Pb avec Virtumonde

Résolu
Bonjour,

Toute nouvelle adhérente, je ne sais pas trop comment marche ce forum. J'ai envoyé un msg pour un pb de virus Virtumonde. J'ai eu une réponse de philéa83 sur mon adresse email, et voilà mes rapports :

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 07:56:10 03/10/2007

Listing files found while scanning....

C:\windows\system32\hhkmp.bak1
C:\windows\system32\hhkmp.bak2
C:\windows\system32\hhkmp.ini
C:\windows\system32\jqyuxcxu.ini
C:\WINDOWS\system32\mdkbgxes.dll
C:\windows\system32\orqss.bak1
C:\windows\system32\orqss.bak2
C:\windows\system32\orqss.ini
C:\windows\system32\pmkhh.dll
C:\WINDOWS\system32\sexgbkdm.ini
C:\windows\system32\ssqro.dll
C:\windows\system32\uxcxuyqj.dll

Beginning removal...

Beginning removal...

Attempting to delete C:\windows\system32\hhkmp.bak1
C:\windows\system32\hhkmp.bak1 Has been deleted!

Attempting to delete C:\windows\system32\hhkmp.bak2
C:\windows\system32\hhkmp.bak2 Has been deleted!

Attempting to delete C:\windows\system32\hhkmp.ini
C:\windows\system32\hhkmp.ini Has been deleted!

Attempting to delete C:\windows\system32\jqyuxcxu.ini
C:\windows\system32\jqyuxcxu.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mdkbgxes.dll
C:\WINDOWS\system32\mdkbgxes.dll Could not be deleted.

Attempting to delete C:\windows\system32\orqss.bak1
C:\windows\system32\orqss.bak1 Has been deleted!

Attempting to delete C:\windows\system32\orqss.bak2
C:\windows\system32\orqss.bak2 Has been deleted!

Attempting to delete C:\windows\system32\orqss.ini
C:\windows\system32\orqss.ini Has been deleted!

Attempting to delete C:\windows\system32\pmkhh.dll
C:\windows\system32\pmkhh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sexgbkdm.ini
C:\WINDOWS\system32\sexgbkdm.ini Has been deleted!

Attempting to delete C:\windows\system32\ssqro.dll
C:\windows\system32\ssqro.dll Has been deleted!

Attempting to delete C:\windows\system32\uxcxuyqj.dll
C:\windows\system32\uxcxuyqj.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 08:05:05 03/10/2007

Listing files found while scanning....

No infected files were found.

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 08:29:27 12/10/2007

Listing files found while scanning....

C:\WINDOWS\system32\carvvpam.dll
C:\windows\system32\ihbqxpox.ini
C:\WINDOWS\system32\mapvvrac.ini
C:\windows\system32\xopxqbhi.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\carvvpam.dll
C:\WINDOWS\system32\carvvpam.dll Could not be deleted.

Attempting to delete C:\windows\system32\ihbqxpox.ini
C:\windows\system32\ihbqxpox.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mapvvrac.ini
C:\WINDOWS\system32\mapvvrac.ini Has been deleted!

Attempting to delete C:\windows\system32\xopxqbhi.dll
C:\windows\system32\xopxqbhi.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 08:33:41 12/10/2007

Listing files found while scanning....

No infected files were found.

Beginning removal...

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 14:24:00 12/10/2007

Listing files found while scanning....

C:\WINDOWS\system32\akujogan.dll
C:\windows\system32\mswstr10.dll
C:\WINDOWS\system32\nagojuka.ini

Beginning removal...

Attempting to delete C:\WINDOWS\system32\akujogan.dll
C:\WINDOWS\system32\akujogan.dll Could not be deleted.

Attempting to delete C:\windows\system32\mswstr10.dll
C:\windows\system32\mswstr10.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nagojuka.ini
C:\WINDOWS\system32\nagojuka.ini Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\akujogan.dll
C:\WINDOWS\system32\akujogan.dll Has been deleted!

Attempting to delete C:\windows\system32\mswstr10.dll
C:\windows\system32\mswstr10.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\mdkbgxes.dll
C:\WINDOWS\system32\mdkbgxes.dll Has been deleted!

Performing Repairs to the registry.
Done!

