Win 32:Agent-HOP Wrm

Rudy2k5 Messages postés 6 Statut Membre -  
philae83 Messages postés 12854 Statut Contributeur sécurité -
Bonjour je me demandais si quelqu'un pourrait maider a trouver une solution a ce probleme de plus en plus nuisible sa fait deja un moment que je lai je croyais men etre debarassé et il est réapparu (Win 32:Agent-HOP Wrm) il occasionne un paquet de probleme sur mon ordinateur alors si vous pourriez maider le plus vite possible se serait plus qu'apprécié

Rudy

p.s. en ce moment jai avast mais je conte changer pour McAfee est ce que vous croyez que je devrais (il m'est offert gratuitement par le Cégep)
A voir également:

12 réponses

philae83 Messages postés 12854 Statut Contributeur sécurité 206
 
bonsoir,

commence par :

* Télécharge HijackThis et poste le rapport stp

http://pchelpbordeaux.free.fr/logiciels.html
Tutorial
http://pchelpbordeaux.free.fr/tuto.html
Démo en image (merci balltrap)
demo hijackenregistrement http://perso.orange.fr/rginformatique/section%20virus/Hijenr.gif
http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

et

* Télécharge CCleaner.

https://www.pcastuces.com/logitheque/ccleaner.htm

Installe le dans un répertoire dédié.

Décoche pendant l'installation

--- les deux cases "Ajouter l'option ... "

--- Contrôler les mises à jour

--- Ajouter la Barre d'Outils Yahoo! CCleaner

* Lance Ccleaner pour un nettoyage complet.

------

* télécharge AVG Anti-Spyware (ewido)

https://www.avg.com/en-ww/free-antivirus-download

* tu l'installes

* lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente

puis

Lance AVG Anti-Spyware

Clique sur le bouton Analyse (de la barre d'outils)

puis fait dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions.

Puis sur l'onglet Paramètres,
sous : "Comment réagir "clique sur Actions recommandées. Sélectionne Quarantaine.

Reviens à l'onglet Analyse. Clique sur Analyse complète du système.

A la fin du scan, choisis l'option 3

"Appliquer toutes les actions " en bas.

Clique sur "Enregistrer le rapport".

Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

Poste le.
0
Rudy2k5 Messages postés 6 Statut Membre
 
Salut désolé pour le delai mais jai été pas mal occupé ces temps-ci mais javais une petite question a te poser

tu ecris ici: "puis fait dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions." est ce que cest apres le scan que je fait sa ?? (surement) mais se qui me melange cest que tu as ecrit ça avant laction danalyse complete

si je le fait avant veux tu mexpliquer comment je dois le faire svp

sur ce je dois y allé jai des trucs importants a faire
merci davance
Rudy
0
Rudy2k5
 
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 09:56:00 2007-09-09

+ Résultat de l'analyse:



C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\95MZ412N\lkjh[1] -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005634.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005636.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005639.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005641.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005642.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\jjejcbwn.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\kgxqkqoo.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\nwcpgxwu.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\owsxfhcy.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\saoqencf.exe -> Downloader.Tiny.id : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\SG-C\Cookies\sg-c@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@casalemedia[1].txt -> TrackingCookie.Casalemedia : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.7:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@ehg-ctv.hitbox[2].txt -> TrackingCookie.Hitbox : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@ehg-u3.hitbox[1].txt -> TrackingCookie.Hitbox : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@hitbox[2].txt -> TrackingCookie.Hitbox : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.42:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.43:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.44:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.45:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.46:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.47:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.48:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.49:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.33:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
:mozilla.34:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
:mozilla.35:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
:mozilla.36:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
:mozilla.37:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
:mozilla.38:C:\Documents and Settings\SG-C\Application Data\Mozilla\Firefox\Profiles\4f1krdyb.default\cookies.txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@statcounter[1].txt -> TrackingCookie.Statcounter : Nettoyé.
C:\Documents and Settings\SG-C\Cookies\sg-c@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Nettoyé.
[400] C:\WINDOWS\system32\vhmjydfi.exe -> Trojan.Agent.aoy : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\95MZ412N\theq3[1].exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005632.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP16\A0012642.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP18\A0012945.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP19\A0013041.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP21\A0013091.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP22\A0013320.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013597.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013600.exe -> Worm.Garm.c : Nettoyé et sauvegardé (mise en quarantaine).


Fin du rapport



voici le resultat du scan cependant jai pas trouvé loption 3 dont tu parle
0
Rudy2k5 Messages postés 6 Statut Membre
 
Logfile of HijackThis v1.99.1
Scan saved at 21:05:15, on 2007-09-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\vhmjydfi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msgs.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/granby
O2 - BHO: (no name) - {44218730-94E0-4b24-BBF0-C3D8B2BCE2C3} - C:\WINDOWS\system32\tmp32.tmp.dll
O2 - BHO: (no name) - {5D8FA654-B27C-4E7F-B2F3-B913DAA78E0F} - C:\WINDOWS\system32\ssttq.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {CC358019-D328-40B4-8E2D-818CE142616C} - C:\WINDOWS\system32\awtsqpo.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awtsqpo - C:\WINDOWS\SYSTEM32\awtsqpo.dll
O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
O20 - Winlogon Notify: ssttq - C:\WINDOWS\system32\ssttq.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: DomainService - - C:\WINDOWS\system32\vhmjydfi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

voici le rapport d'Hijackthis
0
Rudy2k5 Messages postés 6 Statut Membre
 
il est inscrit un petit qqch a propos de Ccleaner et jme pose des question

"A signaler enfin que CCleaner permet également de supprimer les documents récents et les fichiers temporaires de nombreuses applications : Opera, Lecteur Windows Media, eMule, Kazaa, Google Toolbar, Netscape, Microsoft Office, Nero, Adobe Acrobat, WinRAR, WinAce, WinZip, etc."

sa veut tu dire que je pourrais perdre des fichier que jaurais intentionellement downloader comme par exemple musique ou film ??

p.s. saurais tu si je devrais mettre Mc afee a place de Avast ???
0
philae83 Messages postés 12854 Statut Contributeur sécurité 206
 
Bonsoir, et désolée pour le retard

"A signaler enfin que CCleaner permet également de supprimer les documents récents et les fichiers temporaires de nombreuses applications : Opera, Lecteur Windows Media, eMule, Kazaa, Google Toolbar, Netscape, Microsoft Office, Nero, Adobe Acrobat, WinRAR, WinAce, WinZip, etc."

sa veut tu dire que je pourrais perdre des fichier que jaurais intentionellement downloader comme par exemple musique ou film ?? 


uniquement si tu les as mis dans les fichiers temporaires
p.s. saurais tu si je devrais mettre Mc afee a place de Avast ???



oui bien sûr que tu peux, McAfee est un bon antivirus et payant, si on te l'offre pourquoi pas.

pour ton infection, on continue

* Télécharge VundoFix.exe (par Atribune) sur ton Bureau

http://www.atribune.org/ccount/click.php?id=4

* Double-clique VundoFix.exe afin de le lancer

* Clique sur le bouton Scan for Vundo

* Lorsque le scan est complété, clique sur le bouton Remove Vundo

* Une invite te demandera si tu veux supprimer les fichiers, clique YES

* Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers

* Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK

* Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse

Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".

0
Rudy
 
ok mais dit moi si je dois commencer par les etape de ton premier message avant dembarquer sur Vundofix ou je dois commencer par Vundofix ???

et pour se qui est c CCleaner est ce que je dois coché TOUTES les case dans (Windows) et dans (application)

Merci de prendre le temps de me repondre japprécie beaucoup et ya pas de probleme prend le temps quil faut tu fais deja plus que dautre personne que je connais héhé ;P

p.s. historique des saisie automatique nest surement pas obligatoire !?!?!?!?!?

Rudy
0
Rudy2k5 Messages postés 6 Statut Membre
 
Rapport VundoFix


VundoFix V6.5.8

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 10:46:54 2007-09-09

Listing files found while scanning....

