Infecté par virtumonde dll.

Bonjour,

de l aide svp pour desinfecté mon pc en sachant que mon pc c etein en parti et les scan ne trouve rien quand il se termine meme spybot au demarage ce lance plus les partages et les attac sny d apres tune up son desactivé

virtu monde dll. aparé lors des scan et passe tranquille

merci d avance
Configuration: Windows XP Internet Explorer 8.0

8 réponses

  1. Contributeur
    Salut,

    Telecharges RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

    - Fermes toutes les applications en cours et double clic sur RSIT.exe
    - Selectionnes " Continue " à l'ecran >> RSIT va analyser le pc et verifier si l'outil hijackthis ( version à jour) est present sur le pc, si ce n'est pas le cas, RSIT le telechargera >> acceptes la license
    - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent, log.txt à l'écran et info.txt dans la barre des taches
    - Postes le contenu des 2 rapports
    0
    1. merci de maider

      je lai telechargé mai l execution
      c:/ documents and settings/karl/bureau/ rsit.exe n est pas une application win32 valide.
      0
      1. c bon j ai telecharger plusieur fois le lien et j en et un qui et bon lol petit beug
        Logfile of random's system information tool 1.06 (written by random/random)
        Run by karl at 2009-09-07 12:11:56
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 63 GB (80%) free of 78 GB
        Total RAM: 511 MB (38% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 12:12:22, on 07/09/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Windows Defender\MsMpEng.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\TUProgSt.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Documents and Settings\karl\Bureau\RSIT.exe
        C:\Program Files\trend micro\karl.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Logitech SetPoint.lnk.disabled
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        O9 - Extra button: (no name) - {12345678-1234-1234-1234-1234567890AB} - (no file)
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe
        O23 - Service: Ma-Config Service (maconfservice) - Unknown owner - C:\Program Files\ma-config.com\maconfservice.exe (file missing)
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
        O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
        O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
        0
        1. Contributeur
          Télécharges FindyKill de Chiquitine29 :

          ->Enregistres le sur ton bureau et pas ailleurs !

          !! Déconnectes toi et fermes toute applications en cours !!

          ->double Cliques sur "FindyKill.exe" pour lancer l'installe de l'outil . Ne touche surtout pas aux paramètres d'installation.

          ---> Branches tes disques amovibles ( clé usb, disques dur externe, ipod etc..) sans les ouvrir
          --> Double cliques sur le raccourci " FindyKill " qui est sur ton bureau
          --> Au menu, choisis l'option1 et patientes le temps du scan
          --> Postes le rapport Findykill.txt qui sera généré
          0
          1. ############################## | FindyKill V5.009 |

            # User : karl (Administrateurs) # MATH-057FF21299
            # Update on 06/09/2009 by Chiquitine29
            # Start at: 12:21:02 | 07/09/2009
            # Website : http://pagesperso-orange.fr/NosTools/index.html

            # AMD Athlon(tm) XP 2500+
            # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
            # Internet Explorer 8.0.6001.18702
            # Windows Firewall Status : Enabled
            # AV : BitDefender Antivirus 13.0.15 [ (!) Disabled | Updated ]
            # AV : avast! antivirus 4.8.1351 [VPS 090906-1] 4.8.1351 [ Enabled | Updated ]
            # FW : BitDefender Pare-feu[ (!) Disabled ]13.0.15

            # C:\ # Disque fixe local # 76,32 Go (61,27 Go free) # NTFS
            # D:\ # Disque CD-ROM
            # E:\ # Disque amovible # 3,77 Go (3,08 Go free) # FAT
            # F:\ # Disque amovible # 1,87 Go (1,87 Go free) [UDISK] # FAT
            # G:\ # Disque amovible

            ############################## | Processus actifs |

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\System32\TUProgSt.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            ################## | C: |

            ################## | C:\WINDOWS |

            ################## | C:\WINDOWS\system32 |

            ################## | C:\WINDOWS\system32\drivers |

            ################## | C:\Documents and Settings\karl\Application Data |

            ################## | C:\Documents and Settings\karl\Temporary Internet Files |

            ################## | Registre / Clés infectieuses |

            Présent ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
            Présent ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
            Présent ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
            Présent ! [HKLM\software\microsoft\security center] "FirewallOverride"
            Présent ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"

            ################## | Etat / Services / Informations |

            # Affichage des fichiers cachés : OK

            # Mode sans echec : OK

            # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
            # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
            # Ip6Fw -> Start = 3 ( Good = 2 | Bad = 4 )
            # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
            # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
            # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
            # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

            ################## | Cracks / Keygens / Serials |

            ################## | ! Fin du rapport # FindyKill V5.009 ! |
            0
            1. j ai formater y a pas lontemps et mon pc . s etain en partie aussi
              0
              1. c quoi ca ?

                ################## | Registre / Clés infectieuses |

                Présent ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
                Présent ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
                Présent ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
                Présent ! [HKLM\software\microsoft\security center] "FirewallOverride"
                Présent ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"
                stp
                0
                1. mon pc ne s etant pas bysar pour l instant
                  0