HIJACKTHIS

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:24:27, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 9323 bytes

BitDefender Online Scanner

Rapport d'analyse généré à: Fri, Oct 12, 2007 - 22:26:30

Voie d'analyse: C:\;D:\;F:\;

Statistiques

Temps

02:11:16

Fichiers

283411

Directoires

11351

Secteurs de boot

2

Archives

3186

Paquets programmes

14971

Résultats

Virus identifiés

8

Fichiers infectés

25

Fichiers suspects

0

Avertissements

0

Désinfectés

0

Fichiers effacés

24

Info sur les moteurs

Définition virus

826479

Version des moteurs

AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

Analyse des plugins

14

Archive des plugins

38

Unpack des plugins

7

E-mail plugins

6

Système plugins

1

Paramètres d'analyse

Première action

Désinfecté

Seconde Action

Supprimé

Heuristique

Oui

Acceptez les avertissements

Oui

Extensions analysées

*;

Excludez les extensions

Analyse d'emails

Oui

Analyse des Archives

Oui

Analyser paquets programmes

Oui

Analyse des fichiers

Oui

Analyse de boot

Oui

Fichier analysé

Statut

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 0)

Infecté par: Trojan.Downloader.Agent.ALR

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 0)

Echec de la désinfection

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 0)

Supprimé

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)

Echec de la mise à jour

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 15)

Infecté par: Trojan.Fakealert.BX

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 15)

Echec de la désinfection

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 15)

Supprimé

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)

Echec de la mise à jour

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 16)

Infecté par: Trojan.Fakealert.FB

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 16)

Echec de la désinfection

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 16)

Supprimé

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)

Echec de la mise à jour

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temporary Internet Files\Content.IE5\N6S4DPDZ\gepj[1]

Infecté par: Trojan.Vundo.DNR

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temporary Internet Files\Content.IE5\N6S4DPDZ\gepj[1]

Echec de la désinfection

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temporary Internet Files\Content.IE5\N6S4DPDZ\gepj[1]

Supprimé

C:\VundoFix Backups\mdkbgxes.dll.bad

Infecté par: Trojan.Vundo.DNR

C:\VundoFix Backups\mdkbgxes.dll.bad

Echec de la désinfection

C:\VundoFix Backups\mdkbgxes.dll.bad

Supprimé

C:\VundoFix Backups\pmkhh.dll.bad

Infecté par: DeepScan:Generic.Virtumonde.1.DCD3CD61

C:\VundoFix Backups\pmkhh.dll.bad

Echec de la désinfection

C:\VundoFix Backups\pmkhh.dll.bad

Supprimé

C:\VundoFix Backups\ssqro.dll.bad

Infecté par: DeepScan:Generic.Virtumonde.1.DCD3CD61

C:\VundoFix Backups\ssqro.dll.bad

Echec de la désinfection

C:\VundoFix Backups\ssqro.dll.bad

Supprimé

C:\VundoFix Backups\uxcxuyqj.dll.bad

Infecté par: Trojan.Vundo.DNR

C:\VundoFix Backups\uxcxuyqj.dll.bad

Echec de la désinfection

C:\VundoFix Backups\uxcxuyqj.dll.bad

Supprimé

C:\VundoFix Backups\xopxqbhi.dll.bad

Infecté par: Trojan.Vundo.DNR

C:\VundoFix Backups\xopxqbhi.dll.bad

Echec de la désinfection

C:\VundoFix Backups\xopxqbhi.dll.bad

Supprimé

C:\WINDOWS\system32\avjvstwu.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\avjvstwu.dll

Echec de la désinfection

C:\WINDOWS\system32\avjvstwu.dll

Supprimé

C:\WINDOWS\system32\cnkfuutu.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\cnkfuutu.dll

Echec de la désinfection

C:\WINDOWS\system32\cnkfuutu.dll

Supprimé

C:\WINDOWS\system32\cojalghu.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\cojalghu.dll

Echec de la désinfection

C:\WINDOWS\system32\cojalghu.dll

Supprimé

C:\WINDOWS\system32\geebb.dll

Détecté avec: Adware.Vundo.AU

C:\WINDOWS\system32\geebb.dll

Echec de la désinfection

C:\WINDOWS\system32\geebb.dll

Supprimé

C:\WINDOWS\system32\geeda.dll

Détecté avec: Adware.Vundo.AU

C:\WINDOWS\system32\geeda.dll

Echec de la désinfection

C:\WINDOWS\system32\geeda.dll

Supprimé

C:\WINDOWS\system32\kkmrqmgc.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\kkmrqmgc.dll