C:\WINDOWS\sstutt.dll
C:\windows\system32\awtqrqn.dll
C:\windows\system32\awtrpmk.dll
C:\WINDOWS\system32\awtsqpo.dll
C:\windows\system32\awtsrpq.dll
C:\windows\system32\awttusr.dll
C:\windows\system32\awvspmk.dll
C:\windows\system32\byxurrq.dll
C:\windows\system32\byxwxuv.dll
C:\windows\system32\byxxusp.dll
C:\windows\system32\cbxuutq.dll
C:\windows\system32\cbxvtut.dll
C:\windows\system32\cbxwvvt.dll
C:\windows\system32\cbxwwxv.dll
C:\windows\system32\cbxxyvu.dll
C:\windows\system32\cbxywtu.dll
C:\windows\system32\ddawvwu.dll
C:\windows\system32\ddcaayv.dll
C:\windows\system32\ddcaxwx.dll
C:\windows\system32\ddcyxyv.dll
C:\windows\system32\efcaayy.dll
C:\windows\system32\efcbxxw.dll
C:\windows\system32\efcyaba.dll
C:\windows\system32\efcyyxv.dll
C:\windows\system32\fccawus.dll
C:\windows\system32\fccbxvs.dll
C:\windows\system32\fccccby.dll
C:\windows\system32\fccyaby.dll
C:\windows\system32\fccyyaa.dll
C:\windows\system32\fjlluena.dll
C:\windows\system32\gebaaya.dll
C:\windows\system32\gebabyy.dll
C:\windows\system32\gebaywv.dll
C:\windows\system32\gebxusr.dll
C:\windows\system32\gebxwvs.dll
C:\windows\system32\gebyaxx.dll
C:\windows\system32\hggdebc.dll
C:\windows\system32\hggfdba.dll
C:\windows\system32\hgghebb.dll
C:\windows\system32\hgghedc.dll
C:\windows\system32\hgghgff.dll
C:\windows\system32\hgghhif.dll
C:\windows\system32\hsacgmrj.dll
C:\windows\system32\iifefff.dll
C:\windows\system32\jjssqfte.dll
C:\windows\system32\jkkhfdc.dll
C:\windows\system32\jkkjgfg.dll
C:\windows\system32\jkkkjgg.dll
C:\windows\system32\khfcbay.dll
C:\windows\system32\khfcdee.dll
C:\windows\system32\khfdccc.dll
C:\windows\system32\khfeccb.dll
C:\windows\system32\khfecdd.dll
C:\windows\system32\khffeca.dll
C:\windows\system32\khfgfda.dll
C:\windows\system32\khfgfef.dll
C:\windows\system32\khfgffc.dll
C:\windows\system32\khfggde.dll
C:\windows\system32\khfghif.dll
C:\windows\system32\ljjgdee.dll
C:\windows\system32\ljjhfec.dll
C:\windows\system32\ljjhghf.dll
C:\windows\system32\ljjhghi.dll
C:\windows\system32\ljjkigf.dll
C:\windows\system32\ljjkkjg.dll
C:\windows\system32\mljghhe.dll
C:\windows\system32\mljhijj.dll
C:\windows\system32\mljjiig.dll
C:\windows\system32\mljjjki.dll
C:\windows\system32\mljjkjj.dll
C:\windows\system32\nnnmmnn.dll
C:\windows\system32\nnnnkjj.dll
C:\windows\system32\nnnopnk.dll
C:\windows\system32\opnlihh.dll
C:\windows\system32\opnliji.dll
C:\windows\system32\opnmjif.dll
C:\windows\system32\opnmkki.dll
C:\windows\system32\opnnoll.dll
C:\windows\system32\opnolmk.dll
C:\windows\system32\pmnlkkk.dll
C:\windows\system32\pmnomjh.dll
C:\windows\system32\pmnomnl.dll
C:\windows\system32\qomjjgf.dll
C:\windows\system32\qommlml.dll
C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\qttss.ini
C:\windows\system32\rqromjg.dll
C:\windows\system32\rqrqqnk.dll
C:\windows\system32\rqrrpmk.dll
C:\windows\system32\rqrrsss.dll
C:\windows\system32\rqrsppq.dll
C:\windows\system32\rqrsqnk.dll
C:\windows\system32\ssqpmki.dll
C:\WINDOWS\system32\ssttq.dll
C:\windows\system32\tfdwimvh.dll
C:\WINDOWS\system32\tmpD9.tmp.dll
C:\windows\system32\tqilhdsf.dll
C:\windows\system32\tuvtutr.dll
C:\windows\system32\tuvurpn.dll
C:\windows\system32\tuvvwxv.dll
C:\windows\system32\tuvwxut.dll
C:\windows\system32\tuvwxyy.dll
C:\windows\system32\uoldxwps.dll
C:\windows\system32\urqpnlj.dll
C:\windows\system32\urqppno.dll
C:\windows\system32\urqqnlm.dll
C:\windows\system32\urqqpqn.dll
C:\windows\system32\vbudyouk.dll
C:\windows\system32\vturopn.dll
C:\windows\system32\vtuspqo.dll
C:\windows\system32\vtusstt.dll
C:\windows\system32\vtutqpq.dll
C:\windows\system32\vtutrsp.dll
C:\windows\system32\vtuustt.dll
C:\windows\system32\wvurqom.dll
C:\windows\system32\wvutstt.dll
C:\windows\system32\wvuvsrr.dll
C:\windows\system32\xmcsaqms.dll
C:\windows\system32\xxyvsst.dll
C:\windows\system32\xxyyaab.dll
C:\windows\system32\yayaawt.dll
C:\windows\system32\yayaxvu.dll
C:\windows\system32\yaywuur.dll
C:\windows\system32\yayywtu.dll
C:\WINDOWS\ttutss.ini

Beginning removal...

Attempting to delete C:\WINDOWS\sstutt.dll
C:\WINDOWS\sstutt.dll Has been deleted!

Attempting to delete C:\windows\system32\awtqrqn.dll
C:\windows\system32\awtqrqn.dll Has been deleted!

Attempting to delete C:\windows\system32\awtrpmk.dll
C:\windows\system32\awtrpmk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\awtsqpo.dll
C:\WINDOWS\system32\awtsqpo.dll Could not be deleted.

Attempting to delete C:\windows\system32\awtsrpq.dll
C:\windows\system32\awtsrpq.dll Has been deleted!

Attempting to delete C:\windows\system32\awttusr.dll
C:\windows\system32\awttusr.dll Has been deleted!

Attempting to delete C:\windows\system32\awvspmk.dll
C:\windows\system32\awvspmk.dll Has been deleted!

Attempting to delete C:\windows\system32\byxurrq.dll
C:\windows\system32\byxurrq.dll Has been deleted!

Attempting to delete C:\windows\system32\byxwxuv.dll
C:\windows\system32\byxwxuv.dll Has been deleted!

Attempting to delete C:\windows\system32\byxxusp.dll
C:\windows\system32\byxxusp.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxuutq.dll
C:\windows\system32\cbxuutq.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxvtut.dll
C:\windows\system32\cbxvtut.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxwvvt.dll
C:\windows\system32\cbxwvvt.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxwwxv.dll
C:\windows\system32\cbxwwxv.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxxyvu.dll
C:\windows\system32\cbxxyvu.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxywtu.dll
C:\windows\system32\cbxywtu.dll Has been deleted!

Attempting to delete C:\windows\system32\ddawvwu.dll
C:\windows\system32\ddawvwu.dll Has been deleted!

Attempting to delete C:\windows\system32\ddcaayv.dll
C:\windows\system32\ddcaayv.dll Has been deleted!

Attempting to delete C:\windows\system32\ddcaxwx.dll
C:\windows\system32\ddcaxwx.dll Has been deleted!

Attempting to delete C:\windows\system32\ddcyxyv.dll
C:\windows\system32\ddcyxyv.dll Has been deleted!

Attempting to delete C:\windows\system32\efcaayy.dll
C:\windows\system32\efcaayy.dll Has been deleted!

Attempting to delete C:\windows\system32\efcbxxw.dll
C:\windows\system32\efcbxxw.dll Has been deleted!

Attempting to delete C:\windows\system32\efcyaba.dll
C:\windows\system32\efcyaba.dll Has been deleted!

Attempting to delete C:\windows\system32\efcyyxv.dll
C:\windows\system32\efcyyxv.dll Has been deleted!

Attempting to delete C:\windows\system32\fccawus.dll
C:\windows\system32\fccawus.dll Has been deleted!

Attempting to delete C:\windows\system32\fccbxvs.dll
C:\windows\system32\fccbxvs.dll Has been deleted!

Attempting to delete C:\windows\system32\fccccby.dll
C:\windows\system32\fccccby.dll Has been deleted!

Attempting to delete C:\windows\system32\fccyaby.dll
C:\windows\system32\fccyaby.dll Has been deleted!

Attempting to delete C:\windows\system32\fccyyaa.dll
C:\wind
VundoFix V6.5.8

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:35:58 2007-09-09

Listing files found while scanning....

