Win 32:Agent-HOP Wrm

Rudy2k5 Messages postés 6 Statut Membre -  
philae83 Messages postés 12854 Statut Contributeur sécurité -
Bonjour je me demandais si quelqu'un pourrait maider a trouver une solution a ce probleme de plus en plus nuisible sa fait deja un moment que je lai je croyais men etre debarassé et il est réapparu (Win 32:Agent-HOP Wrm) il occasionne un paquet de probleme sur mon ordinateur alors si vous pourriez maider le plus vite possible se serait plus qu'apprécié

Rudy

p.s. en ce moment jai avast mais je conte changer pour McAfee est ce que vous croyez que je devrais (il m'est offert gratuitement par le Cégep)
Configuration: Windows XP
Firefox 2.0.0.6

12 réponses

  1. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    bonsoir,

    commence par :

    * Télécharge HijackThis et poste le rapport stp

    http://pchelpbordeaux.free.fr/logiciels.html
    Tutorial
    http://pchelpbordeaux.free.fr/tuto.html
    Démo en image (merci balltrap)
    demo hijackenregistrement http://perso.orange.fr/rginformatique/section%20virus/Hijenr.gif
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    et

    * Télécharge CCleaner.

    https://www.pcastuces.com/logitheque/ccleaner.htm

    Installe le dans un répertoire dédié.

    Décoche pendant l'installation

    --- les deux cases "Ajouter l'option ... "

    --- Contrôler les mises à jour

    --- Ajouter la Barre d'Outils Yahoo! CCleaner

    * Lance Ccleaner pour un nettoyage complet.

    ------

    * télécharge AVG Anti-Spyware (ewido)

    https://www.avg.com/en-ww/free-antivirus-download

    * tu l'installes

    * lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente

    puis

    Lance AVG Anti-Spyware

    Clique sur le bouton Analyse (de la barre d'outils)

    puis fait dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions.

    Puis sur l'onglet Paramètres,
    sous : "Comment réagir "clique sur Actions recommandées. Sélectionne Quarantaine.

    Reviens à l'onglet Analyse. Clique sur Analyse complète du système.

    A la fin du scan, choisis l'option 3

    "Appliquer toutes les actions " en bas.

    Clique sur "Enregistrer le rapport".

    Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

    Poste le.
    0
    1. Rudy2k5 Messages postés 6 Statut Membre
       
      Salut désolé pour le delai mais jai été pas mal occupé ces temps-ci mais javais une petite question a te poser

      tu ecris ici: "puis fait dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions." est ce que cest apres le scan que je fait sa ?? (surement) mais se qui me melange cest que tu as ecrit ça avant laction danalyse complete

      si je le fait avant veux tu mexpliquer comment je dois le faire svp

      sur ce je dois y allé jai des trucs importants a faire
      merci davance
      Rudy
      0
    2. Rudy2k5
       
      ---------------------------------------------------------
      AVG Anti-Spyware - Rapport d'analyse
      ---------------------------------------------------------

      + Créé à: 09:56:00 2007-09-09

      + Résultat de l'analyse:



      C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\95MZ412N\lkjh[1] -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005634.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005636.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005639.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005641.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005642.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\WINDOWS\system32\jjejcbwn.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\WINDOWS\system32\kgxqkqoo.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\WINDOWS\system32\nwcpgxwu.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\WINDOWS\system32\owsxfhcy.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\WINDOWS\system32\saoqencf.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
      C:\Documents and Settings\SG-C\Cookies\sg-c@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@casalemedia[1].txt -> TrackingCookie.Casalemedia : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Nettoyé.
      :mozilla.7:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@ehg-ctv.hitbox[2].txt -> TrackingCookie.Hitbox : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@ehg-u3.hitbox[1].txt -> TrackingCookie.Hitbox : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@hitbox[2].txt -> TrackingCookie.Hitbox : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Nettoyé.
      :mozilla.42:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
      :mozilla.43:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
      :mozilla.44:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
      :mozilla.45:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
      :mozilla.46:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
      :mozilla.47:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
      :mozilla.48:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
      :mozilla.49:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Nettoyé.
      :mozilla.33:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
      :mozilla.34:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
      :mozilla.35:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
      :mozilla.36:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
      :mozilla.37:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
      :mozilla.38:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@statcounter[1].txt -> TrackingCookie.Statcounter : Nettoyé.
      C:\Documents and Settings\SG-C\Cookies\sg-c@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Nettoyé.
      [400] C:\WINDOWS\system32\vhmjydfi.exe -> Trojan.Agent.aoy : Nettoyé et sauvegardé (mise en quarantaine).
      C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\95MZ412N\theq3[1].exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005632.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP16\A0012642.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP18\A0012945.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP19\A0013041.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP21\A0013091.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP22\A0013320.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013597.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
      C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013600.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).


      Fin du rapport



      voici le resultat du scan cependant jai pas trouvé loption 3 dont tu parle
      0
  2. Rudy2k5 Messages postés 6 Statut Membre
     
    Logfile of HijackThis v1.99.1
    Scan saved at 21:05:15, on 2007-09-03
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\ATKKBService.exe
    C:\WINDOWS\system32\vhmjydfi.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\msgs.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/granby
    O2 - BHO: (no name) - {44218730-94E0-4b24-BBF0-C3D8B2BCE2C3} - C:\WINDOWS\system32\tmp32.tmp.dll
    O2 - BHO: (no name) - {5D8FA654-B27C-4E7F-B2F3-B913DAA78E0F} - C:\WINDOWS\system32\ssttq.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {CC358019-D328-40B4-8E2D-818CE142616C} - C:\WINDOWS\system32\awtsqpo.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: awtsqpo - C:\WINDOWS\SYSTEM32\awtsqpo.dll
    O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
    O20 - Winlogon Notify: ssttq - C:\WINDOWS\system32\ssttq.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: DomainService - - C:\WINDOWS\system32\vhmjydfi.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    voici le rapport d'Hijackthis
    0
  3. Rudy2k5 Messages postés 6 Statut Membre
     
    il est inscrit un petit qqch a propos de Ccleaner et jme pose des question

    "A signaler enfin que CCleaner permet également de supprimer les documents récents et les fichiers temporaires de nombreuses applications : Opera, Lecteur Windows Media, eMule, Kazaa, Google Toolbar, Netscape, Microsoft Office, Nero, Adobe Acrobat, WinRAR, WinAce, WinZip, etc."

    sa veut tu dire que je pourrais perdre des fichier que jaurais intentionellement downloader comme par exemple musique ou film ??

    p.s. saurais tu si je devrais mettre Mc afee a place de Avast ???
    0
  4. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    Bonsoir, et désolée pour le retard

    "A signaler enfin que CCleaner permet également de supprimer les documents récents et les fichiers temporaires de nombreuses applications : Opera, Lecteur Windows Media, eMule, Kazaa, Google Toolbar, Netscape, Microsoft Office, Nero, Adobe Acrobat, WinRAR, WinAce, WinZip, etc."
    
    sa veut tu dire que je pourrais perdre des fichier que jaurais intentionellement downloader comme par exemple musique ou film ?? 


    uniquement si tu les as mis dans les fichiers temporaires
    p.s. saurais tu si je devrais mettre Mc afee a place de Avast ???
    
    


    oui bien sûr que tu peux, McAfee est un bon antivirus et payant, si on te l'offre pourquoi pas.

    pour ton infection, on continue

    * Télécharge VundoFix.exe (par Atribune) sur ton Bureau

    http://www.atribune.org/ccount/click.php?id=4

    * Double-clique VundoFix.exe afin de le lancer

    * Clique sur le bouton Scan for Vundo

    * Lorsque le scan est complété, clique sur le bouton Remove Vundo

    * Une invite te demandera si tu veux supprimer les fichiers, clique YES

    * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers

    * Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK

    * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse

    Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".

    0
    1. Rudy
       
      ok mais dit moi si je dois commencer par les etape de ton premier message avant dembarquer sur Vundofix ou je dois commencer par Vundofix ???

      et pour se qui est c CCleaner est ce que je dois coché TOUTES les case dans (Windows) et dans (application)

      Merci de prendre le temps de me repondre japprécie beaucoup et ya pas de probleme prend le temps quil faut tu fais deja plus que dautre personne que je connais héhé ;P

      p.s. historique des saisie automatique nest surement pas obligatoire !?!?!?!?!?

      Rudy
      0
    2. Rudy2k5 Messages postés 6 Statut Membre
       
      Rapport VundoFix


      VundoFix V6.5.8

      Checking Java version...

      Java version is 1.5.0.3
      Old versions of java are exploitable and should be removed.

      Scan started at 10:46:54 2007-09-09

      Listing files found while scanning....