Echec de la désinfection

C:\WINDOWS\system32\kkmrqmgc.dll

Supprimé

C:\WINDOWS\system32\mljge.dll

Infecté par: Trojan.Vundo.DNO

C:\WINDOWS\system32\mljge.dll

Echec de la désinfection

C:\WINDOWS\system32\mljge.dll

Supprimé

C:\WINDOWS\system32\mlljg.dll

Détecté avec: Adware.Vundo.AU

C:\WINDOWS\system32\mlljg.dll

Echec de la désinfection

C:\WINDOWS\system32\mlljg.dll

Supprimé

C:\WINDOWS\system32\mllji.dll

Infecté par: Trojan.Vundo.DNO

C:\WINDOWS\system32\mllji.dll

Echec de la désinfection

C:\WINDOWS\system32\mllji.dll

Echec de la suppression

C:\WINDOWS\system32\ngmonkfe.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\ngmonkfe.dll

Echec de la désinfection

C:\WINDOWS\system32\ngmonkfe.dll

Supprimé

C:\WINDOWS\system32\ovypcabi.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\ovypcabi.dll

Echec de la désinfection

C:\WINDOWS\system32\ovypcabi.dll

Supprimé

C:\WINDOWS\system32\pmnlj.dll

Détecté avec: Adware.Vundo.AU

C:\WINDOWS\system32\pmnlj.dll

Echec de la désinfection

C:\WINDOWS\system32\pmnlj.dll

Supprimé

C:\WINDOWS\system32\ubodmbgx.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\ubodmbgx.dll

Echec de la désinfection

C:\WINDOWS\system32\ubodmbgx.dll

Supprimé

C:\WINDOWS\system32\vogcbyqt.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\vogcbyqt.dll

Echec de la désinfection

C:\WINDOWS\system32\vogcbyqt.dll

Supprimé

C:\WINDOWS\system32\wrsukdbp.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\wrsukdbp.dll

Echec de la désinfection

C:\WINDOWS\system32\wrsukdbp.dll

Supprimé

C:\WINDOWS\system32\xmdbdvgq.dll

Infecté par: Trojan.Vundo.DNP

C:\WINDOWS\system32\xmdbdvgq.dll

Supprimé

Merci de ton aide
Configuration: Windows XP
Firefox 2.0.0.7

18 réponses

  1. Contributeur sécurité
    bonsoir,

    pas mal :)

    peux tu reposter un nouveau rapport hijackthis stp

    0
    1. Bonjour,

      Voici mon nouveau rapport hijakthis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:53:02, on 14/10/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16544)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\system32\RunDLL32.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\PROGRA~1\INCRED~1\bin\IMApp.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\Program Files\Logitech\SetPoint\KEM.exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
      C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      C:\WINDOWS\system32\SearchProtocolHost.exe
      C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {080B98D0-2D30-4D17-A435-DFC5002A25B9} - (no file)
      O2 - BHO: (no name) - {20B70D8A-A71A-404E-88F8-AC47426F004A} - (no file)
      O2 - BHO: (no name) - {330D348A-0201-4935-8823-25F5D6D237BA} - (no file)
      O2 - BHO: (no name) - {36D2931D-6607-4674-A1F0-ADCF5B49B880} - (no file)
      O2 - BHO: (no name) - {4C7A882F-BA53-474B-B73A-159CDB5EDB01} - (no file)
      O2 - BHO: (no name) - {4D711114-978F-40EB-884A-3A30FBDADD79} - (no file)
      O2 - BHO: (no name) - {4EECA7FC-AC15-43D1-B499-5805428D4AD7} - (no file)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: (no name) - {5B85E697-A87C-4BA9-896C-93B8A58B7180} - C:\WINDOWS\system32\mllji.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {7D4450AB-A000-426E-B923-45B3003D92B9} - (no file)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: (no name) - {8A879199-9F43-4F90-AD1C-A642E5704E28} - C:\WINDOWS\system32\mljgd.dll (file missing)
      O2 - BHO: (no name) - {8EEF3E73-E004-4B21-B966-3E0D455C1656} - (no file)
      O2 - BHO: (no name) - {8F545755-1512-4C73-B539-CDAD49C31CE7} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {961E3A9E-F964-4583-8A4E-4FFB67C734F0} - (no file)
      O2 - BHO: (no name) - {966B5B0C-B38E-404D-8F7B-58870F164DD8} - (no file)
      O2 - BHO: (no name) - {9673FC4C-F20E-4F8F-9B66-3B8C60008089} - (no file)
      O2 - BHO: (no name) - {9AF31604-F5D0-4D3F-AC62-450734D230BE} - (no file)
      O2 - BHO: (no name) - {ADED34D6-3316-4A3A-8B25-25BDE5A6A867} - (no file)
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
      O2 - BHO: (no name) - {B30CA938-866C-4C78-B354-F38B726C1C20} - (no file)
      O2 - BHO: (no name) - {B63AF71A-ABDB-4E65-9A5E-C31995151FF8} - (no file)
      O2 - BHO: (no name) - {BB0E6747-7324-478E-9E51-4A16AD6604ED} - (no file)
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: (no name) - {BF942B28-B5B8-4910-A9AB-D64CC44A99F2} - (no file)
      O2 - BHO: (no name) - {D5C23C31-3C9E-44BA-A62C-59B0DDAA58E8} - (no file)
      O2 - BHO: (no name) - {D7E8DC20-29B3-435B-B949-7EF93740EEBA} - (no file)
      O2 - BHO: (no name) - {E7E890F0-6C73-4A50-8D1D-0AEDDD90A2CA} - (no file)
      O2 - BHO: (no name) - {F619794D-B14A-42F4-89BB-25EB2A6F0A99} - C:\WINDOWS\system32\pmkhi.dll (file missing)
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
      O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
      O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\epctcsxj.dll",sitypnow
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
      O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
      O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
      0
      1. Contributeur sécurité
        bonjour