C:\WINDOWS\sstutt.dll
C:\windows\system32\awtsqpo.dll
C:\windows\system32\fjlluena.dll
C:\windows\system32\gebaaya.dll
C:\windows\system32\gebabyy.dll
C:\windows\system32\gebaywv.dll
C:\windows\system32\gebxusr.dll
C:\windows\system32\gebxwvs.dll
C:\windows\system32\gebyaxx.dll
C:\windows\system32\hggdebc.dll
C:\windows\system32\hggfdba.dll
C:\windows\system32\hgghebb.dll
C:\windows\system32\hgghedc.dll
C:\windows\system32\hgghgff.dll
C:\windows\system32\hgghhif.dll
C:\windows\system32\hsacgmrj.dll
C:\windows\system32\iifefff.dll
C:\windows\system32\jjssqfte.dll
C:\windows\system32\jkkhfdc.dll
C:\windows\system32\jkkjgfg.dll
C:\windows\system32\jkkkjgg.dll
C:\windows\system32\khfcbay.dll
C:\windows\system32\khfcdee.dll
C:\windows\system32\khfdccc.dll
C:\windows\system32\khfeccb.dll
C:\windows\system32\khfecdd.dll
C:\windows\system32\khffeca.dll
C:\windows\system32\khfgfda.dll
C:\windows\system32\khfgfef.dll
C:\windows\system32\khfgffc.dll
C:\windows\system32\khfggde.dll
C:\windows\system32\khfghif.dll
C:\windows\system32\ljjgdee.dll
C:\windows\system32\ljjhfec.dll
C:\windows\system32\ljjhghf.dll
C:\windows\system32\ljjhghi.dll
C:\windows\system32\ljjkigf.dll
C:\windows\system32\ljjkkjg.dll
C:\windows\system32\mljghhe.dll
C:\windows\system32\mljhijj.dll
C:\windows\system32\mljjiig.dll
C:\windows\system32\mljjjki.dll
C:\windows\system32\mljjkjj.dll
C:\windows\system32\nnnmmnn.dll
C:\windows\system32\nnnnkjj.dll
C:\windows\system32\nnnopnk.dll
C:\windows\system32\opnlihh.dll
C:\windows\system32\opnliji.dll
C:\windows\system32\opnmjif.dll
C:\windows\system32\opnmkki.dll
C:\windows\system32\opnnoll.dll
C:\windows\system32\opnolmk.dll
C:\windows\system32\pmnlkkk.dll
C:\windows\system32\pmnomjh.dll
C:\windows\system32\pmnomnl.dll
C:\windows\system32\qomjjgf.dll
C:\WINDOWS\system32\qomjjji.dll
C:\windows\system32\qommlml.dll
C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\qttss.ini
C:\windows\system32\rqromjg.dll
C:\windows\system32\rqrqqnk.dll
C:\windows\system32\rqrrpmk.dll
C:\windows\system32\rqrrsss.dll
C:\windows\system32\rqrsppq.dll
C:\windows\system32\rqrsqnk.dll
C:\windows\system32\ssqpmki.dll
C:\WINDOWS\system32\ssttq.dll
C:\windows\system32\tfdwimvh.dll
C:\WINDOWS\system32\tmpD9.tmp.dll
C:\windows\system32\tqilhdsf.dll
C:\windows\system32\tuvtutr.dll
C:\windows\system32\tuvurpn.dll
C:\windows\system32\tuvvwxv.dll
C:\windows\system32\tuvwxut.dll
C:\windows\system32\tuvwxyy.dll
C:\windows\system32\uoldxwps.dll
C:\windows\system32\urqpnlj.dll
C:\windows\system32\urqppno.dll
C:\windows\system32\urqqnlm.dll
C:\windows\system32\urqqpqn.dll
C:\windows\system32\vbudyouk.dll
C:\windows\system32\vturopn.dll
C:\windows\system32\vtuspqo.dll
C:\windows\system32\vtusstt.dll
C:\windows\system32\vtutqpq.dll
C:\windows\system32\vtutrsp.dll
C:\windows\system32\vtuustt.dll
C:\windows\system32\wvurqom.dll
C:\windows\system32\wvutstt.dll
C:\windows\system32\wvuvsrr.dll
C:\windows\system32\xmcsaqms.dll
C:\windows\system32\xxyvsst.dll
C:\windows\system32\xxyyaab.dll
C:\windows\system32\yayaawt.dll
C:\windows\system32\yayaxvu.dll
C:\windows\system32\yaywuur.dll
C:\windows\system32\yayywtu.dll
C:\WINDOWS\ttutss.ini

Beginning removal...

Attempting to delete C:\windows\system32\awtsqpo.dll
C:\windows\system32\awtsqpo.dll Has been deleted!

Attempting to delete C:\windows\system32\fjlluena.dll
C:\windows\system32\fjlluena.dll Has been deleted!

Attempting to delete C:\windows\system32\gebaaya.dll
C:\windows\system32\gebaaya.dll Has been deleted!

Attempting to delete C:\windows\system32\gebabyy.dll
C:\windows\system32\gebabyy.dll Has been deleted!

Attempting to delete C:\windows\system32\gebaywv.dll
C:\windows\system32\gebaywv.dll Has been deleted!

Attempting to delete C:\windows\system32\gebxusr.dll
C:\windows\system32\gebxusr.dll Has been deleted!

Attempting to delete C:\windows\system32\gebxwvs.dll
C:\windows\system32\gebxwvs.dll Has been deleted!

Attempting to delete C:\windows\system32\gebyaxx.dll
C:\windows\system32\gebyaxx.dll Has been deleted!

Attempting to delete C:\windows\system32\hggdebc.dll
C:\windows\system32\hggdebc.dll Has been deleted!

Attempting to delete C:\windows\system32\hggfdba.dll
C:\windows\system32\hggfdba.dll Has been deleted!

Attempting to delete C:\windows\system32\hgghebb.dll
C:\windows\system32\hgghebb.dll Has been deleted!

Attempting to delete C:\windows\system32\hgghedc.dll
C:\windows\system32\hgghedc.dll Has been deleted!

Attempting to delete C:\windows\system32\hgghgff.dll
C:\windows\system32\hgghgff.dll Has been deleted!

Attempting to delete C:\windows\system32\hgghhif.dll
C:\windows\system32\hgghhif.dll Has been deleted!

Attempting to delete C:\windows\system32\hsacgmrj.dll
C:\windows\system32\hsacgmrj.dll Has been deleted!

Attempting to delete C:\windows\system32\iifefff.dll
C:\windows\system32\iifefff.dll Has been deleted!

Attempting to delete C:\windows\system32\jjssqfte.dll
C:\windows\system32\jjssqfte.dll Has been deleted!

Attempting to delete C:\windows\system32\jkkhfdc.dll
C:\windows\system32\jkkhfdc.dll Has been deleted!

Attempting to delete C:\windows\system32\jkkjgfg.dll
C:\windows\system32\jkkjgfg.dll Has been deleted!

Attempting to delete C:\windows\system32\jkkkjgg.dll
C:\windows\system32\jkkkjgg.dll Has been deleted!

Attempting to delete C:\windows\system32\khfcbay.dll
C:\windows\system32\khfcbay.dll Has been deleted!

Attempting to delete C:\windows\system32\khfcdee.dll
C:\windows\system32\khfcdee.dll Has been deleted!

Attempting to delete C:\windows\system32\khfdccc.dll
C:\windows\system32\khfdccc.dll Has been deleted!

Attempting to delete C:\windows\system32\khfeccb.dll
C:\windows\system32\khfeccb.dll Has been deleted!

Attempting to delete C:\windows\system32\khfecdd.dll
C:\windows\system32\khfecdd.dll Has been deleted!

Attempting to delete C:\windows\system32\khffeca.dll
C:\windows\system32\khffeca.dll Has been deleted!

Attempting to delete C:\windows\system32\khfgfda.dll
C:\windows\system32\khfgfda.dll Has been deleted!

Attempting to delete C:\windows\system32\khfgfef.dll
C:\windows\system32\khfgfef.dll Has been deleted!

Attempting to delete C:\windows\system32\khfgffc.dll
C:\windows\system32\khfgffc.dll Has been deleted!

Attempting to delete C:\windows\system32\khfggde.dll
C:\windows\system32\khfggde.dll Has been deleted!

Attempting to delete C:\windows\system32\khfghif.dll
C:\windows\system32\khfghif.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjgdee.dll
C:\windows\system32\ljjgdee.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjhfec.dll
C:\windows\system32\ljjhfec.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjhghf.dll
C:\windows\system32\ljjhghf.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjhghi.dll
C:\windows\system32\ljjhghi.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjkigf.dll
C:\windows\system32\ljjkigf.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjkkjg.dll
C:\windows\system32\ljjkkjg.dll Has been deleted!

Attempting to delete C:\windows\system32\mljghhe.dll
C:\windows\system32\mljghhe.dll Has been deleted!

Attempting to delete C:\windows\system32\mljhijj.dll
C:\windows\system32\mljhijj.dll Has been deleted!

Attempting to delete C:\windows\system32\mljjiig.dll
C:\windows\system32\mljjiig.dll Has been deleted!

Attempting to delete C:\windows\system32\mljjjki.dll
C:\windows\system32\mljjjki.dll Has been deleted!