      C:\WINDOWS\sstutt.dll
      C:\windows\system32\awtqrqn.dll
      C:\windows\system32\awtrpmk.dll
      C:\WINDOWS\system32\awtsqpo.dll
      C:\windows\system32\awtsrpq.dll
      C:\windows\system32\awttusr.dll
      C:\windows\system32\awvspmk.dll
      C:\windows\system32\byxurrq.dll
      C:\windows\system32\byxwxuv.dll
      C:\windows\system32\byxxusp.dll
      C:\windows\system32\cbxuutq.dll
      C:\windows\system32\cbxvtut.dll
      C:\windows\system32\cbxwvvt.dll
      C:\windows\system32\cbxwwxv.dll
      C:\windows\system32\cbxxyvu.dll
      C:\windows\system32\cbxywtu.dll
      C:\windows\system32\ddawvwu.dll
      C:\windows\system32\ddcaayv.dll
      C:\windows\system32\ddcaxwx.dll
      C:\windows\system32\ddcyxyv.dll
      C:\windows\system32\efcaayy.dll
      C:\windows\system32\efcbxxw.dll
      C:\windows\system32\efcyaba.dll
      C:\windows\system32\efcyyxv.dll
      C:\windows\system32\fccawus.dll
      C:\windows\system32\fccbxvs.dll
      C:\windows\system32\fccccby.dll
      C:\windows\system32\fccyaby.dll
      C:\windows\system32\fccyyaa.dll
      C:\windows\system32\fjlluena.dll
      C:\windows\system32\gebaaya.dll
      C:\windows\system32\gebabyy.dll
      C:\windows\system32\gebaywv.dll
      C:\windows\system32\gebxusr.dll
      C:\windows\system32\gebxwvs.dll
      C:\windows\system32\gebyaxx.dll
      C:\windows\system32\hggdebc.dll
      C:\windows\system32\hggfdba.dll
      C:\windows\system32\hgghebb.dll
      C:\windows\system32\hgghedc.dll
      C:\windows\system32\hgghgff.dll
      C:\windows\system32\hgghhif.dll
      C:\windows\system32\hsacgmrj.dll
      C:\windows\system32\iifefff.dll
      C:\windows\system32\jjssqfte.dll
      C:\windows\system32\jkkhfdc.dll
      C:\windows\system32\jkkjgfg.dll
      C:\windows\system32\jkkkjgg.dll
      C:\windows\system32\khfcbay.dll
      C:\windows\system32\khfcdee.dll
      C:\windows\system32\khfdccc.dll
      C:\windows\system32\khfeccb.dll
      C:\windows\system32\khfecdd.dll
      C:\windows\system32\khffeca.dll
      C:\windows\system32\khfgfda.dll
      C:\windows\system32\khfgfef.dll
      C:\windows\system32\khfgffc.dll
      C:\windows\system32\khfggde.dll
      C:\windows\system32\khfghif.dll
      C:\windows\system32\ljjgdee.dll
      C:\windows\system32\ljjhfec.dll
      C:\windows\system32\ljjhghf.dll
      C:\windows\system32\ljjhghi.dll
      C:\windows\system32\ljjkigf.dll
      C:\windows\system32\ljjkkjg.dll
      C:\windows\system32\mljghhe.dll
      C:\windows\system32\mljhijj.dll
      C:\windows\system32\mljjiig.dll
      C:\windows\system32\mljjjki.dll
      C:\windows\system32\mljjkjj.dll
      C:\windows\system32\nnnmmnn.dll
      C:\windows\system32\nnnnkjj.dll
      C:\windows\system32\nnnopnk.dll
      C:\windows\system32\opnlihh.dll
      C:\windows\system32\opnliji.dll
      C:\windows\system32\opnmjif.dll
      C:\windows\system32\opnmkki.dll
      C:\windows\system32\opnnoll.dll
      C:\windows\system32\opnolmk.dll
      C:\windows\system32\pmnlkkk.dll
      C:\windows\system32\pmnomjh.dll
      C:\windows\system32\pmnomnl.dll
      C:\windows\system32\qomjjgf.dll
      C:\windows\system32\qommlml.dll
      C:\WINDOWS\system32\qttss.bak1
      C:\WINDOWS\system32\qttss.bak2
      C:\WINDOWS\system32\qttss.ini
      C:\windows\system32\rqromjg.dll
      C:\windows\system32\rqrqqnk.dll
      C:\windows\system32\rqrrpmk.dll
      C:\windows\system32\rqrrsss.dll
      C:\windows\system32\rqrsppq.dll
      C:\windows\system32\rqrsqnk.dll
      C:\windows\system32\ssqpmki.dll
      C:\WINDOWS\system32\ssttq.dll
      C:\windows\system32\tfdwimvh.dll
      C:\WINDOWS\system32\tmpD9.tmp.dll
      C:\windows\system32\tqilhdsf.dll
      C:\windows\system32\tuvtutr.dll
      C:\windows\system32\tuvurpn.dll
      C:\windows\system32\tuvvwxv.dll
      C:\windows\system32\tuvwxut.dll
      C:\windows\system32\tuvwxyy.dll
      C:\windows\system32\uoldxwps.dll
      C:\windows\system32\urqpnlj.dll
      C:\windows\system32\urqppno.dll
      C:\windows\system32\urqqnlm.dll
      C:\windows\system32\urqqpqn.dll
      C:\windows\system32\vbudyouk.dll
      C:\windows\system32\vturopn.dll
      C:\windows\system32\vtuspqo.dll
      C:\windows\system32\vtusstt.dll
      C:\windows\system32\vtutqpq.dll
      C:\windows\system32\vtutrsp.dll
      C:\windows\system32\vtuustt.dll
      C:\windows\system32\wvurqom.dll
      C:\windows\system32\wvutstt.dll
      C:\windows\system32\wvuvsrr.dll
      C:\windows\system32\xmcsaqms.dll
      C:\windows\system32\xxyvsst.dll
      C:\windows\system32\xxyyaab.dll
      C:\windows\system32\yayaawt.dll
      C:\windows\system32\yayaxvu.dll
      C:\windows\system32\yaywuur.dll
      C:\windows\system32\yayywtu.dll
      C:\WINDOWS\ttutss.ini

      Beginning removal...

      Attempting to delete C:\WINDOWS\sstutt.dll
      C:\WINDOWS\sstutt.dll Has been deleted!

      Attempting to delete C:\windows\system32\awtqrqn.dll
      C:\windows\system32\awtqrqn.dll Has been deleted!

      Attempting to delete C:\windows\system32\awtrpmk.dll
      C:\windows\system32\awtrpmk.dll Has been deleted!

      Attempting to delete C:\WINDOWS\system32\awtsqpo.dll
      C:\WINDOWS\system32\awtsqpo.dll Could not be deleted.

      Attempting to delete C:\windows\system32\awtsrpq.dll
      C:\windows\system32\awtsrpq.dll Has been deleted!

      Attempting to delete C:\windows\system32\awttusr.dll
      C:\windows\system32\awttusr.dll Has been deleted!

      Attempting to delete C:\windows\system32\awvspmk.dll
      C:\windows\system32\awvspmk.dll Has been deleted!

      Attempting to delete C:\windows\system32\byxurrq.dll
      C:\windows\system32\byxurrq.dll Has been deleted!

      Attempting to delete C:\windows\system32\byxwxuv.dll
      C:\windows\system32\byxwxuv.dll Has been deleted!

      Attempting to delete C:\windows\system32\byxxusp.dll
      C:\windows\system32\byxxusp.dll Has been deleted!

      Attempting to delete C:\windows\system32\cbxuutq.dll
      C:\windows\system32\cbxuutq.dll Has been deleted!

      Attempting to delete C:\windows\system32\cbxvtut.dll
      C:\windows\system32\cbxvtut.dll Has been deleted!

      Attempting to delete C:\windows\system32\cbxwvvt.dll
      C:\windows\system32\cbxwvvt.dll Has been deleted!

      Attempting to delete C:\windows\system32\cbxwwxv.dll
      C:\windows\system32\cbxwwxv.dll Has been deleted!

      Attempting to delete C:\windows\system32\cbxxyvu.dll
      C:\windows\system32\cbxxyvu.dll Has been deleted!

      Attempting to delete C:\windows\system32\cbxywtu.dll
      C:\windows\system32\cbxywtu.dll Has been deleted!

      Attempting to delete C:\windows\system32\ddawvwu.dll
      C:\windows\system32\ddawvwu.dll Has been deleted!

      Attempting to delete C:\windows\system32\ddcaayv.dll
      C:\windows\system32\ddcaayv.dll Has been deleted!

      Attempting to delete C:\windows\system32\ddcaxwx.dll
      C:\windows\system32\ddcaxwx.dll Has been deleted!

      Attempting to delete C:\windows\system32\ddcyxyv.dll
      C:\windows\system32\ddcyxyv.dll Has been deleted!

      Attempting to delete C:\windows\system32\efcaayy.dll
      C:\windows\system32\efcaayy.dll Has been deleted!

      Attempting to delete C:\windows\system32\efcbxxw.dll
      C:\windows\system32\efcbxxw.dll Has been deleted!

      Attempting to delete C:\windows\system32\efcyaba.dll
      C:\windows\system32\efcyaba.dll Has been deleted!

      Attempting to delete C:\windows\system32\efcyyxv.dll
      C:\windows\system32\efcyyxv.dll Has been deleted!

      Attempting to delete C:\windows\system32\fccawus.dll
      C:\windows\system32\fccawus.dll Has been deleted!

      Attempting to delete C:\windows\system32\fccbxvs.dll
      C:\windows\system32\fccbxvs.dll Has been deleted!

      Attempting to delete C:\windows\system32\fccccby.dll
      C:\windows\system32\fccccby.dll Has been deleted!

      Attempting to delete C:\windows\system32\fccyaby.dll
      C:\windows\system32\fccyaby.dll Has been deleted!

      Attempting to delete C:\windows\system32\fccyyaa.dll
      C:\wind
      VundoFix V6.5.8

      Checking Java version...

      Java version is 1.5.0.3
      Old versions of java are exploitable and should be removed.