        tu as 2 sujets pour le même problème, je t'ai d'ailleurs répondu sur les 2
        je préfèrerais continuer sur celui ci

        es tu encore là ?

        0
        1. Oui, je suis toujours là, mais je ne sais pas trop comme ça marche le forum de "comment ça marche", j'ai du faire une erreur.
          0
          1. Contributeur sécurité
            OK

            alors si tu es toujours là, je regarde les rapports, et je reviens
            0
            1. Contributeur sécurité
              on continue sur celui ci de post.

              * désactive le résident de spybot
              clic droit sur l'icone (à côté de l'horloge) du résident, puis quitter le résident.

              ensuite

              * Relance Vundofix
              * Ne clique pas sur "Scan for a vundo"
              * Clique droit au milieu de la fenêtre
              * Clique sur Add more files ?
              * Copie/colle le fichier ci-dessous :

              C:\WINDOWS\system32\mllji.dll

              * Clique sur Add files
              * Ensuite clique sur Close Windows
              * Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaitre dans la fenêtre principale)
              * Si l'outils demande un redémarrage, accepte
              * Poste le rapport Vundofix

              puis

              * lance hijackthis puis coche ces lignes :

              O2 - BHO: (no name) - {080B98D0-2D30-4D17-A435-DFC5002A25B9} - (no file)
              O2 - BHO: (no name) - {20B70D8A-A71A-404E-88F8-AC47426F004A} - (no file)
              O2 - BHO: (no name) - {330D348A-0201-4935-8823-25F5D6D237BA} - (no file)
              O2 - BHO: (no name) - {36D2931D-6607-4674-A1F0-ADCF5B49B880} - (no file)
              O2 - BHO: (no name) - {4C7A882F-BA53-474B-B73A-159CDB5EDB01} - (no file)
              O2 - BHO: (no name) - {4D711114-978F-40EB-884A-3A30FBDADD79} - (no file)
              O2 - BHO: (no name) - {4EECA7FC-AC15-43D1-B499-5805428D4AD7} - (no file)
              O2 - BHO: (no name) - {5B85E697-A87C-4BA9-896C-93B8A58B7180} - C:\WINDOWS\system32\mllji.dll
              O2 - BHO: (no name) - {7D4450AB-A000-426E-B923-45B3003D92B9} - (no file)
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: (no name) - {8A879199-9F43-4F90-AD1C-A642E5704E28} - C:\WINDOWS\system32\mljgd.dll (file missing)
              O2 - BHO: (no name) - {8EEF3E73-E004-4B21-B966-3E0D455C1656} - (no file)
              O2 - BHO: (no name) - {8F545755-1512-4C73-B539-CDAD49C31CE7} - (no file)
              O2 - BHO: (no name) - {961E3A9E-F964-4583-8A4E-4FFB67C734F0} - (no file)
              O2 - BHO: (no name) - {966B5B0C-B38E-404D-8F7B-58870F164DD8} - (no file)
              O2 - BHO: (no name) - {9673FC4C-F20E-4F8F-9B66-3B8C60008089} - (no file)
              O2 - BHO: (no name) - {9AF31604-F5D0-4D3F-AC62-450734D230BE} - (no file)
              O2 - BHO: (no name) - {ADED34D6-3316-4A3A-8B25-25BDE5A6A867} - (no file)
              O2 - BHO: (no name) - {B30CA938-866C-4C78-B354-F38B726C1C20} - (no file)
              O2 - BHO: (no name) - {B63AF71A-ABDB-4E65-9A5E-C31995151FF8} - (no file)
              O2 - BHO: (no name) - {BB0E6747-7324-478E-9E51-4A16AD6604ED} - (no file)
              O2 - BHO: (no name) - {BF942B28-B5B8-4910-A9AB-D64CC44A99F2} - (no file)
              O2 - BHO: (no name) - {D5C23C31-3C9E-44BA-A62C-59B0DDAA58E8} - (no file)
              O2 - BHO: (no name) - {D7E8DC20-29B3-435B-B949-7EF93740EEBA} - (no file)
              O2 - BHO: (no name) - {E7E890F0-6C73-4A50-8D1D-0AEDDD90A2CA} - (no file)
              O2 - BHO: (no name) - {F619794D-B14A-42F4-89BB-25EB2A6F0A99} - C:\WINDOWS\system32\pmkhi.dll (file missing)
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\epctcsxj.dll",sitypnow
              O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
              O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