Attempting to delete C:\windows\system32\mljjkjj.dll
C:\windows\system32\mljjkjj.dll Has been deleted!

Attempting to delete C:\windows\system32\nnnmmnn.dll
C:\windows\system32\nnnmmnn.dll Has been deleted!

Attempting to delete C:\windows\system32\nnnnkjj.dll
C:\windows\system32\nnnnkjj.dll Has been deleted!

Attempting to delete C:\windows\system32\nnnopnk.dll
C:\windows\system32\nnnopnk.dll Has been deleted!

Attempting to delete C:\windows\system32\opnlihh.dll
C:\windows\system32\opnlihh.dll Has been deleted!

Attempting to delete C:\windows\system32\opnliji.dll
C:\windows\system32\opnliji.dll Has been deleted!

Attempting to delete C:\windows\system32\opnmjif.dll
C:\windows\system32\opnmjif.dll Has been deleted!

Attempting to delete C:\windows\system32\opnmkki.dll
C:\windows\system32\opnmkki.dll Has been deleted!

Attempting to delete C:\windows\system32\opnnoll.dll
C:\windows\system32\opnnoll.dll Has been deleted!

Attempting to delete C:\windows\system32\opnolmk.dll
C:\windows\system32\opnolmk.dll Has been deleted!

Attempting to delete C:\windows\system32\pmnlkkk.dll
C:\windows\system32\pmnlkkk.dll Has been deleted!

Attempting to delete C:\windows\system32\pmnomjh.dll
C:\windows\system32\pmnomjh.dll Has been deleted!

Attempting to delete C:\windows\system32\pmnomnl.dll
C:\windows\system32\pmnomnl.dll Has been deleted!

Attempting to delete C:\windows\system32\qomjjgf.dll
C:\windows\system32\qomjjgf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomjjji.dll
C:\WINDOWS\system32\qomjjji.dll Could not be deleted.

Attempting to delete C:\windows\system32\qommlml.dll
C:\windows\system32\qommlml.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\qttss.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\qttss.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\qttss.ini
C:\WINDOWS\system32\qttss.ini Has been deleted!

Attempting to delete C:\windows\system32\rqromjg.dll
C:\windows\system32\rqromjg.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrqqnk.dll
C:\windows\system32\rqrqqnk.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrrpmk.dll
C:\windows\system32\rqrrpmk.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrrsss.dll
C:\windows\system32\rqrrsss.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrsppq.dll
C:\windows\system32\rqrsppq.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrsqnk.dll
C:\windows\system32\rqrsqnk.dll Has been deleted!

Attempting to delete C:\windows\system32\ssqpmki.dll
C:\windows\system32\ssqpmki.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssttq.dll
C:\WINDOWS\system32\ssttq.dll Could not be deleted.

Attempting to delete C:\windows\system32\tfdwimvh.dll
C:\windows\system32\tfdwimvh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tmpD9.tmp.dll
C:\WINDOWS\system32\tmpD9.tmp.dll Has been deleted!

Attempting to delete C:\windows\system32\tqilhdsf.dll
C:\windows\system32\tqilhdsf.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvtutr.dll
C:\windows\system32\tuvtutr.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvurpn.dll
C:\windows\system32\tuvurpn.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvvwxv.dll
C:\windows\system32\tuvvwxv.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvwxut.dll
C:\windows\system32\tuvwxut.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvwxyy.dll
C:\windows\system32\tuvwxyy.dll Has been deleted!

Attempting to delete C:\windows\system32\uoldxwps.dll
C:\windows\system32\uoldxwps.dll Has been deleted!

Attempting to delete C:\windows\system32\urqpnlj.dll
C:\windows\system32\urqpnlj.dll Has been deleted!

Attempting to delete C:\windows\system32\urqppno.dll
C:\windows\system32\urqppno.dll Has been deleted!

Attempting to delete C:\windows\system32\urqqnlm.dll
C:\windows\system32\urqqnlm.dll Has been deleted!

Attempting to delete C:\windows\system32\urqqpqn.dll
C:\windows\system32\urqqpqn.dll Has been deleted!

Attempting to delete C:\windows\system32\vbudyouk.dll
C:\windows\system32\vbudyouk.dll Has been deleted!

Attempting to delete C:\windows\system32\vturopn.dll
C:\windows\system32\vturopn.dll Has been deleted!

Attempting to delete C:\windows\system32\vtuspqo.dll
C:\windows\system32\vtuspqo.dll Has been deleted!

Attempting to delete C:\windows\system32\vtusstt.dll
C:\windows\system32\vtusstt.dll Has been deleted!

Attempting to delete C:\windows\system32\vtutqpq.dll
C:\windows\system32\vtutqpq.dll Has been deleted!

Attempting to delete C:\windows\system32\vtutrsp.dll
C:\windows\system32\vtutrsp.dll Has been deleted!

Attempting to delete C:\windows\system32\vtuustt.dll
C:\windows\system32\vtuustt.dll Has been deleted!

Attempting to delete C:\windows\system32\wvurqom.dll
C:\windows\system32\wvurqom.dll Has been deleted!

Attempting to delete C:\windows\system32\wvutstt.dll
C:\windows\system32\wvutstt.dll Has been deleted!

Attempting to delete C:\windows\system32\wvuvsrr.dll
C:\windows\system32\wvuvsrr.dll Has been deleted!

Attempting to delete C:\windows\system32\xmcsaqms.dll
C:\windows\system32\xmcsaqms.dll Has been deleted!

Attempting to delete C:\windows\system32\xxyvsst.dll
C:\windows\system32\xxyvsst.dll Has been deleted!

Attempting to delete C:\windows\system32\xxyyaab.dll
C:\windows\system32\xxyyaab.dll Has been deleted!

Attempting to delete C:\windows\system32\yayaawt.dll
C:\windows\system32\yayaawt.dll Has been deleted!

Attempting to delete C:\windows\system32\yayaxvu.dll
C:\windows\system32\yayaxvu.dll Has been deleted!

Attempting to delete C:\windows\system32\yaywuur.dll
C:\windows\system32\yaywuur.dll Has been deleted!

Attempting to delete C:\windows\system32\yayywtu.dll
C:\windows\system32\yayywtu.dll Has been deleted!

Attempting to delete C:\WINDOWS\ttutss.ini
C:\WINDOWS\ttutss.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.8

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:47:19 2007-09-09

Listing files found while scanning....

C:\windows\system32\qomjjji.dll
C:\windows\system32\ssttq.dll

Beginning removal...

Attempting to delete C:\windows\system32\qomjjji.dll
C:\windows\system32\qomjjji.dll Has been deleted!

Attempting to delete C:\windows\system32\ssttq.dll
C:\windows\system32\ssttq.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.8

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:51:55 2007-09-09

Listing files found while scanning....

C:\windows\system32\opnnllj.dll

Beginning removal...

Attempting to delete C:\windows\system32\opnnllj.dll
C:\windows\system32\opnnllj.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\windows\system32\opnnllj.dll
C:\windows\system32\opnnllj.dll Has been deleted!

Performing Repairs to the registry.
Done!






Rapport De Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 11:58:17, on 2007-09-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/granby
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {768FEE08-9B75-4653-A2CD-8822C83A5453} - C:\WINDOWS\system32\ssttq.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\vhmjydfi.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


jai comme une impression que sa a pas changé grand chose pcq jai encore les alerte de virus c vrm chiant :S
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
philae83 Messages postés 12854 Statut Contributeur sécurité 206
 
bonjour,
ok mais dit moi si je dois commencer par les etape de ton premier message avant dembarquer sur Vundofix ou je dois commencer par Vundofix ???


non tu fais dans l'ordre stp.

et pour se qui est c CCleaner est ce que je dois coché TOUTES les case dans (Windows) et dans (application)


tu le laisses en l'état une fois que tu l'as téléchargé et installé, tu lances simplement le nettoyage uniquement le nettoyage

p.s. historique des saisie automatique nest surement pas obligatoire !?!?!?!?!? 


je n'ai pas compris

0
philae83 Messages postés 12854 Statut Contributeur sécurité 206
 
bonjour,

* Fait un scan antivirus en ligne ICI
https://www.bitdefender.fr/
et copie colle le résultat ici
* En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
* Dans la nouvelle fenêtre, clique sur I agree
* La fenêtre change encore, clique sur Click here to scan
* Les signatures se chargent, etc.

tuto en image

http://pageperso.aol.fr/rginformatique/mapage/defender.htm

0
philae83 Messages postés 12854 Statut Contributeur sécurité 206
 
re

pourquoi es tu allé poster au dessus, difficile de s'y retrouver, aussi je mets tout ton rapport ici

Rapport VundoFix

VundoFix V6.5.8

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 10:46:54 2007-09-09

Listing files found while scanning....

