


Running processes:











C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe



C:\Program Files\SPACENET\Internet Page Accelerator\RPAService.exe

C:\Program Files\SPACENET\Internet Page Accelerator\AS_Agent.exe




C:\Program Files\iTunes\iTunesHelper.exe





C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe


C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Hijackthis\HijackThis.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =;CM=MsgrInstall

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:9877

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll

O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [iPA_PROXY_SETTINGS] C:\Program Files\SPACENET\Internet Page Accelerator\BRW_Setup.exe

O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [HPWRTOOLBOX] C:\Program Files\Hewlett-Packard\hp deskjet 460 series\Toolbox\HPWRTBX.exe "-i"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')


O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: RPA Service - Unknown owner - C:\Program Files\SPACENET\Internet Page Accelerator\RPAService.exe

O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE



End of file - 5891 bytes



Alors je connaissait cette procédure mais même avec Avira j'avais aussi pas mal de pbs de vers :P

Bref je l'ai refait quand même et voilà mon rapport HJT:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:50:16, on 08/03/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal


Running processes:










C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe


C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe




C:\Program Files\iTunes\iTunesHelper.exe





C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe


C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe

C:\Program Files\Hijackthis\HijackThis.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =;CM=MsgrInstall

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll

O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [HPWRTOOLBOX] C:\Program Files\Hewlett-Packard\hp deskjet 460 series\Toolbox\HPWRTBX.exe "-i"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')


O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE



End of file - 5458 bytes



En fait j'ai toujors mes dossiers cachés qui ne s'affichent plus et je pens etre encore infecté.

Voilà le rapport Antivir partition C:



AntiVir PersonalEdition Classic

Report file date: samedi 8 mars 2008 12:23


Scanning for 835736 virus strains and unwanted programs.


Licensed to: Avira AntiVir PersonalEdition Classic

Serial number: 0000149996-ADJIE-0001

Platform: Windows XP

Windows version: (Service Pack 2) [5.1.2600]

Username: Log nordkivu

Computer name: PU


Version information:

BUILD.DAT : 270 15603 Bytes 9/19/2007 13:32:00

AVSCAN.EXE : 290856 Bytes 8/23/2007 12:16:29

AVSCAN.DLL : 49192 Bytes 8/16/2007 11:23:51

LUKE.DLL : 147496 Bytes 8/14/2007 14:32:47

LUKERES.DLL : 10280 Bytes 8/21/2007 11:35:20

ANTIVIR0.VDF : 11030528 Bytes 7/18/2007 13:27:15

ANTIVIR1.VDF : 1640448 Bytes 9/13/2007 13:26:55

ANTIVIR2.VDF : 2048 Bytes 9/13/2007 13:27:04

ANTIVIR3.VDF : 2048 Bytes 9/13/2007 13:27:13

AVEWIN32.DLL : 2806272 Bytes 9/17/2007 16:43:56

AVWINLL.DLL : 14376 Bytes 2/26/2007 09:36:26

AVPREF.DLL : 25640 Bytes 7/18/2007 06:39:17

AVREP.DLL : 155688 Bytes 4/16/2007 12:16:24

AVPACK32.DLL : 360488 Bytes 8/3/2007 07:46:00

AVREG.DLL : 30760 Bytes 7/18/2007 06:17:06

AVARKT.DLL : 278568 Bytes 8/28/2007 11:26:33

AVEVTLOG.DLL : 86056 Bytes 7/18/2007 06:10:18

NETNT.DLL : 7720 Bytes 3/8/2007 10:09:42

RCIMAGE.DLL : 2342952 Bytes 8/7/2007 11:38:13

RCTEXT.DLL : 86056 Bytes 8/21/2007 11:50:37

SQLITE3.DLL : 339968 Bytes 7/23/2007 08:37:21


Configuration settings for the scan:

Jobname..........................: Manual Selection

Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp

Logging..........................: low

Primary action...................: interactive

Secondary action.................: ignore

Scan master boot sector..........: off

Scan boot sector.................: on

Boot sectors.....................: C:,

Scan memory......................: on

Process scan.....................: on

Scan registry....................: on

Search for rootkits..............: off

Scan all files...................: All files

Scan archives....................: on

Recursion depth..................: 20

Smart extensions.................: on

Macro heuristic..................: on

File heuristic...................: high


Start of the scan: samedi 8 mars 2008 12:23


The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'explorer.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

12 processes with 12 modules were scanned


Start scanning boot sectors:

Boot sector 'C:\'

[NOTE] No virus was found!