      Scan started at 11:35:58 2007-09-09

      Listing files found while scanning....

      C:\WINDOWS\sstutt.dll
      C:\windows\system32\awtsqpo.dll
      C:\windows\system32\fjlluena.dll
      C:\windows\system32\gebaaya.dll
      C:\windows\system32\gebabyy.dll
      C:\windows\system32\gebaywv.dll
      C:\windows\system32\gebxusr.dll
      C:\windows\system32\gebxwvs.dll
      C:\windows\system32\gebyaxx.dll
      C:\windows\system32\hggdebc.dll
      C:\windows\system32\hggfdba.dll
      C:\windows\system32\hgghebb.dll
      C:\windows\system32\hgghedc.dll
      C:\windows\system32\hgghgff.dll
      C:\windows\system32\hgghhif.dll
      C:\windows\system32\hsacgmrj.dll
      C:\windows\system32\iifefff.dll
      C:\windows\system32\jjssqfte.dll
      C:\windows\system32\jkkhfdc.dll
      C:\windows\system32\jkkjgfg.dll
      C:\windows\system32\jkkkjgg.dll
      C:\windows\system32\khfcbay.dll
      C:\windows\system32\khfcdee.dll
      C:\windows\system32\khfdccc.dll
      C:\windows\system32\khfeccb.dll
      C:\windows\system32\khfecdd.dll
      C:\windows\system32\khffeca.dll
      C:\windows\system32\khfgfda.dll
      C:\windows\system32\khfgfef.dll
      C:\windows\system32\khfgffc.dll
      C:\windows\system32\khfggde.dll
      C:\windows\system32\khfghif.dll
      C:\windows\system32\ljjgdee.dll
      C:\windows\system32\ljjhfec.dll
      C:\windows\system32\ljjhghf.dll
      C:\windows\system32\ljjhghi.dll
      C:\windows\system32\ljjkigf.dll
      C:\windows\system32\ljjkkjg.dll
      C:\windows\system32\mljghhe.dll
      C:\windows\system32\mljhijj.dll
      C:\windows\system32\mljjiig.dll
      C:\windows\system32\mljjjki.dll
      C:\windows\system32\mljjkjj.dll
      C:\windows\system32\nnnmmnn.dll
      C:\windows\system32\nnnnkjj.dll
      C:\windows\system32\nnnopnk.dll
      C:\windows\system32\opnlihh.dll
      C:\windows\system32\opnliji.dll
      C:\windows\system32\opnmjif.dll
      C:\windows\system32\opnmkki.dll
      C:\windows\system32\opnnoll.dll
      C:\windows\system32\opnolmk.dll
      C:\windows\system32\pmnlkkk.dll
      C:\windows\system32\pmnomjh.dll
      C:\windows\system32\pmnomnl.dll
      C:\windows\system32\qomjjgf.dll
      C:\WINDOWS\system32\qomjjji.dll
      C:\windows\system32\qommlml.dll
      C:\WINDOWS\system32\qttss.bak1
      C:\WINDOWS\system32\qttss.bak2
      C:\WINDOWS\system32\qttss.ini
      C:\windows\system32\rqromjg.dll
      C:\windows\system32\rqrqqnk.dll
      C:\windows\system32\rqrrpmk.dll
      C:\windows\system32\rqrrsss.dll
      C:\windows\system32\rqrsppq.dll
      C:\windows\system32\rqrsqnk.dll
      C:\windows\system32\ssqpmki.dll
      C:\WINDOWS\system32\ssttq.dll
      C:\windows\system32\tfdwimvh.dll
      C:\WINDOWS\system32\tmpD9.tmp.dll
      C:\windows\system32\tqilhdsf.dll
      C:\windows\system32\tuvtutr.dll
      C:\windows\system32\tuvurpn.dll
      C:\windows\system32\tuvvwxv.dll
      C:\windows\system32\tuvwxut.dll
      C:\windows\system32\tuvwxyy.dll
      C:\windows\system32\uoldxwps.dll
      C:\windows\system32\urqpnlj.dll
      C:\windows\system32\urqppno.dll
      C:\windows\system32\urqqnlm.dll
      C:\windows\system32\urqqpqn.dll
      C:\windows\system32\vbudyouk.dll
      C:\windows\system32\vturopn.dll
      C:\windows\system32\vtuspqo.dll
      C:\windows\system32\vtusstt.dll
      C:\windows\system32\vtutqpq.dll
      C:\windows\system32\vtutrsp.dll
      C:\windows\system32\vtuustt.dll
      C:\windows\system32\wvurqom.dll
      C:\windows\system32\wvutstt.dll
      C:\windows\system32\wvuvsrr.dll
      C:\windows\system32\xmcsaqms.dll
      C:\windows\system32\xxyvsst.dll
      C:\windows\system32\xxyyaab.dll
      C:\windows\system32\yayaawt.dll
      C:\windows\system32\yayaxvu.dll
      C:\windows\system32\yaywuur.dll
      C:\windows\system32\yayywtu.dll
      C:\WINDOWS\ttutss.ini

      Beginning removal...

      Attempting to delete C:\windows\system32\awtsqpo.dll
      C:\windows\system32\awtsqpo.dll Has been deleted!

      Attempting to delete C:\windows\system32\fjlluena.dll
      C:\windows\system32\fjlluena.dll Has been deleted!

      Attempting to delete C:\windows\system32\gebaaya.dll
      C:\windows\system32\gebaaya.dll Has been deleted!

      Attempting to delete C:\windows\system32\gebabyy.dll
      C:\windows\system32\gebabyy.dll Has been deleted!

      Attempting to delete C:\windows\system32\gebaywv.dll
      C:\windows\system32\gebaywv.dll Has been deleted!

      Attempting to delete C:\windows\system32\gebxusr.dll
      C:\windows\system32\gebxusr.dll Has been deleted!

      Attempting to delete C:\windows\system32\gebxwvs.dll
      C:\windows\system32\gebxwvs.dll Has been deleted!

      Attempting to delete C:\windows\system32\gebyaxx.dll
      C:\windows\system32\gebyaxx.dll Has been deleted!

      Attempting to delete C:\windows\system32\hggdebc.dll
      C:\windows\system32\hggdebc.dll Has been deleted!

      Attempting to delete C:\windows\system32\hggfdba.dll
      C:\windows\system32\hggfdba.dll Has been deleted!

      Attempting to delete C:\windows\system32\hgghebb.dll
      C:\windows\system32\hgghebb.dll Has been deleted!

      Attempting to delete C:\windows\system32\hgghedc.dll
      C:\windows\system32\hgghedc.dll Has been deleted!

      Attempting to delete C:\windows\system32\hgghgff.dll
      C:\windows\system32\hgghgff.dll Has been deleted!

      Attempting to delete C:\windows\system32\hgghhif.dll
      C:\windows\system32\hgghhif.dll Has been deleted!

      Attempting to delete C:\windows\system32\hsacgmrj.dll
      C:\windows\system32\hsacgmrj.dll Has been deleted!

      Attempting to delete C:\windows\system32\iifefff.dll
      C:\windows\system32\iifefff.dll Has been deleted!

      Attempting to delete C:\windows\system32\jjssqfte.dll
      C:\windows\system32\jjssqfte.dll Has been deleted!

      Attempting to delete C:\windows\system32\jkkhfdc.dll
      C:\windows\system32\jkkhfdc.dll Has been deleted!

      Attempting to delete C:\windows\system32\jkkjgfg.dll
      C:\windows\system32\jkkjgfg.dll Has been deleted!

      Attempting to delete C:\windows\system32\jkkkjgg.dll
      C:\windows\system32\jkkkjgg.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfcbay.dll
      C:\windows\system32\khfcbay.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfcdee.dll
      C:\windows\system32\khfcdee.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfdccc.dll
      C:\windows\system32\khfdccc.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfeccb.dll
      C:\windows\system32\khfeccb.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfecdd.dll
      C:\windows\system32\khfecdd.dll Has been deleted!

      Attempting to delete C:\windows\system32\khffeca.dll
      C:\windows\system32\khffeca.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfgfda.dll
      C:\windows\system32\khfgfda.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfgfef.dll
      C:\windows\system32\khfgfef.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfgffc.dll
      C:\windows\system32\khfgffc.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfggde.dll
      C:\windows\system32\khfggde.dll Has been deleted!

      Attempting to delete C:\windows\system32\khfghif.dll
      C:\windows\system32\khfghif.dll Has been deleted!

      Attempting to delete C:\windows\system32\ljjgdee.dll
      C:\windows\system32\ljjgdee.dll Has been deleted!

      Attempting to delete C:\windows\system32\ljjhfec.dll
      C:\windows\system32\ljjhfec.dll Has been deleted!

      Attempting to delete C:\windows\system32\ljjhghf.dll
      C:\windows\system32\ljjhghf.dll Has been deleted!

      Attempting to delete C:\windows\system32\ljjhghi.dll
      C:\windows\system32\ljjhghi.dll Has been deleted!

      Attempting to delete C:\windows\system32\ljjkigf.dll
      C:\windows\system32\ljjkigf.dll Has been deleted!

      Attempting to delete C:\windows\system32\ljjkkjg.dll
      C:\windows\system32\ljjkkjg.dll Has been deleted!

      Attempting to delete C:\windows\system32\mljghhe.dll
      C:\windows\system32\mljghhe.dll Has been deleted!