C:\WINDOWS\sstutt.dll
C:\windows\system32\awtqrqn.dll
C:\windows\system32\awtrpmk.dll
C:\WINDOWS\system32\awtsqpo.dll
C:\windows\system32\awtsrpq.dll
C:\windows\system32\awttusr.dll
C:\windows\system32\awvspmk.dll
C:\windows\system32\byxurrq.dll
C:\windows\system32\byxwxuv.dll
C:\windows\system32\byxxusp.dll
C:\windows\system32\cbxuutq.dll
C:\windows\system32\cbxvtut.dll
C:\windows\system32\cbxwvvt.dll
C:\windows\system32\cbxwwxv.dll
C:\windows\system32\cbxxyvu.dll
C:\windows\system32\cbxywtu.dll
C:\windows\system32\ddawvwu.dll
C:\windows\system32\ddcaayv.dll
C:\windows\system32\ddcaxwx.dll
C:\windows\system32\ddcyxyv.dll
C:\windows\system32\efcaayy.dll
C:\windows\system32\efcbxxw.dll
C:\windows\system32\efcyaba.dll
C:\windows\system32\efcyyxv.dll
C:\windows\system32\fccawus.dll
C:\windows\system32\fccbxvs.dll
C:\windows\system32\fccccby.dll
C:\windows\system32\fccyaby.dll
C:\windows\system32\fccyyaa.dll
C:\windows\system32\fjlluena.dll
C:\windows\system32\gebaaya.dll
C:\windows\system32\gebabyy.dll
C:\windows\system32\gebaywv.dll
C:\windows\system32\gebxusr.dll
C:\windows\system32\gebxwvs.dll
C:\windows\system32\gebyaxx.dll
C:\windows\system32\hggdebc.dll
C:\windows\system32\hggfdba.dll
C:\windows\system32\hgghebb.dll
C:\windows\system32\hgghedc.dll
C:\windows\system32\hgghgff.dll
C:\windows\system32\hgghhif.dll
C:\windows\system32\hsacgmrj.dll
C:\windows\system32\iifefff.dll
C:\windows\system32\jjssqfte.dll
C:\windows\system32\jkkhfdc.dll
C:\windows\system32\jkkjgfg.dll
C:\windows\system32\jkkkjgg.dll
C:\windows\system32\khfcbay.dll
C:\windows\system32\khfcdee.dll
C:\windows\system32\khfdccc.dll
C:\windows\system32\khfeccb.dll
C:\windows\system32\khfecdd.dll
C:\windows\system32\khffeca.dll
C:\windows\system32\khfgfda.dll
C:\windows\system32\khfgfef.dll
C:\windows\system32\khfgffc.dll
C:\windows\system32\khfggde.dll
C:\windows\system32\khfghif.dll
C:\windows\system32\ljjgdee.dll
C:\windows\system32\ljjhfec.dll
C:\windows\system32\ljjhghf.dll
C:\windows\system32\ljjhghi.dll
C:\windows\system32\ljjkigf.dll
C:\windows\system32\ljjkkjg.dll
C:\windows\system32\mljghhe.dll
C:\windows\system32\mljhijj.dll
C:\windows\system32\mljjiig.dll
C:\windows\system32\mljjjki.dll
C:\windows\system32\mljjkjj.dll
C:\windows\system32\nnnmmnn.dll
C:\windows\system32\nnnnkjj.dll
C:\windows\system32\nnnopnk.dll
C:\windows\system32\opnlihh.dll
C:\windows\system32\opnliji.dll
C:\windows\system32\opnmjif.dll
C:\windows\system32\opnmkki.dll
C:\windows\system32\opnnoll.dll
C:\windows\system32\opnolmk.dll
C:\windows\system32\pmnlkkk.dll
C:\windows\system32\pmnomjh.dll
C:\windows\system32\pmnomnl.dll
C:\windows\system32\qomjjgf.dll
C:\windows\system32\qommlml.dll
C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\qttss.ini
C:\windows\system32\rqromjg.dll
C:\windows\system32\rqrqqnk.dll
C:\windows\system32\rqrrpmk.dll
C:\windows\system32\rqrrsss.dll
C:\windows\system32\rqrsppq.dll
C:\windows\system32\rqrsqnk.dll
C:\windows\system32\ssqpmki.dll
C:\WINDOWS\system32\ssttq.dll
C:\windows\system32\tfdwimvh.dll
C:\WINDOWS\system32\tmpD9.tmp.dll
C:\windows\system32\tqilhdsf.dll
C:\windows\system32\tuvtutr.dll
C:\windows\system32\tuvurpn.dll
C:\windows\system32\tuvvwxv.dll
C:\windows\system32\tuvwxut.dll
C:\windows\system32\tuvwxyy.dll
C:\windows\system32\uoldxwps.dll
C:\windows\system32\urqpnlj.dll
C:\windows\system32\urqppno.dll
C:\windows\system32\urqqnlm.dll
C:\windows\system32\urqqpqn.dll
C:\windows\system32\vbudyouk.dll
C:\windows\system32\vturopn.dll
C:\windows\system32\vtuspqo.dll
C:\windows\system32\vtusstt.dll
C:\windows\system32\vtutqpq.dll
C:\windows\system32\vtutrsp.dll
C:\windows\system32\vtuustt.dll
C:\windows\system32\wvurqom.dll
C:\windows\system32\wvutstt.dll
C:\windows\system32\wvuvsrr.dll
C:\windows\system32\xmcsaqms.dll
C:\windows\system32\xxyvsst.dll
C:\windows\system32\xxyyaab.dll
C:\windows\system32\yayaawt.dll
C:\windows\system32\yayaxvu.dll
C:\windows\system32\yaywuur.dll
C:\windows\system32\yayywtu.dll
C:\WINDOWS\ttutss.ini

Beginning removal...

Attempting to delete C:\WINDOWS\sstutt.dll
C:\WINDOWS\sstutt.dll Has been deleted!

Attempting to delete C:\windows\system32\awtqrqn.dll
C:\windows\system32\awtqrqn.dll Has been deleted!

Attempting to delete C:\windows\system32\awtrpmk.dll
C:\windows\system32\awtrpmk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\awtsqpo.dll
C:\WINDOWS\system32\awtsqpo.dll Could not be deleted.

Attempting to delete C:\windows\system32\awtsrpq.dll
C:\windows\system32\awtsrpq.dll Has been deleted!

Attempting to delete C:\windows\system32\awttusr.dll
C:\windows\system32\awttusr.dll Has been deleted!

Attempting to delete C:\windows\system32\awvspmk.dll
C:\windows\system32\awvspmk.dll Has been deleted!

Attempting to delete C:\windows\system32\byxurrq.dll
C:\windows\system32\byxurrq.dll Has been deleted!

Attempting to delete C:\windows\system32\byxwxuv.dll
C:\windows\system32\byxwxuv.dll Has been deleted!

Attempting to delete C:\windows\system32\byxxusp.dll
C:\windows\system32\byxxusp.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxuutq.dll
C:\windows\system32\cbxuutq.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxvtut.dll
C:\windows\system32\cbxvtut.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxwvvt.dll
C:\windows\system32\cbxwvvt.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxwwxv.dll
C:\windows\system32\cbxwwxv.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxxyvu.dll
C:\windows\system32\cbxxyvu.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxywtu.dll
C:\windows\system32\cbxywtu.dll Has been deleted!

Attempting to delete C:\windows\system32\ddawvwu.dll
C:\windows\system32\ddawvwu.dll Has been deleted!

Attempting to delete C:\windows\system32\ddcaayv.dll
C:\windows\system32\ddcaayv.dll Has been deleted!

Attempting to delete C:\windows\system32\ddcaxwx.dll
C:\windows\system32\ddcaxwx.dll Has been deleted!

Attempting to delete C:\windows\system32\ddcyxyv.dll
C:\windows\system32\ddcyxyv.dll Has been deleted!

Attempting to delete C:\windows\system32\efcaayy.dll
C:\windows\system32\efcaayy.dll Has been deleted!

Attempting to delete C:\windows\system32\efcbxxw.dll
C:\windows\system32\efcbxxw.dll Has been deleted!

Attempting to delete C:\windows\system32\efcyaba.dll
C:\windows\system32\efcyaba.dll Has been deleted!

Attempting to delete C:\windows\system32\efcyyxv.dll
C:\windows\system32\efcyyxv.dll Has been deleted!

Attempting to delete C:\windows\system32\fccawus.dll
C:\windows\system32\fccawus.dll Has been deleted!

Attempting to delete C:\windows\system32\fccbxvs.dll
C:\windows\system32\fccbxvs.dll Has been deleted!

Attempting to delete C:\windows\system32\fccccby.dll
C:\windows\system32\fccccby.dll Has been deleted!

Attempting to delete C:\windows\system32\fccyaby.dll
C:\windows\system32\fccyaby.dll Has been deleted!