              * toutes applications fermées et hors connexion, clique sur "fix checked"

              Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.
              http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

              double-clique sur OTMoveIt.exe pour le lancer.
              copie la ligne qui se trouve en citation ci-dessous,
              et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
              C:\WINDOWS\system32\epctcsxj.dll


              clique sur MoveIt! pour lancer la suppression.
              le résultat apparaitra dans le cadre Results.
              clique sur Exit pour fermer.
              poste le rapport situé dans C:\\\_OTMoveIt\MovedFiles.

              il te sera peut-être demander de redémarrer le pc pour achever la suppression.
              si c'est le cas accepte par Yes.

              reviens avec le rapport vundo, otmoveit, et un nouveau rapport hijackthis

              0
              1. Bonsoir,

                J'ai fait en partie ce que tu m'as demandé. Mon 1er pb est que je ne trouve pas la ligne

                O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\epctcsxj.dll",sitypnow

                Mon 2ème pb est que sur OTMovelt je ne sais pas où trouver

                C:\\\_OTMoveIt\MovedFiles.

                Help
                0
                1. Contributeur sécurité
                  bonsoir,

                  laisse tomber la ligne que tu ne trouves pas

                  pour OTMoveIt, normalement tu devrais trouver le rapport
                  dans C, puis dans le dossier
                  C:\_OTMoveIt\MovedFiles.

                  0
                  1. J'ai recommencé en cliquant sur OTMoveIt.exe. J'ai collé dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved. C:\WINDOWS\system32\epctcsxj.dll
                    J'ai cliqué sur Movelt! Le résultat apparut dans Result est

                    File/Folder C:\WINDOWS\system32\epctcsxj.dll not found.

                    Created on 10/17/2007 07:50:33

                    et j'ai le msg "cannot create file C:\_OTMoveIt\MovedFiles\10172007_075448.log"

                    Est-ce que cela a un rapport au fait que je ne le trouve pas ?

                    A+
                    0
                    1. Contributeur sécurité
                      bonjour,

                      ok, c'est bon cela me suffit pour l'instant

                      poste les rapports vundo et hijackthis stp
                      0
                      1. Voilà mes 2 rapports

                        VundoFix V6.5.9

                        Checking Java version...

                        Java version is 1.5.0.10

                        Java version is 1.5.0.11

                        Scan started at 07:56:10 03/10/2007

                        Listing files found while scanning....

                        C:\windows\system32\hhkmp.bak1
                        C:\windows\system32\hhkmp.bak2
                        C:\windows\system32\hhkmp.ini
                        C:\windows\system32\jqyuxcxu.ini
                        C:\WINDOWS\system32\mdkbgxes.dll
                        C:\windows\system32\orqss.bak1
                        C:\windows\system32\orqss.bak2
                        C:\windows\system32\orqss.ini
                        C:\windows\system32\pmkhh.dll
                        C:\WINDOWS\system32\sexgbkdm.ini
                        C:\windows\system32\ssqro.dll
                        C:\windows\system32\uxcxuyqj.dll

                        Beginning removal...