      Attempting to delete C:\windows\system32\mljhijj.dll
      C:\windows\system32\mljhijj.dll Has been deleted!

      Attempting to delete C:\windows\system32\mljjiig.dll
      C:\windows\system32\mljjiig.dll Has been deleted!

      Attempting to delete C:\windows\system32\mljjjki.dll
      C:\windows\system32\mljjjki.dll Has been deleted!

      Attempting to delete C:\windows\system32\mljjkjj.dll
      C:\windows\system32\mljjkjj.dll Has been deleted!

      Attempting to delete C:\windows\system32\nnnmmnn.dll
      C:\windows\system32\nnnmmnn.dll Has been deleted!

      Attempting to delete C:\windows\system32\nnnnkjj.dll
      C:\windows\system32\nnnnkjj.dll Has been deleted!

      Attempting to delete C:\windows\system32\nnnopnk.dll
      C:\windows\system32\nnnopnk.dll Has been deleted!

      Attempting to delete C:\windows\system32\opnlihh.dll
      C:\windows\system32\opnlihh.dll Has been deleted!

      Attempting to delete C:\windows\system32\opnliji.dll
      C:\windows\system32\opnliji.dll Has been deleted!

      Attempting to delete C:\windows\system32\opnmjif.dll
      C:\windows\system32\opnmjif.dll Has been deleted!

      Attempting to delete C:\windows\system32\opnmkki.dll
      C:\windows\system32\opnmkki.dll Has been deleted!

      Attempting to delete C:\windows\system32\opnnoll.dll
      C:\windows\system32\opnnoll.dll Has been deleted!

      Attempting to delete C:\windows\system32\opnolmk.dll
      C:\windows\system32\opnolmk.dll Has been deleted!

      Attempting to delete C:\windows\system32\pmnlkkk.dll
      C:\windows\system32\pmnlkkk.dll Has been deleted!

      Attempting to delete C:\windows\system32\pmnomjh.dll
      C:\windows\system32\pmnomjh.dll Has been deleted!

      Attempting to delete C:\windows\system32\pmnomnl.dll
      C:\windows\system32\pmnomnl.dll Has been deleted!

      Attempting to delete C:\windows\system32\qomjjgf.dll
      C:\windows\system32\qomjjgf.dll Has been deleted!

      Attempting to delete C:\WINDOWS\system32\qomjjji.dll
      C:\WINDOWS\system32\qomjjji.dll Could not be deleted.

      Attempting to delete C:\windows\system32\qommlml.dll
      C:\windows\system32\qommlml.dll Has been deleted!

      Attempting to delete C:\WINDOWS\system32\qttss.bak1
      C:\WINDOWS\system32\qttss.bak1 Has been deleted!

      Attempting to delete C:\WINDOWS\system32\qttss.bak2
      C:\WINDOWS\system32\qttss.bak2 Has been deleted!

      Attempting to delete C:\WINDOWS\system32\qttss.ini
      C:\WINDOWS\system32\qttss.ini Has been deleted!

      Attempting to delete C:\windows\system32\rqromjg.dll
      C:\windows\system32\rqromjg.dll Has been deleted!

      Attempting to delete C:\windows\system32\rqrqqnk.dll
      C:\windows\system32\rqrqqnk.dll Has been deleted!

      Attempting to delete C:\windows\system32\rqrrpmk.dll
      C:\windows\system32\rqrrpmk.dll Has been deleted!

      Attempting to delete C:\windows\system32\rqrrsss.dll
      C:\windows\system32\rqrrsss.dll Has been deleted!

      Attempting to delete C:\windows\system32\rqrsppq.dll
      C:\windows\system32\rqrsppq.dll Has been deleted!

      Attempting to delete C:\windows\system32\rqrsqnk.dll
      C:\windows\system32\rqrsqnk.dll Has been deleted!

      Attempting to delete C:\windows\system32\ssqpmki.dll
      C:\windows\system32\ssqpmki.dll Has been deleted!

      Attempting to delete C:\WINDOWS\system32\ssttq.dll
      C:\WINDOWS\system32\ssttq.dll Could not be deleted.

      Attempting to delete C:\windows\system32\tfdwimvh.dll
      C:\windows\system32\tfdwimvh.dll Has been deleted!

      Attempting to delete C:\WINDOWS\system32\tmpD9.tmp.dll
      C:\WINDOWS\system32\tmpD9.tmp.dll Has been deleted!

      Attempting to delete C:\windows\system32\tqilhdsf.dll
      C:\windows\system32\tqilhdsf.dll Has been deleted!

      Attempting to delete C:\windows\system32\tuvtutr.dll
      C:\windows\system32\tuvtutr.dll Has been deleted!

      Attempting to delete C:\windows\system32\tuvurpn.dll
      C:\windows\system32\tuvurpn.dll Has been deleted!

      Attempting to delete C:\windows\system32\tuvvwxv.dll
      C:\windows\system32\tuvvwxv.dll Has been deleted!

      Attempting to delete C:\windows\system32\tuvwxut.dll
      C:\windows\system32\tuvwxut.dll Has been deleted!

      Attempting to delete C:\windows\system32\tuvwxyy.dll
      C:\windows\system32\tuvwxyy.dll Has been deleted!

      Attempting to delete C:\windows\system32\uoldxwps.dll
      C:\windows\system32\uoldxwps.dll Has been deleted!

      Attempting to delete C:\windows\system32\urqpnlj.dll
      C:\windows\system32\urqpnlj.dll Has been deleted!

      Attempting to delete C:\windows\system32\urqppno.dll
      C:\windows\system32\urqppno.dll Has been deleted!

      Attempting to delete C:\windows\system32\urqqnlm.dll
      C:\windows\system32\urqqnlm.dll Has been deleted!

      Attempting to delete C:\windows\system32\urqqpqn.dll
      C:\windows\system32\urqqpqn.dll Has been deleted!

      Attempting to delete C:\windows\system32\vbudyouk.dll
      C:\windows\system32\vbudyouk.dll Has been deleted!

      Attempting to delete C:\windows\system32\vturopn.dll
      C:\windows\system32\vturopn.dll Has been deleted!

      Attempting to delete C:\windows\system32\vtuspqo.dll
      C:\windows\system32\vtuspqo.dll Has been deleted!

      Attempting to delete C:\windows\system32\vtusstt.dll
      C:\windows\system32\vtusstt.dll Has been deleted!

      Attempting to delete C:\windows\system32\vtutqpq.dll
      C:\windows\system32\vtutqpq.dll Has been deleted!

      Attempting to delete C:\windows\system32\vtutrsp.dll
      C:\windows\system32\vtutrsp.dll Has been deleted!

      Attempting to delete C:\windows\system32\vtuustt.dll
      C:\windows\system32\vtuustt.dll Has been deleted!

      Attempting to delete C:\windows\system32\wvurqom.dll
      C:\windows\system32\wvurqom.dll Has been deleted!

      Attempting to delete C:\windows\system32\wvutstt.dll
      C:\windows\system32\wvutstt.dll Has been deleted!

      Attempting to delete C:\windows\system32\wvuvsrr.dll
      C:\windows\system32\wvuvsrr.dll Has been deleted!

      Attempting to delete C:\windows\system32\xmcsaqms.dll
      C:\windows\system32\xmcsaqms.dll Has been deleted!

      Attempting to delete C:\windows\system32\xxyvsst.dll
      C:\windows\system32\xxyvsst.dll Has been deleted!

      Attempting to delete C:\windows\system32\xxyyaab.dll
      C:\windows\system32\xxyyaab.dll Has been deleted!

      Attempting to delete C:\windows\system32\yayaawt.dll
      C:\windows\system32\yayaawt.dll Has been deleted!

      Attempting to delete C:\windows\system32\yayaxvu.dll
      C:\windows\system32\yayaxvu.dll Has been deleted!

      Attempting to delete C:\windows\system32\yaywuur.dll
      C:\windows\system32\yaywuur.dll Has been deleted!

      Attempting to delete C:\windows\system32\yayywtu.dll
      C:\windows\system32\yayywtu.dll Has been deleted!

      Attempting to delete C:\WINDOWS\ttutss.ini
      C:\WINDOWS\ttutss.ini Has been deleted!

      Performing Repairs to the registry.
      Done!

      VundoFix V6.5.8

      Checking Java version...

      Java version is 1.5.0.3
      Old versions of java are exploitable and should be removed.

      Scan started at 11:47:19 2007-09-09

      Listing files found while scanning....

      C:\windows\system32\qomjjji.dll
      C:\windows\system32\ssttq.dll

      Beginning removal...

      Attempting to delete C:\windows\system32\qomjjji.dll
      C:\windows\system32\qomjjji.dll Has been deleted!

      Attempting to delete C:\windows\system32\ssttq.dll
      C:\windows\system32\ssttq.dll Has been deleted!

      Performing Repairs to the registry.
      Done!

      VundoFix V6.5.8

      Checking Java version...

      Java version is 1.5.0.3
      Old versions of java are exploitable and should be removed.

      Scan started at 11:51:55 2007-09-09

      Listing files found while scanning....

      C:\windows\system32\opnnllj.dll

      Beginning removal...

      Attempting to delete C:\windows\system32\opnnllj.dll
      C:\windows\system32\opnnllj.dll Could not be deleted.

      Performing Repairs to the registry.
      Done!

      Beginning removal...

      Attempting to delete C:\windows\system32\opnnllj.dll
      C:\windows\system32\opnnllj.dll Has been deleted!