Attempting to delete C:\windows\system32\fccyyaa.dll
C:\wind
VundoFix V6.5.8

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:35:58 2007-09-09

Listing files found while scanning....

C:\WINDOWS\sstutt.dll
C:\windows\system32\awtsqpo.dll
C:\windows\system32\fjlluena.dll
C:\windows\system32\gebaaya.dll
C:\windows\system32\gebabyy.dll
C:\windows\system32\gebaywv.dll
C:\windows\system32\gebxusr.dll
C:\windows\system32\gebxwvs.dll
C:\windows\system32\gebyaxx.dll
C:\windows\system32\hggdebc.dll
C:\windows\system32\hggfdba.dll
C:\windows\system32\hgghebb.dll
C:\windows\system32\hgghedc.dll
C:\windows\system32\hgghgff.dll
C:\windows\system32\hgghhif.dll
C:\windows\system32\hsacgmrj.dll
C:\windows\system32\iifefff.dll
C:\windows\system32\jjssqfte.dll
C:\windows\system32\jkkhfdc.dll
C:\windows\system32\jkkjgfg.dll
C:\windows\system32\jkkkjgg.dll
C:\windows\system32\khfcbay.dll
C:\windows\system32\khfcdee.dll
C:\windows\system32\khfdccc.dll
C:\windows\system32\khfeccb.dll
C:\windows\system32\khfecdd.dll
C:\windows\system32\khffeca.dll
C:\windows\system32\khfgfda.dll
C:\windows\system32\khfgfef.dll
C:\windows\system32\khfgffc.dll
C:\windows\system32\khfggde.dll
C:\windows\system32\khfghif.dll
C:\windows\system32\ljjgdee.dll
C:\windows\system32\ljjhfec.dll
C:\windows\system32\ljjhghf.dll
C:\windows\system32\ljjhghi.dll
C:\windows\system32\ljjkigf.dll
C:\windows\system32\ljjkkjg.dll
C:\windows\system32\mljghhe.dll
C:\windows\system32\mljhijj.dll
C:\windows\system32\mljjiig.dll
C:\windows\system32\mljjjki.dll
C:\windows\system32\mljjkjj.dll
C:\windows\system32\nnnmmnn.dll
C:\windows\system32\nnnnkjj.dll
C:\windows\system32\nnnopnk.dll
C:\windows\system32\opnlihh.dll
C:\windows\system32\opnliji.dll
C:\windows\system32\opnmjif.dll
C:\windows\system32\opnmkki.dll
C:\windows\system32\opnnoll.dll
C:\windows\system32\opnolmk.dll
C:\windows\system32\pmnlkkk.dll
C:\windows\system32\pmnomjh.dll
C:\windows\system32\pmnomnl.dll
C:\windows\system32\qomjjgf.dll
C:\WINDOWS\system32\qomjjji.dll
C:\windows\system32\qommlml.dll
C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\qttss.ini
C:\windows\system32\rqromjg.dll
C:\windows\system32\rqrqqnk.dll
C:\windows\system32\rqrrpmk.dll
C:\windows\system32\rqrrsss.dll
C:\windows\system32\rqrsppq.dll
C:\windows\system32\rqrsqnk.dll
C:\windows\system32\ssqpmki.dll
C:\WINDOWS\system32\ssttq.dll
C:\windows\system32\tfdwimvh.dll
C:\WINDOWS\system32\tmpD9.tmp.dll
C:\windows\system32\tqilhdsf.dll
C:\windows\system32\tuvtutr.dll
C:\windows\system32\tuvurpn.dll
C:\windows\system32\tuvvwxv.dll
C:\windows\system32\tuvwxut.dll
C:\windows\system32\tuvwxyy.dll
C:\windows\system32\uoldxwps.dll
C:\windows\system32\urqpnlj.dll
C:\windows\system32\urqppno.dll
C:\windows\system32\urqqnlm.dll
C:\windows\system32\urqqpqn.dll
C:\windows\system32\vbudyouk.dll
C:\windows\system32\vturopn.dll
C:\windows\system32\vtuspqo.dll
C:\windows\system32\vtusstt.dll
C:\windows\system32\vtutqpq.dll
C:\windows\system32\vtutrsp.dll
C:\windows\system32\vtuustt.dll
C:\windows\system32\wvurqom.dll
C:\windows\system32\wvutstt.dll
C:\windows\system32\wvuvsrr.dll
C:\windows\system32\xmcsaqms.dll
C:\windows\system32\xxyvsst.dll
C:\windows\system32\xxyyaab.dll
C:\windows\system32\yayaawt.dll
C:\windows\system32\yayaxvu.dll
C:\windows\system32\yaywuur.dll
C:\windows\system32\yayywtu.dll
C:\WINDOWS\ttutss.ini

Beginning removal...

Attempting to delete C:\windows\system32\awtsqpo.dll
C:\windows\system32\awtsqpo.dll Has been deleted!

Attempting to delete C:\windows\system32\fjlluena.dll
C:\windows\system32\fjlluena.dll Has been deleted!

Attempting to delete C:\windows\system32\gebaaya.dll
C:\windows\system32\gebaaya.dll Has been deleted!

Attempting to delete C:\windows\system32\gebabyy.dll
C:\windows\system32\gebabyy.dll Has been deleted!

Attempting to delete C:\windows\system32\gebaywv.dll
C:\windows\system32\gebaywv.dll Has been deleted!

Attempting to delete C:\windows\system32\gebxusr.dll
C:\windows\system32\gebxusr.dll Has been deleted!

Attempting to delete C:\windows\system32\gebxwvs.dll
C:\windows\system32\gebxwvs.dll Has been deleted!

Attempting to delete C:\windows\system32\gebyaxx.dll
C:\windows\system32\gebyaxx.dll Has been deleted!

Attempting to delete C:\windows\system32\hggdebc.dll
C:\windows\system32\hggdebc.dll Has been deleted!

Attempting to delete C:\windows\system32\hggfdba.dll
C:\windows\system32\hggfdba.dll Has been deleted!

Attempting to delete C:\windows\system32\hgghebb.dll
C:\windows\system32\hgghebb.dll Has been deleted!

Attempting to delete C:\windows\system32\hgghedc.dll
C:\windows\system32\hgghedc.dll Has been deleted!

Attempting to delete C:\windows\system32\hgghgff.dll
C:\windows\system32\hgghgff.dll Has been deleted!

Attempting to delete C:\windows\system32\hgghhif.dll
C:\windows\system32\hgghhif.dll Has been deleted!

Attempting to delete C:\windows\system32\hsacgmrj.dll
C:\windows\system32\hsacgmrj.dll Has been deleted!

Attempting to delete C:\windows\system32\iifefff.dll
C:\windows\system32\iifefff.dll Has been deleted!

Attempting to delete C:\windows\system32\jjssqfte.dll
C:\windows\system32\jjssqfte.dll Has been deleted!

Attempting to delete C:\windows\system32\jkkhfdc.dll
C:\windows\system32\jkkhfdc.dll Has been deleted!

Attempting to delete C:\windows\system32\jkkjgfg.dll
C:\windows\system32\jkkjgfg.dll Has been deleted!

Attempting to delete C:\windows\system32\jkkkjgg.dll
C:\windows\system32\jkkkjgg.dll Has been deleted!

Attempting to delete C:\windows\system32\khfcbay.dll
C:\windows\system32\khfcbay.dll Has been deleted!

Attempting to delete C:\windows\system32\khfcdee.dll
C:\windows\system32\khfcdee.dll Has been deleted!

Attempting to delete C:\windows\system32\khfdccc.dll
C:\windows\system32\khfdccc.dll Has been deleted!

Attempting to delete C:\windows\system32\khfeccb.dll
C:\windows\system32\khfeccb.dll Has been deleted!

Attempting to delete C:\windows\system32\khfecdd.dll
C:\windows\system32\khfecdd.dll Has been deleted!

Attempting to delete C:\windows\system32\khffeca.dll
C:\windows\system32\khffeca.dll Has been deleted!

Attempting to delete C:\windows\system32\khfgfda.dll
C:\windows\system32\khfgfda.dll Has been deleted!

Attempting to delete C:\windows\system32\khfgfef.dll
C:\windows\system32\khfgfef.dll Has been deleted!

Attempting to delete C:\windows\system32\khfgffc.dll
C:\windows\system32\khfgffc.dll Has been deleted!

Attempting to delete C:\windows\system32\khfggde.dll
C:\windows\system32\khfggde.dll Has been deleted!

Attempting to delete C:\windows\system32\khfghif.dll
C:\windows\system32\khfghif.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjgdee.dll
C:\windows\system32\ljjgdee.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjhfec.dll
C:\windows\system32\ljjhfec.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjhghf.dll
C:\windows\system32\ljjhghf.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjhghi.dll
C:\windows\system32\ljjhghi.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjkigf.dll
C:\windows\system32\ljjkigf.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjkkjg.dll
C:\windows\system32\ljjkkjg.dll Has been deleted!