Starting to scan the registry.

The registry was scanned ( '29' files ).



Starting the file scan:


Begin scan in 'C:\' <Logiciels>


[DETECTION] Contains suspicious code HEUR/Crypted

[iNFO] The file was moved to '4839695b.qua'!


[WARNING] The file could not be opened!

C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\INFECTED\4839695b.qua

[DETECTION] Contains suspicious code HEUR/Crypted

[iNFO] The file was moved to '4805696b.qua'!


[DETECTION] Contains suspicious code HEUR/Crypted

[iNFO] The file was moved to '484871f4.qua'!


[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was deleted!


[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was deleted!



End of the scan: samedi 8 mars 2008 13:07

Used time: 43:41 min


The scan has been done completely.


3082 Scanning directories

121479 Files were scanned

2 viruses and/or unwanted programs were found

3 Files were classified as suspicious:

2 files were deleted

0 files were repaired

3 files were moved to quarantine

0 files were renamed

1 Files cannot be scanned

121477 Files not concerned

1084 Archives were scanned

1 Warnings

0 Notes





En fait j'ai toujors mes dossiers cachés qui ne s'affichent plus et je pens etre encore infecté.

Voilà le rapport Antivir partition C:



AntiVir PersonalEdition Classic

Report file date: samedi 8 mars 2008 12:23


Scanning for 835736 virus strains and unwanted programs.


Licensed to: Avira AntiVir PersonalEdition Classic

Serial number: 0000149996-ADJIE-0001

Platform: Windows XP

Windows version: (Service Pack 2) [5.1.2600]

Username: Log nordkivu

Computer name: PU


Version information:

BUILD.DAT : 270 15603 Bytes 9/19/2007 13:32:00

AVSCAN.EXE : 290856 Bytes 8/23/2007 12:16:29

AVSCAN.DLL : 49192 Bytes 8/16/2007 11:23:51

LUKE.DLL : 147496 Bytes 8/14/2007 14:32:47

LUKERES.DLL : 10280 Bytes 8/21/2007 11:35:20

ANTIVIR0.VDF : 11030528 Bytes 7/18/2007 13:27:15

ANTIVIR1.VDF : 1640448 Bytes 9/13/2007 13:26:55

ANTIVIR2.VDF : 2048 Bytes 9/13/2007 13:27:04

ANTIVIR3.VDF : 2048 Bytes 9/13/2007 13:27:13

AVEWIN32.DLL : 2806272 Bytes 9/17/2007 16:43:56

AVWINLL.DLL : 14376 Bytes 2/26/2007 09:36:26

AVPREF.DLL : 25640 Bytes 7/18/2007 06:39:17

AVREP.DLL : 155688 Bytes 4/16/2007 12:16:24

AVPACK32.DLL : 360488 Bytes 8/3/2007 07:46:00

AVREG.DLL : 30760 Bytes 7/18/2007 06:17:06

AVARKT.DLL : 278568 Bytes 8/28/2007 11:26:33

AVEVTLOG.DLL : 86056 Bytes 7/18/2007 06:10:18

NETNT.DLL : 7720 Bytes 3/8/2007 10:09:42

RCIMAGE.DLL : 2342952 Bytes 8/7/2007 11:38:13

RCTEXT.DLL : 86056 Bytes 8/21/2007 11:50:37

SQLITE3.DLL : 339968 Bytes 7/23/2007 08:37:21


Configuration settings for the scan:

Jobname..........................: Manual Selection

Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp

Logging..........................: low

Primary action...................: interactive

Secondary action.................: ignore

Scan master boot sector..........: off

Scan boot sector.................: on

Boot sectors.....................: C:,

Scan memory......................: on

Process scan.....................: on

Scan registry....................: on

Search for rootkits..............: off

Scan all files...................: All files

Scan archives....................: on

Recursion depth..................: 20

Smart extensions.................: on

Macro heuristic..................: on

File heuristic...................: high


Start of the scan: samedi 8 mars 2008 12:23


The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'explorer.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

12 processes with 12 modules were scanned


Start scanning boot sectors:

Boot sector 'C:\'

[NOTE] No virus was found!


Starting to scan the registry.

The registry was scanned ( '29' files ).



Starting the file scan:


Begin scan in 'C:\' <Logiciels>


[DETECTION] Contains suspicious code HEUR/Crypted

[iNFO] The file was moved to '4839695b.qua'!


[WARNING] The file could not be opened!

C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\INFECTED\4839695b.qua

[DETECTION] Contains suspicious code HEUR/Crypted

[iNFO] The file was moved to '4805696b.qua'!


[DETECTION] Contains suspicious code HEUR/Crypted

[iNFO] The file was moved to '484871f4.qua'!


[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was deleted!


[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was deleted!



End of the scan: samedi 8 mars 2008 13:07

Used time: 43:41 min


The scan has been done completely.


3082 Scanning directories

121479 Files were scanned

2 viruses and/or unwanted programs were found

3 Files were classified as suspicious:

2 files were deleted

0 files were repaired

3 files were moved to quarantine

0 files were renamed

1 Files cannot be scanned

121477 Files not concerned

1084 Archives were scanned

1 Warnings

0 Notes






AntiVir PersonalEdition Classic

Report file date: samedi 8 mars 2008 13:10


Scanning for 835736 virus strains and unwanted programs.


Licensed to: Avira AntiVir PersonalEdition Classic

Serial number: 0000149996-ADJIE-0001

Platform: Windows XP

Windows version: (Service Pack 2) [5.1.2600]

Username: Log nordkivu

Computer name: PU


Version information:

BUILD.DAT : 270 15603 Bytes 9/19/2007 13:32:00

AVSCAN.EXE : 290856 Bytes 8/23/2007 12:16:29

AVSCAN.DLL : 49192 Bytes 8/16/2007 11:23:51

LUKE.DLL : 147496 Bytes 8/14/2007 14:32:47

LUKERES.DLL : 10280 Bytes 8/21/2007 11:35:20

ANTIVIR0.VDF : 11030528 Bytes 7/18/2007 13:27:15

ANTIVIR1.VDF : 1640448 Bytes 9/13/2007 13:26:55

ANTIVIR2.VDF : 2048 Bytes 9/13/2007 13:27:04

ANTIVIR3.VDF : 2048 Bytes 9/13/2007 13:27:13

AVEWIN32.DLL : 2806272 Bytes 9/17/2007 16:43:56

AVWINLL.DLL : 14376 Bytes 2/26/2007 09:36:26

AVPREF.DLL : 25640 Bytes 7/18/2007 06:39:17

AVREP.DLL : 155688 Bytes 4/16/2007 12:16:24

AVPACK32.DLL : 360488 Bytes 8/3/2007 07:46:00

AVREG.DLL : 30760 Bytes 7/18/2007 06:17:06

AVARKT.DLL : 278568 Bytes 8/28/2007 11:26:33

AVEVTLOG.DLL : 86056 Bytes 7/18/2007 06:10:18

NETNT.DLL : 7720 Bytes 3/8/2007 10:09:42

RCIMAGE.DLL : 2342952 Bytes 8/7/2007 11:38:13

RCTEXT.DLL : 86056 Bytes 8/21/2007 11:50:37

SQLITE3.DLL : 339968 Bytes 7/23/2007 08:37:21


Configuration settings for the scan:

Jobname..........................: Manual Selection

Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp

Logging..........................: low

Primary action...................: interactive

Secondary action.................: ignore

Scan master boot sector..........: off

Scan boot sector.................: on

Boot sectors.....................: E:,

Scan memory......................: on

Process scan.....................: on

Scan registry....................: on

Search for rootkits..............: off

Scan all files...................: All files

Scan archives....................: on

Recursion depth..................: 20

Smart extensions.................: on

Macro heuristic..................: on

File heuristic...................: high


Start of the scan: samedi 8 mars 2008 13:10


The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'explorer.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

11 processes with 11 modules were scanned


Start scanning boot sectors:

Boot sector 'D:\'

[NOTE] No virus was found!

Boot sector 'E:\'

[NOTE] No virus was found!


Starting to scan the registry.

The registry was scanned ( '29' files ).



Starting the file scan:


Begin scan in 'D:\' <Documents >


[DETECTION] Contains suspicious code HEUR/Crypted

[iNFO] The file was moved to '4839746e.qua'!


[0] Archive type: ACE SFX (self extracting)

--> html\franais\av.htm

[WARNING] Error creating the file

--> html\franais\commands.htm

[WARNING] No further files can be extracted from this archive. The archive will be closed

[WARNING] No further files can be extracted from this archive. The archive will be closed

Begin scan in 'E:\' <Rien ici>


[DETECTION] Contains suspicious code HEUR/Crypted

[iNFO] The file was moved to '483979a4.qua'!



End of the scan: samedi 8 mars 2008 13:33

Used time: 22:34 min


The scan has been done completely.


1009 Scanning directories

38262 Files were scanned

0 viruses and/or unwanted programs were found

2 Files were classified as suspicious:

0 files were deleted

0 files were repaired

2 files were moved to quarantine

0 files were renamed

0 Files cannot be scanned

38262 Files not concerned

403 Archives were scanned

3 Warnings

1 Notes


Bonjour !


Veuillez configurer votre antivirus sur on pour cet item

Search for rootkits..............: off


Ensuite faite ceci :


Télécharger sur le bureau Flash Disinfector (de SUBS) à cette adresse :




Double-cliquez sur l’icône.


Les icônes vont disparaître. C’est normal.


Si un rapport est généré en cas d'infection, sauvegardez-le sur le bureau.


Redémarrer ensuite le PC.


Poster le rapport





Alors j'ai effectué la manip de configuration de l'antivirus.

Ensuite, j'avais déjà le logiciel "flash desinfector" (cf messages précedents). Il me semble que ce logiciel est spécialement conçu pour les DDE et flashdisks. En tout cas je m'en sers depuis 2 mois et il ne m'a jamais donné de rapport.

Bref je l'ai fait quand même et j'ai toujours les mêmes pbs.




Pouvez vous faire ceci :


1. Télécharger combofix.exe (par sUBs) ici :


sur votre Bureau.


2. Double clique sur combofix.exe et suivez les invites.

3. Lorsque le scan sera complété, un rapport apparaîtra. Copier/coller ce rapport dans votre prochaine réponse.


Voilà le rapport Combo fix:

ComboFix 08-03-08.2 - Log nordkivu 2008-03-09 16:34:14.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.130 [GMT 2:00]

Running from: C:\Documents and Settings\Log nordkivu\Desktop\ComboFix.exe

* Created a new restore point





((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))



2008-03-08 12:16 . 2008-03-08 12:16 <DIR> d-------- C:\Program Files\Avira

2008-03-08 12:16 . 2008-03-08 12:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira

2008-03-08 11:34 . 2008-03-08 11:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7

2008-03-02 14:45 . 2008-03-02 14:45 <DIR> d-------- C:\WINDOWS\Sun

2008-03-02 14:38 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl

2008-03-02 14:37 . 2008-03-02 14:38 <DIR> d-------- C:\Program Files\Java

2008-03-02 14:30 . 2008-03-02 14:30 <DIR> d-------- C:\Program Files\Common Files\Java