      Performing Repairs to the registry.
      Done!






      Rapport De Hijackthis

      Logfile of HijackThis v1.99.1
      Scan saved at 11:58:17, on 2007-09-09
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\SYSTEM32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\WINDOWS\ATKKBService.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/granby
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {768FEE08-9B75-4653-A2CD-8822C83A5453} - C:\WINDOWS\system32\ssttq.dll (file missing)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\vhmjydfi.exe (file missing)
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


      jai comme une impression que sa a pas changé grand chose pcq jai encore les alerte de virus c vrm chiant :S
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    bonjour,
    ok mais dit moi si je dois commencer par les etape de ton premier message avant dembarquer sur Vundofix ou je dois commencer par Vundofix ???


    non tu fais dans l'ordre stp.

    et pour se qui est c CCleaner est ce que je dois coché TOUTES les case dans (Windows) et dans (application)


    tu le laisses en l'état une fois que tu l'as téléchargé et installé, tu lances simplement le nettoyage uniquement le nettoyage

    p.s. historique des saisie automatique nest surement pas obligatoire !?!?!?!?!? 


    je n'ai pas compris

    0
  7. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    bonjour,

    * Fait un scan antivirus en ligne ICI
    https://www.bitdefender.fr/
    et copie colle le résultat ici
    * En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
    * Dans la nouvelle fenêtre, clique sur I agree
    * La fenêtre change encore, clique sur Click here to scan
    * Les signatures se chargent, etc.

    tuto en image

    http://pageperso.aol.fr/rginformatique/mapage/defender.htm

    0
  8. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    re

    pourquoi es tu allé poster au dessus, difficile de s'y retrouver, aussi je mets tout ton rapport ici

    Rapport VundoFix

    VundoFix V6.5.8

    Checking Java version...

    Java version is 1.5.0.3
    Old versions of java are exploitable and should be removed.

    Scan started at 10:46:54 2007-09-09

    Listing files found while scanning....

    C:\WINDOWS\sstutt.dll
    C:\windows\system32\awtqrqn.dll
    C:\windows\system32\awtrpmk.dll
    C:\WINDOWS\system32\awtsqpo.dll
    C:\windows\system32\awtsrpq.dll
    C:\windows\system32\awttusr.dll
    C:\windows\system32\awvspmk.dll
    C:\windows\system32\byxurrq.dll
    C:\windows\system32\byxwxuv.dll
    C:\windows\system32\byxxusp.dll
    C:\windows\system32\cbxuutq.dll
    C:\windows\system32\cbxvtut.dll
    C:\windows\system32\cbxwvvt.dll
    C:\windows\system32\cbxwwxv.dll
    C:\windows\system32\cbxxyvu.dll
    C:\windows\system32\cbxywtu.dll
    C:\windows\system32\ddawvwu.dll
    C:\windows\system32\ddcaayv.dll
    C:\windows\system32\ddcaxwx.dll
    C:\windows\system32\ddcyxyv.dll
    C:\windows\system32\efcaayy.dll
    C:\windows\system32\efcbxxw.dll
    C:\windows\system32\efcyaba.dll
    C:\windows\system32\efcyyxv.dll
    C:\windows\system32\fccawus.dll
    C:\windows\system32\fccbxvs.dll
    C:\windows\system32\fccccby.dll
    C:\windows\system32\fccyaby.dll
    C:\windows\system32\fccyyaa.dll
    C:\windows\system32\fjlluena.dll
    C:\windows\system32\gebaaya.dll
    C:\windows\system32\gebabyy.dll
    C:\windows\system32\gebaywv.dll
    C:\windows\system32\gebxusr.dll
    C:\windows\system32\gebxwvs.dll
    C:\windows\system32\gebyaxx.dll
    C:\windows\system32\hggdebc.dll
    C:\windows\system32\hggfdba.dll
    C:\windows\system32\hgghebb.dll
    C:\windows\system32\hgghedc.dll
    C:\windows\system32\hgghgff.dll
    C:\windows\system32\hgghhif.dll
    C:\windows\system32\hsacgmrj.dll
    C:\windows\system32\iifefff.dll
    C:\windows\system32\jjssqfte.dll
    C:\windows\system32\jkkhfdc.dll
    C:\windows\system32\jkkjgfg.dll
    C:\windows\system32\jkkkjgg.dll
    C:\windows\system32\khfcbay.dll
    C:\windows\system32\khfcdee.dll
    C:\windows\system32\khfdccc.dll
    C:\windows\system32\khfeccb.dll
    C:\windows\system32\khfecdd.dll
    C:\windows\system32\khffeca.dll
    C:\windows\system32\khfgfda.dll
    C:\windows\system32\khfgfef.dll
    C:\windows\system32\khfgffc.dll
    C:\windows\system32\khfggde.dll
    C:\windows\system32\khfghif.dll
    C:\windows\system32\ljjgdee.dll
    C:\windows\system32\ljjhfec.dll
    C:\windows\system32\ljjhghf.dll
    C:\windows\system32\ljjhghi.dll
    C:\windows\system32\ljjkigf.dll
    C:\windows\system32\ljjkkjg.dll
    C:\windows\system32\mljghhe.dll
    C:\windows\system32\mljhijj.dll
    C:\windows\system32\mljjiig.dll
    C:\windows\system32\mljjjki.dll
    C:\windows\system32\mljjkjj.dll
    C:\windows\system32\nnnmmnn.dll
    C:\windows\system32\nnnnkjj.dll
    C:\windows\system32\nnnopnk.dll
    C:\windows\system32\opnlihh.dll
    C:\windows\system32\opnliji.dll
    C:\windows\system32\opnmjif.dll
    C:\windows\system32\opnmkki.dll
    C:\windows\system32\opnnoll.dll
    C:\windows\system32\opnolmk.dll
    C:\windows\system32\pmnlkkk.dll
    C:\windows\system32\pmnomjh.dll
    C:\windows\system32\pmnomnl.dll
    C:\windows\system32\qomjjgf.dll
    C:\windows\system32\qommlml.dll
    C:\WINDOWS\system32\qttss.bak1
    C:\WINDOWS\system32\qttss.bak2
    C:\WINDOWS\system32\qttss.ini
    C:\windows\system32\rqromjg.dll
    C:\windows\system32\rqrqqnk.dll
    C:\windows\system32\rqrrpmk.dll
    C:\windows\system32\rqrrsss.dll
    C:\windows\system32\rqrsppq.dll
    C:\windows\system32\rqrsqnk.dll
    C:\windows\system32\ssqpmki.dll
    C:\WINDOWS\system32\ssttq.dll
    C:\windows\system32\tfdwimvh.dll
    C:\WINDOWS\system32\tmpD9.tmp.dll
    C:\windows\system32\tqilhdsf.dll
    C:\windows\system32\tuvtutr.dll
    C:\windows\system32\tuvurpn.dll
    C:\windows\system32\tuvvwxv.dll
    C:\windows\system32\tuvwxut.dll
    C:\windows\system32\tuvwxyy.dll
    C:\windows\system32\uoldxwps.dll
    C:\windows\system32\urqpnlj.dll
    C:\windows\system32\urqppno.dll
    C:\windows\system32\urqqnlm.dll
    C:\windows\system32\urqqpqn.dll
    C:\windows\system32\vbudyouk.dll
    C:\windows\system32\vturopn.dll
    C:\windows\system32\vtuspqo.dll
    C:\windows\system32\vtusstt.dll
    C:\windows\system32\vtutqpq.dll
    C:\windows\system32\vtutrsp.dll
    C:\windows\system32\vtuustt.dll
    C:\windows\system32\wvurqom.dll
    C:\windows\system32\wvutstt.dll
    C:\windows\system32\wvuvsrr.dll
    C:\windows\system32\xmcsaqms.dll
    C:\windows\system32\xxyvsst.dll
    C:\windows\system32\xxyyaab.dll
    C:\windows\system32\yayaawt.dll
    C:\windows\system32\yayaxvu.dll
    C:\windows\system32\yaywuur.dll
    C:\windows\system32\yayywtu.dll
    C:\WINDOWS\ttutss.ini

    Beginning removal...

    Attempting to delete C:\WINDOWS\sstutt.dll
    C:\WINDOWS\sstutt.dll Has been deleted!

    Attempting to delete C:\windows\system32\awtqrqn.dll
    C:\windows\system32\awtqrqn.dll Has been deleted!

    Attempting to delete C:\windows\system32\awtrpmk.dll
    C:\windows\system32\awtrpmk.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\awtsqpo.dll
    C:\WINDOWS\system32\awtsqpo.dll Could not be deleted.

    Attempting to delete C:\windows\system32\awtsrpq.dll
    C:\windows\system32\awtsrpq.dll Has been deleted!

    Attempting to delete C:\windows\system32\awttusr.dll
    C:\windows\system32\awttusr.dll Has been deleted!

    Attempting to delete C:\windows\system32\awvspmk.dll
    C:\windows\system32\awvspmk.dll Has been deleted!

    Attempting to delete C:\windows\system32\byxurrq.dll
    C:\windows\system32\byxurrq.dll Has been deleted!

    Attempting to delete C:\windows\system32\byxwxuv.dll
    C:\windows\system32\byxwxuv.dll Has been deleted!

    Attempting to delete C:\windows\system32\byxxusp.dll
    C:\windows\system32\byxxusp.dll Has been deleted!