Attempting to delete C:\windows\system32\mljghhe.dll
C:\windows\system32\mljghhe.dll Has been deleted!

Attempting to delete C:\windows\system32\mljhijj.dll
C:\windows\system32\mljhijj.dll Has been deleted!

Attempting to delete C:\windows\system32\mljjiig.dll
C:\windows\system32\mljjiig.dll Has been deleted!

Attempting to delete C:\windows\system32\mljjjki.dll
C:\windows\system32\mljjjki.dll Has been deleted!

Attempting to delete C:\windows\system32\mljjkjj.dll
C:\windows\system32\mljjkjj.dll Has been deleted!

Attempting to delete C:\windows\system32\nnnmmnn.dll
C:\windows\system32\nnnmmnn.dll Has been deleted!

Attempting to delete C:\windows\system32\nnnnkjj.dll
C:\windows\system32\nnnnkjj.dll Has been deleted!

Attempting to delete C:\windows\system32\nnnopnk.dll
C:\windows\system32\nnnopnk.dll Has been deleted!

Attempting to delete C:\windows\system32\opnlihh.dll
C:\windows\system32\opnlihh.dll Has been deleted!

Attempting to delete C:\windows\system32\opnliji.dll
C:\windows\system32\opnliji.dll Has been deleted!

Attempting to delete C:\windows\system32\opnmjif.dll
C:\windows\system32\opnmjif.dll Has been deleted!

Attempting to delete C:\windows\system32\opnmkki.dll
C:\windows\system32\opnmkki.dll Has been deleted!

Attempting to delete C:\windows\system32\opnnoll.dll
C:\windows\system32\opnnoll.dll Has been deleted!

Attempting to delete C:\windows\system32\opnolmk.dll
C:\windows\system32\opnolmk.dll Has been deleted!

Attempting to delete C:\windows\system32\pmnlkkk.dll
C:\windows\system32\pmnlkkk.dll Has been deleted!

Attempting to delete C:\windows\system32\pmnomjh.dll
C:\windows\system32\pmnomjh.dll Has been deleted!

Attempting to delete C:\windows\system32\pmnomnl.dll
C:\windows\system32\pmnomnl.dll Has been deleted!

Attempting to delete C:\windows\system32\qomjjgf.dll
C:\windows\system32\qomjjgf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomjjji.dll
C:\WINDOWS\system32\qomjjji.dll Could not be deleted.

Attempting to delete C:\windows\system32\qommlml.dll
C:\windows\system32\qommlml.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\qttss.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\qttss.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\qttss.ini
C:\WINDOWS\system32\qttss.ini Has been deleted!

Attempting to delete C:\windows\system32\rqromjg.dll
C:\windows\system32\rqromjg.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrqqnk.dll
C:\windows\system32\rqrqqnk.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrrpmk.dll
C:\windows\system32\rqrrpmk.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrrsss.dll
C:\windows\system32\rqrrsss.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrsppq.dll
C:\windows\system32\rqrsppq.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrsqnk.dll
C:\windows\system32\rqrsqnk.dll Has been deleted!

Attempting to delete C:\windows\system32\ssqpmki.dll
C:\windows\system32\ssqpmki.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssttq.dll
C:\WINDOWS\system32\ssttq.dll Could not be deleted.

Attempting to delete C:\windows\system32\tfdwimvh.dll
C:\windows\system32\tfdwimvh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tmpD9.tmp.dll
C:\WINDOWS\system32\tmpD9.tmp.dll Has been deleted!

Attempting to delete C:\windows\system32\tqilhdsf.dll
C:\windows\system32\tqilhdsf.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvtutr.dll
C:\windows\system32\tuvtutr.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvurpn.dll
C:\windows\system32\tuvurpn.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvvwxv.dll
C:\windows\system32\tuvvwxv.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvwxut.dll
C:\windows\system32\tuvwxut.dll Has been deleted!

Attempting to delete C:\windows\system32\tuvwxyy.dll
C:\windows\system32\tuvwxyy.dll Has been deleted!

Attempting to delete C:\windows\system32\uoldxwps.dll
C:\windows\system32\uoldxwps.dll Has been deleted!

Attempting to delete C:\windows\system32\urqpnlj.dll
C:\windows\system32\urqpnlj.dll Has been deleted!

Attempting to delete C:\windows\system32\urqppno.dll
C:\windows\system32\urqppno.dll Has been deleted!

Attempting to delete C:\windows\system32\urqqnlm.dll
C:\windows\system32\urqqnlm.dll Has been deleted!

Attempting to delete C:\windows\system32\urqqpqn.dll
C:\windows\system32\urqqpqn.dll Has been deleted!

Attempting to delete C:\windows\system32\vbudyouk.dll
C:\windows\system32\vbudyouk.dll Has been deleted!

Attempting to delete C:\windows\system32\vturopn.dll
C:\windows\system32\vturopn.dll Has been deleted!

Attempting to delete C:\windows\system32\vtuspqo.dll
C:\windows\system32\vtuspqo.dll Has been deleted!

Attempting to delete C:\windows\system32\vtusstt.dll
C:\windows\system32\vtusstt.dll Has been deleted!

Attempting to delete C:\windows\system32\vtutqpq.dll
C:\windows\system32\vtutqpq.dll Has been deleted!

Attempting to delete C:\windows\system32\vtutrsp.dll
C:\windows\system32\vtutrsp.dll Has been deleted!

Attempting to delete C:\windows\system32\vtuustt.dll
C:\windows\system32\vtuustt.dll Has been deleted!

Attempting to delete C:\windows\system32\wvurqom.dll
C:\windows\system32\wvurqom.dll Has been deleted!

Attempting to delete C:\windows\system32\wvutstt.dll
C:\windows\system32\wvutstt.dll Has been deleted!

Attempting to delete C:\windows\system32\wvuvsrr.dll
C:\windows\system32\wvuvsrr.dll Has been deleted!

Attempting to delete C:\windows\system32\xmcsaqms.dll
C:\windows\system32\xmcsaqms.dll Has been deleted!

Attempting to delete C:\windows\system32\xxyvsst.dll
C:\windows\system32\xxyvsst.dll Has been deleted!

Attempting to delete C:\windows\system32\xxyyaab.dll
C:\windows\system32\xxyyaab.dll Has been deleted!

Attempting to delete C:\windows\system32\yayaawt.dll
C:\windows\system32\yayaawt.dll Has been deleted!

Attempting to delete C:\windows\system32\yayaxvu.dll
C:\windows\system32\yayaxvu.dll Has been deleted!

Attempting to delete C:\windows\system32\yaywuur.dll
C:\windows\system32\yaywuur.dll Has been deleted!

Attempting to delete C:\windows\system32\yayywtu.dll
C:\windows\system32\yayywtu.dll Has been deleted!

Attempting to delete C:\WINDOWS\ttutss.ini
C:\WINDOWS\ttutss.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.8

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:47:19 2007-09-09

Listing files found while scanning....

C:\windows\system32\qomjjji.dll
C:\windows\system32\ssttq.dll

Beginning removal...

Attempting to delete C:\windows\system32\qomjjji.dll
C:\windows\system32\qomjjji.dll Has been deleted!

Attempting to delete C:\windows\system32\ssttq.dll
C:\windows\system32\ssttq.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.8

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:51:55 2007-09-09

Listing files found while scanning....

C:\windows\system32\opnnllj.dll

Beginning removal...

Attempting to delete C:\windows\system32\opnnllj.dll
C:\windows\system32\opnnllj.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\windows\system32\opnnllj.dll
C:\windows\system32\opnnllj.dll Has been deleted!

Performing Repairs to the registry.
Done!