2008-02-29 09:21 . 2003-11-11 07:22 102,400 -ra------ C:\WINDOWS\scrub2k.exe

2008-02-29 09:21 . 2005-05-10 16:18 37,376 --a------ C:\WINDOWS\system32\hpz3l3xt.dll.1

2008-02-29 09:21 . 2004-10-28 02:45 443 -ra------ C:\WINDOWS\hpw0460k.ini

2008-02-29 09:19 . 2008-02-29 09:19 1,835 --a------ C:\WINDOWS\hpbvnstp.his

2008-02-29 09:19 . 2008-02-29 09:23 1,252 --a------ C:\WINDOWS\mariner.his

2008-02-29 09:19 . 2008-02-29 09:19 574 --a------ C:\WINDOWS\hpbvnstp.ini

2008-02-29 09:19 . 2008-02-29 09:20 399 --a------ C:\WINDOWS\hpdj460.his

2008-02-29 09:19 . 2008-02-29 09:23 303 --a------ C:\WINDOWS\hpdj460.ini

2008-02-29 09:19 . 2008-02-29 09:23 176 --a------ C:\WINDOWS\mariner.ini

2008-02-29 09:18 . 2004-09-29 05:52 184,320 -ra------ C:\WINDOWS\system32\hpbvnstp.dll

2008-02-29 09:18 . 2005-05-10 16:18 37,376 --a------ C:\WINDOWS\system32\hpz3l3xt.dll

2008-02-29 09:18 . 2004-08-13 19:47 346 -ra------ C:\WINDOWS\system32\hpbvnstp.dat

2008-02-29 08:54 . 2008-02-29 08:54 268 --ah----- C:\sqmdata03.sqm

2008-02-29 08:54 . 2008-02-29 08:54 244 --ah----- C:\sqmnoopt03.sqm

2008-02-28 07:56 . 2008-02-28 07:56 268 --ah----- C:\sqmdata02.sqm

2008-02-28 07:56 . 2008-02-28 07:56 244 --ah----- C:\sqmnoopt02.sqm

2008-02-28 00:05 . 2008-02-28 00:05 268 --ah----- C:\sqmdata01.sqm

2008-02-28 00:05 . 2008-02-28 00:05 244 --ah----- C:\sqmnoopt01.sqm

2008-02-27 19:23 . 2008-02-27 19:23 244 --ah----- C:\sqmnoopt00.sqm

2008-02-27 19:23 . 2008-02-27 19:23 232 --ah----- C:\sqmdata00.sqm

2008-02-25 21:23 . 2008-03-02 14:39 1,279 --a------ C:\WINDOWS\mozver.dat

2008-02-22 11:45 . 2008-02-29 17:49 <DIR> d-------- C:\Program Files\Marvell-HP

2008-02-22 11:44 . 2007-09-03 11:41 257,024 --a------ C:\WINDOWS\system32\HP2014LM.DLL

2008-02-22 11:44 . 2007-08-31 16:58 65,536 --a------ C:\WINDOWS\system32\HPPMLVS.DLL

2008-02-22 11:31 . 2008-02-22 11:32 <DIR> d-------- C:\Program Files\Common Files\Adobe

2008-02-20 19:46 . 2008-02-21 20:47 <DIR> d-------- C:\Program Files\MSN Apps

2008-02-20 19:46 . 2008-02-20 19:46 <DIR> d---s---- C:\Documents and Settings\Log nordkivu\UserData

2008-02-20 19:24 . 2008-02-20 19:43 <DIR> d-------- C:\Program Files\MSN Messenger

2008-02-20 19:18 . 2007-02-28 11:10 2,180,352 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe

2008-02-20 19:18 . 2007-02-28 11:08 2,136,064 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe

2008-02-20 19:18 . 2007-02-28 10:38 2,057,600 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe

2008-02-20 19:18 . 2007-02-28 10:38 2,015,744 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe

2008-02-19 19:20 . 2008-02-19 19:21 <DIR> d-------- C:\WINDOWS\system32\NtmsData

2008-02-19 18:53 . 2008-02-19 18:53 <DIR> d-------- C:\Program Files\NetWaiting

2008-02-18 12:55 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys

2008-02-18 12:55 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys

2008-02-18 12:55 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys

2008-02-18 12:55 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys

2008-02-18 09:28 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll

2008-02-18 09:28 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll

2008-02-18 09:28 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui

2008-02-18 08:43 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys

2008-02-18 08:43 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys

2008-02-18 08:43 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys

2008-02-18 08:43 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys

2008-02-16 10:02 . 2008-02-16 10:02 <DIR> d-------- C:\Program Files\Broadcom

2008-02-16 10:02 . 2006-06-13 14:03 667,648 --a------ C:\WINDOWS\system32\BCMLogon.dll

2008-02-14 16:57 . 2008-02-14 16:57 <DIR> d-------- C:\Documents and Settings\Log nordkivu\Application Data\InstallShield

2008-02-14 08:22 . 2006-06-13 13:57 139,264 --a------ C:\WINDOWS\system32\igfxres.dll

2008-02-14 07:57 . 2008-02-14 07:57 <DIR> d-------- C:\Program Files\Synaptics

2008-02-14 07:57 . 2006-06-17 01:40 193,120 --a------ C:\WINDOWS\system32\drivers\SynTP.sys

2008-02-14 07:57 . 2006-06-17 01:54 114,688 --a------ C:\WINDOWS\system32\SynCtrl.dll

2008-02-14 07:57 . 2006-06-17 01:54 94,297 --a------ C:\WINDOWS\system32\SynTPAPI.dll

2008-02-14 07:57 . 2006-06-17 01:53 82,012 --a------ C:\WINDOWS\system32\SynCOM.dll

2008-02-14 07:57 . 2006-06-17 02:30 81,920 --a------ C:\WINDOWS\system32\SynTPCo2.dll

2008-02-14 07:57 . 2006-06-17 02:25 69,721 --a------ C:\WINDOWS\system32\SynTPFcs.dll

2008-02-14 07:42 . 2008-02-14 07:42 <DIR> d-------- C:\Documents and Settings\Log nordkivu\Application Data\vlc

2008-02-13 23:36 . 2008-02-13 23:36 <DIR> d-------- C:\Program Files\iTunes

2008-02-13 23:36 . 2008-02-13 23:36 <DIR> d-------- C:\Program Files\iPod

2008-02-13 23:36 . 2008-02-13 23:36 1,409 --a------ C:\WINDOWS\QTFont.for

2008-02-13 23:34 . 2008-02-13 23:35 <DIR> d-------- C:\Program Files\QuickTime

2008-02-13 20:19 . 2008-02-13 20:19 <DIR> d-------- C:\Documents and Settings\Log nordkivu\Contacts

2008-02-13 17:15 . 2008-02-13 17:15 <DIR> d-------- C:\Documents and Settings\Log nordkivu\Application Data\Apple Computer

2008-02-13 17:15 . 2008-03-09 11:35 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-02-13 17:14 . 2008-02-22 11:44 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE

2008-02-13 17:14 . 2008-02-13 17:14 <DIR> d-------- C:\Program Files\Apple Software Update

2008-02-13 17:14 . 2008-02-13 17:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer

2008-02-13 17:13 . 2008-02-13 17:13 <DIR> d-------- C:\Program Files\Common Files\Apple

2008-02-13 17:13 . 2008-02-13 17:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple

2008-02-13 17:12 . 2008-02-13 17:12 <DIR> d-------- C:\Program Files\VideoLAN

2008-02-13 17:10 . 2008-02-19 18:53 <DIR> d-------- C:\Program Files\CONEXANT

2008-02-13 17:07 . 2008-02-14 15:22 <DIR> d-------- C:\Program Files\WinAce

2008-02-13 17:05 . 2008-02-13 17:05 <DIR> d-------- C:\Program Files\MSBuild

2008-02-13 17:05 . 2008-02-13 17:05 <DIR> d-------- C:\Program Files\Microsoft Works