    Attempting to delete C:\windows\system32\cbxuutq.dll
    C:\windows\system32\cbxuutq.dll Has been deleted!

    Attempting to delete C:\windows\system32\cbxvtut.dll
    C:\windows\system32\cbxvtut.dll Has been deleted!

    Attempting to delete C:\windows\system32\cbxwvvt.dll
    C:\windows\system32\cbxwvvt.dll Has been deleted!

    Attempting to delete C:\windows\system32\cbxwwxv.dll
    C:\windows\system32\cbxwwxv.dll Has been deleted!

    Attempting to delete C:\windows\system32\cbxxyvu.dll
    C:\windows\system32\cbxxyvu.dll Has been deleted!

    Attempting to delete C:\windows\system32\cbxywtu.dll
    C:\windows\system32\cbxywtu.dll Has been deleted!

    Attempting to delete C:\windows\system32\ddawvwu.dll
    C:\windows\system32\ddawvwu.dll Has been deleted!

    Attempting to delete C:\windows\system32\ddcaayv.dll
    C:\windows\system32\ddcaayv.dll Has been deleted!

    Attempting to delete C:\windows\system32\ddcaxwx.dll
    C:\windows\system32\ddcaxwx.dll Has been deleted!

    Attempting to delete C:\windows\system32\ddcyxyv.dll
    C:\windows\system32\ddcyxyv.dll Has been deleted!

    Attempting to delete C:\windows\system32\efcaayy.dll
    C:\windows\system32\efcaayy.dll Has been deleted!

    Attempting to delete C:\windows\system32\efcbxxw.dll
    C:\windows\system32\efcbxxw.dll Has been deleted!

    Attempting to delete C:\windows\system32\efcyaba.dll
    C:\windows\system32\efcyaba.dll Has been deleted!

    Attempting to delete C:\windows\system32\efcyyxv.dll
    C:\windows\system32\efcyyxv.dll Has been deleted!

    Attempting to delete C:\windows\system32\fccawus.dll
    C:\windows\system32\fccawus.dll Has been deleted!

    Attempting to delete C:\windows\system32\fccbxvs.dll
    C:\windows\system32\fccbxvs.dll Has been deleted!

    Attempting to delete C:\windows\system32\fccccby.dll
    C:\windows\system32\fccccby.dll Has been deleted!

    Attempting to delete C:\windows\system32\fccyaby.dll
    C:\windows\system32\fccyaby.dll Has been deleted!

    Attempting to delete C:\windows\system32\fccyyaa.dll
    C:\wind
    VundoFix V6.5.8

    Checking Java version...

    Java version is 1.5.0.3
    Old versions of java are exploitable and should be removed.

    Scan started at 11:35:58 2007-09-09

    Listing files found while scanning....

    C:\WINDOWS\sstutt.dll
    C:\windows\system32\awtsqpo.dll
    C:\windows\system32\fjlluena.dll
    C:\windows\system32\gebaaya.dll
    C:\windows\system32\gebabyy.dll
    C:\windows\system32\gebaywv.dll
    C:\windows\system32\gebxusr.dll
    C:\windows\system32\gebxwvs.dll
    C:\windows\system32\gebyaxx.dll
    C:\windows\system32\hggdebc.dll
    C:\windows\system32\hggfdba.dll
    C:\windows\system32\hgghebb.dll
    C:\windows\system32\hgghedc.dll
    C:\windows\system32\hgghgff.dll
    C:\windows\system32\hgghhif.dll
    C:\windows\system32\hsacgmrj.dll
    C:\windows\system32\iifefff.dll
    C:\windows\system32\jjssqfte.dll
    C:\windows\system32\jkkhfdc.dll
    C:\windows\system32\jkkjgfg.dll
    C:\windows\system32\jkkkjgg.dll
    C:\windows\system32\khfcbay.dll
    C:\windows\system32\khfcdee.dll
    C:\windows\system32\khfdccc.dll
    C:\windows\system32\khfeccb.dll
    C:\windows\system32\khfecdd.dll
    C:\windows\system32\khffeca.dll
    C:\windows\system32\khfgfda.dll
    C:\windows\system32\khfgfef.dll
    C:\windows\system32\khfgffc.dll
    C:\windows\system32\khfggde.dll
    C:\windows\system32\khfghif.dll
    C:\windows\system32\ljjgdee.dll
    C:\windows\system32\ljjhfec.dll
    C:\windows\system32\ljjhghf.dll
    C:\windows\system32\ljjhghi.dll
    C:\windows\system32\ljjkigf.dll
    C:\windows\system32\ljjkkjg.dll
    C:\windows\system32\mljghhe.dll
    C:\windows\system32\mljhijj.dll
    C:\windows\system32\mljjiig.dll
    C:\windows\system32\mljjjki.dll
    C:\windows\system32\mljjkjj.dll
    C:\windows\system32\nnnmmnn.dll
    C:\windows\system32\nnnnkjj.dll
    C:\windows\system32\nnnopnk.dll
    C:\windows\system32\opnlihh.dll
    C:\windows\system32\opnliji.dll
    C:\windows\system32\opnmjif.dll
    C:\windows\system32\opnmkki.dll
    C:\windows\system32\opnnoll.dll
    C:\windows\system32\opnolmk.dll
    C:\windows\system32\pmnlkkk.dll
    C:\windows\system32\pmnomjh.dll
    C:\windows\system32\pmnomnl.dll
    C:\windows\system32\qomjjgf.dll
    C:\WINDOWS\system32\qomjjji.dll
    C:\windows\system32\qommlml.dll
    C:\WINDOWS\system32\qttss.bak1
    C:\WINDOWS\system32\qttss.bak2
    C:\WINDOWS\system32\qttss.ini
    C:\windows\system32\rqromjg.dll
    C:\windows\system32\rqrqqnk.dll
    C:\windows\system32\rqrrpmk.dll
    C:\windows\system32\rqrrsss.dll
    C:\windows\system32\rqrsppq.dll
    C:\windows\system32\rqrsqnk.dll
    C:\windows\system32\ssqpmki.dll
    C:\WINDOWS\system32\ssttq.dll
    C:\windows\system32\tfdwimvh.dll
    C:\WINDOWS\system32\tmpD9.tmp.dll
    C:\windows\system32\tqilhdsf.dll
    C:\windows\system32\tuvtutr.dll
    C:\windows\system32\tuvurpn.dll
    C:\windows\system32\tuvvwxv.dll
    C:\windows\system32\tuvwxut.dll
    C:\windows\system32\tuvwxyy.dll
    C:\windows\system32\uoldxwps.dll
    C:\windows\system32\urqpnlj.dll
    C:\windows\system32\urqppno.dll
    C:\windows\system32\urqqnlm.dll
    C:\windows\system32\urqqpqn.dll
    C:\windows\system32\vbudyouk.dll
    C:\windows\system32\vturopn.dll
    C:\windows\system32\vtuspqo.dll
    C:\windows\system32\vtusstt.dll
    C:\windows\system32\vtutqpq.dll
    C:\windows\system32\vtutrsp.dll
    C:\windows\system32\vtuustt.dll
    C:\windows\system32\wvurqom.dll
    C:\windows\system32\wvutstt.dll
    C:\windows\system32\wvuvsrr.dll
    C:\windows\system32\xmcsaqms.dll
    C:\windows\system32\xxyvsst.dll
    C:\windows\system32\xxyyaab.dll
    C:\windows\system32\yayaawt.dll
    C:\windows\system32\yayaxvu.dll
    C:\windows\system32\yaywuur.dll
    C:\windows\system32\yayywtu.dll
    C:\WINDOWS\ttutss.ini

    Beginning removal...

    Attempting to delete C:\windows\system32\awtsqpo.dll
    C:\windows\system32\awtsqpo.dll Has been deleted!

    Attempting to delete C:\windows\system32\fjlluena.dll
    C:\windows\system32\fjlluena.dll Has been deleted!

    Attempting to delete C:\windows\system32\gebaaya.dll
    C:\windows\system32\gebaaya.dll Has been deleted!

    Attempting to delete C:\windows\system32\gebabyy.dll
    C:\windows\system32\gebabyy.dll Has been deleted!

    Attempting to delete C:\windows\system32\gebaywv.dll
    C:\windows\system32\gebaywv.dll Has been deleted!

    Attempting to delete C:\windows\system32\gebxusr.dll
    C:\windows\system32\gebxusr.dll Has been deleted!

    Attempting to delete C:\windows\system32\gebxwvs.dll
    C:\windows\system32\gebxwvs.dll Has been deleted!

    Attempting to delete C:\windows\system32\gebyaxx.dll
    C:\windows\system32\gebyaxx.dll Has been deleted!

    Attempting to delete C:\windows\system32\hggdebc.dll
    C:\windows\system32\hggdebc.dll Has been deleted!

    Attempting to delete C:\windows\system32\hggfdba.dll
    C:\windows\system32\hggfdba.dll Has been deleted!

    Attempting to delete C:\windows\system32\hgghebb.dll
    C:\windows\system32\hgghebb.dll Has been deleted!

    Attempting to delete C:\windows\system32\hgghedc.dll
    C:\windows\system32\hgghedc.dll Has been deleted!

    Attempting to delete C:\windows\system32\hgghgff.dll
    C:\windows\system32\hgghgff.dll Has been deleted!

    Attempting to delete C:\windows\system32\hgghhif.dll
    C:\windows\system32\hgghhif.dll Has been deleted!