Rapport De Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 11:58:17, on 2007-09-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/granby
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {768FEE08-9B75-4653-A2CD-8822C83A5453} - C:\WINDOWS\system32\ssttq.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\vhmjydfi.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

jai comme une impression que sa a pas changé grand chose pcq jai encore les alerte de virus c vrm chiant :S
0
Rudy2k5
 
je tenvois le rapport de bit defender il sest produit qqch dassé important je crois lors du scan de bit defender jai recu PLUSIEURS

alertes de Avast je ten donne la liste si sa peut taider Win32:Vundo-gen48[Adw] Win32:Vundo-gen46[Adw]

Win32:Vundo-gen47[Adw] Win32:Vundo-gen49[Adw] Win32: Agent-HOP[Wrm] (celui dont il est question depuis le debut :s)

Win32:Tiny-IF [Trj] Ils sont tous apparu a plusieurs reprise dont le derniere qui est apparu 5x de suite des que je fesait mettre en

quarantaine, il réapparaissait :s ....... et la plupart etais detecté ds system Volume Information/ restore et dans le dossier vundofix Backup et a une autre place que je nai pas prit en note :s

donc voici le rapport:

<HTML>
<HEAD>
<TITLE>BitDefender Online Scanner - Rapport d'analyse</TITLE>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
</HEAD>
<BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >

<table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
<tr>
<td width="458">
<p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender Online Scanner</b></span></font></p>
</td>
<td width="40%">
<p> </p>
</td>
<td width="10%">
<p> </p>
</td>
</tr>
<tr>
<td colspan="3" width="912">
<p><font face="Arial"><span style="font-size:11pt;"><B>Rapport d'analyse généré à: Sun, Sep 09, 2007 - 13:22:57</b></span></font></p>
</td>
</tr>

<tr>
<td width="458">
<p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
</td>
<td width="40%">
<p> </p>
</td>
<td width="10%">
<p> </p>
</td>
</tr>

<tr>
<td width="458">
<p><font face="Arial"><span style="font-size:11pt;"><B>Voie d'analyse: </b></span><span style="font-size:10pt;">A:\;C:\;D:\;</span></font></p>
</td>
<td width="40%">
<p> </p>
</td>
<td width="10%">
<p> </p>
</td>
</tr>

<tr>
<td width="458">
<p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
</td>
<td width="40%">
<p> </p>
</td>
<td width="10%">
<p> </p>
</td>
</tr>

<tr>
<td width="458">
<table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
<tr>
<td width="451" colspan="2" bgcolor="#CCCCCC">
<p><font face="Arial" size="2"><B>Statistiques</b></font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Temps</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">01:04:26</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Fichiers</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">261302</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Directoires</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">7750</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Secteurs de boot</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">2</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Archives</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">1608</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Paquets programmes</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">9964</font></p>
</td>
</tr>
</table>
</td>
<td width="40%">
<p> </p>
</td>
<td width="10%">
<p> </p>
</td>
</tr>

<tr>
<td width="458">
<table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
<tr>
<td width="451" colspan="2" bgcolor="#CCCCCC">
<p><font face="Arial" size="2"><B>Résultats</b></font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Virus identifiés</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">9</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Fichiers infectés</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">282</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Fichiers suspects</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">0</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Avertissements</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">0</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Désinfectés</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">0</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Fichiers effacés</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">282</font></p>
</td>
</tr>
</table>
</td>
<td width="40%">
<p> </p>
</td>
<td width="10%">
<p> </p>
</td>
</tr>

<tr>
<td width="458">
<table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
<tr>
<td width="451" colspan="2" bgcolor="#CCCCCC">
<p><font face="Arial" size="2"><B>Info sur les moteurs</b></font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Définition virus</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">800243</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Version des moteurs</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Analyse des plugins</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">14</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Archive des plugins</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">38</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Unpack des plugins</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">7</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">E-mail plugins</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">6</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Système plugins</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">1</font></p>
</td>
</tr>
</table>
</td>
<td width="40%">
<p> </p>
</td>
<td width="10%">
<p> </p>
</td>
</tr>

<tr>
<td width="458">
<table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
<tr>
<td width="451" colspan="2" bgcolor="#CCCCCC">
<p><font face="Arial" size="2"><B>Paramètres d'analyse</b></font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Première action</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">Désinfecté</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Seconde Action</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Heuristique</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">Oui</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Acceptez les avertissements</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">Oui</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Extensions analysées</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">*;</font></p>
</td>
</tr>

<tr>
<td width="57%">
<p><font face="Arial" size="2">Excludez les extensions</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2"> </font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Analyse d'emails</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">Oui</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Analyse des Archives</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">Oui</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Analyser paquets programmes</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">Oui</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Analyse des fichiers</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">Oui</font></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">Analyse de boot</font></p>
</td>
<td width="43%" align="right">
<p><font face="Arial" size="2">Oui</font></p>
</td>
</tr>
</table>
</td>
<td width="40%">
<p> </p>
</td>
<td width="10%">
<p> </p>
</td>
</tr>

<tr>
<td colspan=2>
<table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
<tr>
<td width="252" bgcolor="#CCCCCC">
<p><font face="Arial" size="2"><B>Fichier analysé</b></font></p>
</td>
<td width="195" bgcolor="#CCCCCC" align="right">
<p align="left"><b><font size="2" face="Arial"> Statut</font></b></p>
</td>
</tr>
<tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp2.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Dropper.Agent.BON</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp2.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp2.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp3.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Juan.V</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp3.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp3.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp31.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Dropper.Agent.BON</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp31.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp31.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp32.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Juan.V</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp32.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmp32.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmpD9.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: MemScan:Trojan.Juan.V</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmpD9.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Application Data\tmpD9.tmp.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\theq3[1].exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Win32.Worm.Garm.C</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\theq3[1].exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\theq3[1].exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\poep[1].exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\Documents and Settings\SG-C\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\poep[1].exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005635.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMP</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005635.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005635.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005637.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMP</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005637.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005637.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005638.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMX</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005638.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP14\A0005638.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013565.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Win32.Worm.Garm.C</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013565.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013565.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013677.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013677.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013679.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013679.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013679.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013680.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013680.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013680.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013681.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013681.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013681.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013682.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013682.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013682.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013683.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Clicker.Agent.NP</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013683.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013683.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013684.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Fotomoto.E</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013684.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013684.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013696.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Win32.Worm.Garm.C</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013696.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Echec de la désinfection</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013696.exe</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013700.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013700.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013701.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013701.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013702.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013702.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013703.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013703.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013704.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013704.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013705.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013705.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013706.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013706.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013707.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013707.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013708.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013708.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013709.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013709.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013710.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013710.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013711.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013711.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013712.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013712.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013713.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013713.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013714.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013714.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013715.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Infecté par: Trojan.Vundo.DMU</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013715.dll</font></p>
</td>
<td width="43%" align="left">
<p><font face="Arial" size="2">Supprimé</font></p>
</td>
</tr><tr>
<td width="57%">
<p><font face="Arial" size="2">C:\System Volume Information\_restore{995D90B2-AF53-4B6D-9670-B808B517FFC7}\RP23\A0013716.dll
0
Rudy2k5 Messages postés 6 Statut Membre
 
au juste pourquoi as tu reposté mon rapport ??
0
philae83 Messages postés 12854 Statut Contributeur sécurité 206
 
J'ai reposté ton rapport car il n'avait pas été mis au bon endroit, c plus facile pour moi surtout quand je reprends ce que l'on a déjà fait, les avoir dans l'ordre me parait plus simple :)

bon le scan a bien travaillé visiblement

reposte un nouveau rapport hijackthis
0
Rudy2k5
 
Voici le dernier log de Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 21:57:14, on 2007-09-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msgs.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/granby
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {768FEE08-9B75-4653-A2CD-8822C83A5453} - C:\WINDOWS\system32\ssttq.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\vhmjydfi.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
0
philae83 Messages postés 12854 Statut Contributeur sécurité 206
 
bonjour,

* Relance Vundofix
* Ne clique pas sur "Scan for a vundo"
* Clique droit au milieu de la fenêtre
* Clique sur Add more files ?
* Copie/colle les fichiers ci-dessous ( un par case) :

C:\WINDOWS\SYSTEM32\ieakdlv.dll

* Clique sur Add files
* Ensuite clique sur Close Windows
* Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaitre dans la fenêtre principale)
* Si l'outils demande un redémarrage, accepte
* Poste le rapport Vundofix

puis

* lance hijackthis puis coche ces lignes :

O2 - BHO: (no name) - {768FEE08-9B75-4653-A2CD-8822C83A5453} - C:\WINDOWS\system32\ssttq.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O20 - Winlogon Notify: ieakdlv - C:\WINDOWS\SYSTEM32\ieakdlv.dll
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\vhmjydfi.exe (file missing)

* ferme toutes les applications ouvertes y compris internet explorer et clique sur "fixer objet"

puis

* Assure toi d'avoir accès à tous les fichiers

-démarrer

-poste de travail ou autre dossier

-menu outils

-options de dossier

-onglet affichage

puis

- activer la case : Afficher les fichiers et dossiers cachés

- désactiver la case : Masquer les extensions des fichiers dont le type est connu

- désactiver la case : Masquer les fichier protégés du système d'exploitation

Puis - Appliquer

* et Supprime le(s) fichier(s) ci dessous si il(s) est (sont) présent(s) :

C:\WINDOWS\system32\vhmjydfi.exe

* Dans l'Explorateur Windows recache les fichiers système afin de ne pas faire d'erreur à l'avenir. Retourne à la fenêtre Paramètres de dossiers et sélectionne Ne pas afficher les fichiers cachés ou les fichiers système

puis

reposte un nouveau rapport hijackthis
0