2008-02-13 17:02 . 2008-02-13 17:05 <DIR> d-------- C:\WINDOWS\SHELLNEW

2008-02-13 17:01 . 2008-02-13 17:01 <DIR> dr-h----- C:\MSOCache

2008-02-13 17:01 . 2008-02-22 20:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help

2008-02-13 13:49 . 2006-12-20 22:56 988,800 --a------ C:\WINDOWS\system32\drivers\HSF_DPV.sys

2008-02-13 13:49 . 2006-12-20 22:55 730,112 --a------ C:\WINDOWS\system32\drivers\HSF_CNXT.sys

2008-02-13 13:49 . 2006-12-20 22:56 209,664 --a------ C:\WINDOWS\system32\drivers\HSFHWAZL.sys

2008-02-13 13:49 . 2006-12-19 04:37 176,128 --a------ C:\WINDOWS\system32\UCI32M16.dll

2008-02-13 13:49 . 2006-12-21 02:04 144,201 --a------ C:\WINDOWS\system32\drivers\HSFProf.cty

2008-02-13 13:49 . 2006-06-18 01:26 94,208 --a------ C:\WINDOWS\system32\mdmxsdk.dll

2008-02-13 13:49 . 2006-06-18 01:26 12,672 --a------ C:\WINDOWS\system32\drivers\mdmxsdk.sys



(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


2008-03-07 15:23 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-02-29 07:20 --------- d-----w C:\Program Files\Hewlett-Packard

2008-02-13 14:58 --------- d-----w C:\Program Files\Windows Media Connect 2

2008-02-13 14:39 --------- d-----w C:\Documents and Settings\Log nordkivu\Application Data\Talkback

2008-02-13 14:25 --------- d-----w C:\Program Files\Intel

2008-02-13 14:17 --------- d-----w C:\Program Files\Common Files\InstallShield

2008-02-13 12:30 --------- d-----w C:\Program Files\microsoft frontpage



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown




"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2007-07-27 14:00 15360]

"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55 5674352]



"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 14:18 267048]

"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-06-13 13:57 94208]

"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-06-13 13:57 77824]

"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-06-13 13:57 118784]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 02:22 794713]

"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-06-13 14:03 1236992]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

"HPWRTOOLBOX"="C:\Program Files\Hewlett-Packard\hp deskjet 460 series\Toolbox\HPWRTBX.exe" [2005-10-26 01:29 344064]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-08-31 12:25 249896]



"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2007-07-27 14:00 15360]




"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"C:\\Program Files\\iTunes\\iTunes.exe"=

"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"C:\\Program Files\\MSN Messenger\\livecall.exe"=





\Shell\AutoRun\command - G:\a3g3.bat

\Shell\explore\Command - G:\a3g3.bat

\Shell\open\Command - G:\a3g3.bat



\Shell\AutoRun\command - xo8wr9.exe

\Shell\explore\Command - xo8wr9.exe

\Shell\open\Command - xo8wr9.exe



\Shell\AutoRun\command - G:\a3g3.bat

\Shell\explore\Command - G:\a3g3.bat

\Shell\open\Command - G:\a3g3.bat



\Shell\AutoRun\command - oufddh.exe

\Shell\explore\Command - oufddh.exe

\Shell\open\Command - oufddh.exe



Contents of the 'Scheduled Tasks' folder

"2008-03-04 09:13:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"

- C:\Program Files\Apple Software Update\SoftwareUpdate.exe




catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,

Rootkit scan 2008-03-09 16:35:25

Windows 5.1.2600 Service Pack 2 NTFS


scanning hidden processes ...


scanning hidden autostart entries ...


scanning hidden files ...


scan completed successfully

hidden files: 0




Completion time: 2008-03-09 16:35:58


2008-02-25 05:59:09 --- E O F ---

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
  • Créer...