    Attempting to delete C:\windows\system32\hsacgmrj.dll
    C:\windows\system32\hsacgmrj.dll Has been deleted!

    Attempting to delete C:\windows\system32\iifefff.dll
    C:\windows\system32\iifefff.dll Has been deleted!

    Attempting to delete C:\windows\system32\jjssqfte.dll
    C:\windows\system32\jjssqfte.dll Has been deleted!

    Attempting to delete C:\windows\system32\jkkhfdc.dll
    C:\windows\system32\jkkhfdc.dll Has been deleted!

    Attempting to delete C:\windows\system32\jkkjgfg.dll
    C:\windows\system32\jkkjgfg.dll Has been deleted!

    Attempting to delete C:\windows\system32\jkkkjgg.dll
    C:\windows\system32\jkkkjgg.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfcbay.dll
    C:\windows\system32\khfcbay.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfcdee.dll
    C:\windows\system32\khfcdee.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfdccc.dll
    C:\windows\system32\khfdccc.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfeccb.dll
    C:\windows\system32\khfeccb.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfecdd.dll
    C:\windows\system32\khfecdd.dll Has been deleted!

    Attempting to delete C:\windows\system32\khffeca.dll
    C:\windows\system32\khffeca.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfgfda.dll
    C:\windows\system32\khfgfda.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfgfef.dll
    C:\windows\system32\khfgfef.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfgffc.dll
    C:\windows\system32\khfgffc.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfggde.dll
    C:\windows\system32\khfggde.dll Has been deleted!

    Attempting to delete C:\windows\system32\khfghif.dll
    C:\windows\system32\khfghif.dll Has been deleted!

    Attempting to delete C:\windows\system32\ljjgdee.dll
    C:\windows\system32\ljjgdee.dll Has been deleted!

    Attempting to delete C:\windows\system32\ljjhfec.dll
    C:\windows\system32\ljjhfec.dll Has been deleted!

    Attempting to delete C:\windows\system32\ljjhghf.dll
    C:\windows\system32\ljjhghf.dll Has been deleted!

    Attempting to delete C:\windows\system32\ljjhghi.dll
    C:\windows\system32\ljjhghi.dll Has been deleted!

    Attempting to delete C:\windows\system32\ljjkigf.dll
    C:\windows\system32\ljjkigf.dll Has been deleted!

    Attempting to delete C:\windows\system32\ljjkkjg.dll
    C:\windows\system32\ljjkkjg.dll Has been deleted!

    Attempting to delete C:\windows\system32\mljghhe.dll
    C:\windows\system32\mljghhe.dll Has been deleted!

    Attempting to delete C:\windows\system32\mljhijj.dll
    C:\windows\system32\mljhijj.dll Has been deleted!

    Attempting to delete C:\windows\system32\mljjiig.dll
    C:\windows\system32\mljjiig.dll Has been deleted!

    Attempting to delete C:\windows\system32\mljjjki.dll
    C:\windows\system32\mljjjki.dll Has been deleted!

    Attempting to delete C:\windows\system32\mljjkjj.dll
    C:\windows\system32\mljjkjj.dll Has been deleted!

    Attempting to delete C:\windows\system32\nnnmmnn.dll
    C:\windows\system32\nnnmmnn.dll Has been deleted!

    Attempting to delete C:\windows\system32\nnnnkjj.dll
    C:\windows\system32\nnnnkjj.dll Has been deleted!

    Attempting to delete C:\windows\system32\nnnopnk.dll
    C:\windows\system32\nnnopnk.dll Has been deleted!

    Attempting to delete C:\windows\system32\opnlihh.dll
    C:\windows\system32\opnlihh.dll Has been deleted!

    Attempting to delete C:\windows\system32\opnliji.dll
    C:\windows\system32\opnliji.dll Has been deleted!

    Attempting to delete C:\windows\system32\opnmjif.dll
    C:\windows\system32\opnmjif.dll Has been deleted!

    Attempting to delete C:\windows\system32\opnmkki.dll
    C:\windows\system32\opnmkki.dll Has been deleted!

    Attempting to delete C:\windows\system32\opnnoll.dll
    C:\windows\system32\opnnoll.dll Has been deleted!

    Attempting to delete C:\windows\system32\opnolmk.dll
    C:\windows\system32\opnolmk.dll Has been deleted!

    Attempting to delete C:\windows\system32\pmnlkkk.dll
    C:\windows\system32\pmnlkkk.dll Has been deleted!

    Attempting to delete C:\windows\system32\pmnomjh.dll
    C:\windows\system32\pmnomjh.dll Has been deleted!

    Attempting to delete C:\windows\system32\pmnomnl.dll
    C:\windows\system32\pmnomnl.dll Has been deleted!

    Attempting to delete C:\windows\system32\qomjjgf.dll
    C:\windows\system32\qomjjgf.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\qomjjji.dll
    C:\WINDOWS\system32\qomjjji.dll Could not be deleted.

    Attempting to delete C:\windows\system32\qommlml.dll
    C:\windows\system32\qommlml.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\qttss.bak1
    C:\WINDOWS\system32\qttss.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\qttss.bak2
    C:\WINDOWS\system32\qttss.bak2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\qttss.ini
    C:\WINDOWS\system32\qttss.ini Has been deleted!

    Attempting to delete C:\windows\system32\rqromjg.dll
    C:\windows\system32\rqromjg.dll Has been deleted!

    Attempting to delete C:\windows\system32\rqrqqnk.dll
    C:\windows\system32\rqrqqnk.dll Has been deleted!

    Attempting to delete C:\windows\system32\rqrrpmk.dll
    C:\windows\system32\rqrrpmk.dll Has been deleted!

    Attempting to delete C:\windows\system32\rqrrsss.dll
    C:\windows\system32\rqrrsss.dll Has been deleted!

    Attempting to delete C:\windows\system32\rqrsppq.dll
    C:\windows\system32\rqrsppq.dll Has been deleted!

    Attempting to delete C:\windows\system32\rqrsqnk.dll
    C:\windows\system32\rqrsqnk.dll Has been deleted!

    Attempting to delete C:\windows\system32\ssqpmki.dll
    C:\windows\system32\ssqpmki.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ssttq.dll
    C:\WINDOWS\system32\ssttq.dll Could not be deleted.

    Attempting to delete C:\windows\system32\tfdwimvh.dll
    C:\windows\system32\tfdwimvh.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\tmpD9.tmp.dll
    C:\WINDOWS\system32\tmpD9.tmp.dll Has been deleted!

    Attempting to delete C:\windows\system32\tqilhdsf.dll
    C:\windows\system32\tqilhdsf.dll Has been deleted!

    Attempting to delete C:\windows\system32\tuvtutr.dll
    C:\windows\system32\tuvtutr.dll Has been deleted!

    Attempting to delete C:\windows\system32\tuvurpn.dll
    C:\windows\system32\tuvurpn.dll Has been deleted!

    Attempting to delete C:\windows\system32\tuvvwxv.dll
    C:\windows\system32\tuvvwxv.dll Has been deleted!

    Attempting to delete C:\windows\system32\tuvwxut.dll
    C:\windows\system32\tuvwxut.dll Has been deleted!

    Attempting to delete C:\windows\system32\tuvwxyy.dll
    C:\windows\system32\tuvwxyy.dll Has been deleted!

    Attempting to delete C:\windows\system32\uoldxwps.dll
    C:\windows\system32\uoldxwps.dll Has been deleted!

    Attempting to delete C:\windows\system32\urqpnlj.dll
    C:\windows\system32\urqpnlj.dll Has been deleted!

    Attempting to delete C:\windows\system32\urqppno.dll
    C:\windows\system32\urqppno.dll Has been deleted!

    Attempting to delete C:\windows\system32\urqqnlm.dll
    C:\windows\system32\urqqnlm.dll Has been deleted!

    Attempting to delete C:\windows\system32\urqqpqn.dll
    C:\windows\system32\urqqpqn.dll Has been deleted!

    Attempting to delete C:\windows\system32\vbudyouk.dll
    C:\windows\system32\vbudyouk.dll Has been deleted!

    Attempting to delete C:\windows\system32\vturopn.dll
    C:\windows\system32\vturopn.dll Has been deleted!

    Attempting to delete C:\windows\system32\vtuspqo.dll
    C:\windows\system32\vtuspqo.dll Has been deleted!

    Attempting to delete C:\windows\system32\vtusstt.dll
    C:\windows\system32\vtusstt.dll Has been deleted!

    Attempting to delete C:\windows\system32\vtutqpq.dll
    C:\windows\system32\vtutqpq.dll Has been deleted!

    Attempting to delete C:\windows\system32\vtutrsp.dll
    C:\windows\system32\vtutrsp.dll Has been deleted!

    Attempting to delete C:\windows\system32\vtuustt.dll
    C:\windows\system32\vtuustt.dll Has been deleted!

    Attempting to delete C:\windows\system32\wvurqom.dll
    C:\windows\system32\wvurqom.dll Has been deleted!

    Attempting to delete C:\windows\system32\wvutstt.dll
    C:\windows\system32\wvutstt.dll Has been deleted!

    Attempting to delete C:\windows\system32\wvuvsrr.dll
    C:\windows\system32\wvuvsrr.dll Has been deleted!

    Attempting to delete C:\windows\system32\xmcsaqms.dll
    C:\windows\system32\xmcsaqms.dll Has been deleted!

    Attempting to delete C:\windows\system32\xxyvsst.dll
    C:\windows\system32\xxyvsst.dll Has been deleted!

    Attempting to delete C:\windows\system32\xxyyaab.dll
    C:\windows\system32\xxyyaab.dll Has been deleted!

    Attempting to delete C:\windows\system32\yayaawt.dll
    C:\windows\system32\yayaawt.dll Has been deleted!

    Attempting to delete C:\windows\system32\yayaxvu.dll
    C:\windows\system32\yayaxvu.dll Has been deleted!

    Attempting to delete C:\windows\system32\yaywuur.dll
    C:\windows\system32\yaywuur.dll Has been deleted!

    Attempting to delete C:\windows\system32\yayywtu.dll
    C:\windows\system32\yayywtu.dll Has been deleted!

    Attempting to delete C:\WINDOWS\ttutss.ini
    C:\WINDOWS\ttutss.ini Has been deleted!

    Performing Repairs to the registry.
    Done!

    VundoFix V6.5.8

    Checking Java version...

    Java version is 1.5.0.3
    Old versions of java are exploitable and should be removed.

    Scan started at 11:47:19 2007-09-09

    Listing files found while scanning....

    C:\windows\system32\qomjjji.dll
    C:\windows\system32\ssttq.dll

    Beginning removal...

    Attempting to delete C:\windows\system32\qomjjji.dll
    C:\windows\system32\qomjjji.dll Has been deleted!

    Attempting to delete C:\windows\system32\ssttq.dll
    C:\windows\system32\ssttq.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    VundoFix V6.5.8

    Checking Java version...

    Java version is 1.5.0.3
    Old versions of java are exploitable and should be removed.

    Scan started at 11:51:55 2007-09-09

    Listing files found while scanning....

    C:\windows\system32\opnnllj.dll

    Beginning removal...

    Attempting to delete C:\windows\system32\opnnllj.dll
    C:\windows\system32\opnnllj.dll Could not be deleted.

    Performing Repairs to the registry.
    Done!

    Beginning removal...

    Attempting to delete C:\windows\system32\opnnllj.dll
    C:\windows\system32\opnnllj.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    Rapport De Hijackthis

    Logfile of HijackThis v1.99.1
    Scan saved at 11:58:17, on 2007-09-09
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\ATKKBService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/granby
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {768FEE08-9B75-4653-A2CD-8822C83A5453} - C:\WINDOWS\system32\ssttq.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\vhmjydfi.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    jai comme une impression que sa a pas changé grand chose pcq jai encore les alerte de virus c vrm chiant :S
    0
  9. Rudy2k5
     
    je tenvois le rapport de bit defender il sest produit qqch dassé important je crois lors du scan de bit defender jai recu PLUSIEURS

    alertes de Avast je ten donne la liste si sa peut taider Win32:Vundo-gen48[Adw] Win32:Vundo-gen46[Adw]

    Win32:Vundo-gen47[Adw] Win32:Vundo-gen49[Adw] Win32: Agent-HOP[Wrm] (celui dont il est question depuis le debut :s)

    Win32:Tiny-IF [Trj] Ils sont tous apparu a plusieurs reprise dont le derniere qui est apparu 5x de suite des que je fesait mettre en

    quarantaine, il réapparaissait :s ....... et la plupart etais detecté ds system Volume Information/ restore et dans le dossier vundofix Backup et a une autre place que je nai pas prit en note :s

    donc voici le rapport:

    <HTML>
    <HEAD>
    <TITLE>BitDefender Online Scanner - Rapport d'analyse</TITLE>
    <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
    </HEAD>
    <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >

    <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
    <tr>
    <td width="458">
    <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender Online Scanner</b></span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>
    <tr>
    <td colspan="3" width="912">
    <p><font face="Arial"><span style="font-size:11pt;"><B>Rapport d'analyse généré à: Sun, Sep 09, 2007 - 13:22:57</b></span></font></p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <p><font face="Arial"><span style="font-size:11pt;"><B>Voie d'analyse: </b></span><span style="font-size:10pt;">A:\;C:\;D:\;</span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="451" colspan="2" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Statistiques</b></font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Temps</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">01:04:26</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Fichiers</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">261302</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Directoires</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">7750</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Secteurs de boot</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">2</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Archives</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">1608</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Paquets programmes</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">9964</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="451" colspan="2" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Résultats</b></font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Virus identifiés</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">9</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Fichiers infectés</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">282</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Fichiers suspects</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">0</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Avertissements</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">0</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Désinfectés</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">0</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Fichiers effacés</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">282</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="451" colspan="2" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Info sur les moteurs</b></font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Définition virus</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">800243</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Version des moteurs</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Analyse des plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">14</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Archive des plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">38</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Unpack des plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">7</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">E-mail plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">6</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Système plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">1</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="451" colspan="2" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Paramètres d'analyse</b></font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Première action</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Désinfecté</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Seconde Action</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Heuristique</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Oui</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Acceptez les avertissements</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Oui</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Extensions analysées</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">*;</font></p>
    </td>
    </tr>

    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Excludez les extensions</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2"> </font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Analyse d'emails</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Oui</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Analyse des Archives</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Oui</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Analyser paquets programmes</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Oui</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Analyse des fichiers</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Oui</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Analyse de boot</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Oui</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td colspan=2>
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="252" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Fichier analysé</b></font></p>
    </td>
    <td width="195" bgcolor="#CCCCCC" align="right">
    <p align="left"><b><font size="2" face="Arial"> Statut</font></b></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp2.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Dropper.Agent.BON</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp2.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp2.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp3.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Juan.V</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp3.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp3.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp31.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Dropper.Agent.BON</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp31.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp31.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp32.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Juan.V</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp32.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp32.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmpD9.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Juan.V</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmpD9.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmpD9.tmp.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\theq3[1].exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Win32.Worm.Garm.C</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\theq3[1].exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\theq3[1].exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\poep[1].exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\poep[1].exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005635.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMP</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005635.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005635.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005637.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMP</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005637.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005637.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005638.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMX</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005638.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005638.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013565.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Win32.Worm.Garm.C</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013565.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013565.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013677.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013677.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013679.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013679.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013679.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013680.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013680.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013680.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013681.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013681.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013681.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013682.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013682.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013682.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013683.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013683.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013683.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013684.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Fotomoto.E</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013684.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013684.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013696.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Win32.Worm.Garm.C</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013696.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Echec de la désinfection</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013696.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013700.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013700.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013701.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013701.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013702.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013702.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013703.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013703.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013704.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013704.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013705.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013705.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013706.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013706.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013707.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013707.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013708.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013708.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013709.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013709.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013710.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013710.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013711.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013711.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013712.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013712.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013713.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013713.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013714.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013714.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013715.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013715.dll</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Supprimé</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013716.dll
    0
  10. Rudy2k5 Messages postés 6 Statut Membre
     
    au juste pourquoi as tu reposté mon rapport ??
    0
  11. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    J'ai reposté ton rapport car il n'avait pas été mis au bon endroit, c plus facile pour moi surtout quand je reprends ce que l'on a déjà fait, les avoir dans l'ordre me parait plus simple :)

    bon le scan a bien travaillé visiblement

    reposte un nouveau rapport hijackthis
    0
  12. Rudy2k5
     
    Voici le dernier log de Hijackthis

    Logfile of HijackThis v1.99.1
    Scan saved at 21:57:14, on 2007-09-09
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\ATKKBService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\msgs.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Steam\Steam.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/granby
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {768FEE08-9B75-4653-A2CD-8822C83A5453} - C:\WINDOWS\system32\ssttq.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\vhmjydfi.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    0
  13. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    bonjour,

    * Relance Vundofix
    * Ne clique pas sur "Scan for a vundo"
    * Clique droit au milieu de la fenêtre
    * Clique sur Add more files ?
    * Copie/colle les fichiers ci-dessous ( un par case) :

    C:\WINDOWS\SYSTEM32\ieakdlv.dll

    * Clique sur Add files
    * Ensuite clique sur Close Windows
    * Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaitre dans la fenêtre principale)
    * Si l'outils demande un redémarrage, accepte
    * Poste le rapport Vundofix

    puis

    * lance hijackthis puis coche ces lignes :

    O2 - BHO: (no name) - {768FEE08-9B75-4653-A2CD-8822C83A5453} - C:\WINDOWS\system32\ssttq.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\vhmjydfi.exe (file missing)

    * ferme toutes les applications ouvertes y compris internet explorer et clique sur "fixer objet"

    puis

    * Assure toi d'avoir accès à tous les fichiers

    -démarrer

    -poste de travail ou autre dossier

    -menu outils

    -options de dossier

    -onglet affichage

    puis

    - activer la case : Afficher les fichiers et dossiers cachés

    - désactiver la case : Masquer les extensions des fichiers dont le type est connu

    - désactiver la case : Masquer les fichier protégés du système d'exploitation

    Puis - Appliquer

    * et Supprime le(s) fichier(s) ci dessous si il(s) est (sont) présent(s) :

    C:\WINDOWS\system32\vhmjydfi.exe

    * Dans l'Explorateur Windows recache les fichiers système afin de ne pas faire d'erreur à l'avenir. Retourne à la fenêtre Paramètres de dossiers et sélectionne Ne pas afficher les fichiers cachés ou les fichiers système

    puis

    reposte un nouveau rapport hijackthis
    0