                        Beginning removal...

                        Attempting to delete C:\windows\system32\hhkmp.bak1
                        C:\windows\system32\hhkmp.bak1 Has been deleted!

                        Attempting to delete C:\windows\system32\hhkmp.bak2
                        C:\windows\system32\hhkmp.bak2 Has been deleted!

                        Attempting to delete C:\windows\system32\hhkmp.ini
                        C:\windows\system32\hhkmp.ini Has been deleted!

                        Attempting to delete C:\windows\system32\jqyuxcxu.ini
                        C:\windows\system32\jqyuxcxu.ini Has been deleted!

                        Attempting to delete C:\WINDOWS\system32\mdkbgxes.dll
                        C:\WINDOWS\system32\mdkbgxes.dll Could not be deleted.

                        Attempting to delete C:\windows\system32\orqss.bak1
                        C:\windows\system32\orqss.bak1 Has been deleted!

                        Attempting to delete C:\windows\system32\orqss.bak2
                        C:\windows\system32\orqss.bak2 Has been deleted!

                        Attempting to delete C:\windows\system32\orqss.ini
                        C:\windows\system32\orqss.ini Has been deleted!

                        Attempting to delete C:\windows\system32\pmkhh.dll
                        C:\windows\system32\pmkhh.dll Has been deleted!

                        Attempting to delete C:\WINDOWS\system32\sexgbkdm.ini
                        C:\WINDOWS\system32\sexgbkdm.ini Has been deleted!

                        Attempting to delete C:\windows\system32\ssqro.dll
                        C:\windows\system32\ssqro.dll Has been deleted!

                        Attempting to delete C:\windows\system32\uxcxuyqj.dll
                        C:\windows\system32\uxcxuyqj.dll Has been deleted!

                        Performing Repairs to the registry.
                        Done!

                        VundoFix V6.5.9

                        Checking Java version...

                        Java version is 1.5.0.10

                        Java version is 1.5.0.11

                        Scan started at 08:05:05 03/10/2007

                        Listing files found while scanning....

                        No infected files were found.

                        VundoFix V6.5.9

                        Checking Java version...

                        Java version is 1.5.0.10

                        Java version is 1.5.0.11

                        Scan started at 08:29:27 12/10/2007

                        Listing files found while scanning....

                        C:\WINDOWS\system32\carvvpam.dll
                        C:\windows\system32\ihbqxpox.ini
                        C:\WINDOWS\system32\mapvvrac.ini
                        C:\windows\system32\xopxqbhi.dll

                        Beginning removal...

                        Attempting to delete C:\WINDOWS\system32\carvvpam.dll
                        C:\WINDOWS\system32\carvvpam.dll Could not be deleted.

                        Attempting to delete C:\windows\system32\ihbqxpox.ini
                        C:\windows\system32\ihbqxpox.ini Has been deleted!

                        Attempting to delete C:\WINDOWS\system32\mapvvrac.ini
                        C:\WINDOWS\system32\mapvvrac.ini Has been deleted!

                        Attempting to delete C:\windows\system32\xopxqbhi.dll
                        C:\windows\system32\xopxqbhi.dll Has been deleted!

                        Performing Repairs to the registry.
                        Done!

                        VundoFix V6.5.9

                        Checking Java version...

                        Java version is 1.5.0.10

                        Java version is 1.5.0.11

                        Scan started at 08:33:41 12/10/2007

                        Listing files found while scanning....

                        No infected files were found.

                        Beginning removal...

                        VundoFix V6.5.9

                        Checking Java version...

                        Java version is 1.5.0.10

                        Java version is 1.5.0.11

                        Scan started at 14:24:00 12/10/2007

                        Listing files found while scanning....

                        C:\WINDOWS\system32\akujogan.dll
                        C:\windows\system32\mswstr10.dll
                        C:\WINDOWS\system32\nagojuka.ini

                        Beginning removal...

                        Attempting to delete C:\WINDOWS\system32\akujogan.dll
                        C:\WINDOWS\system32\akujogan.dll Could not be deleted.

                        Attempting to delete C:\windows\system32\mswstr10.dll
                        C:\windows\system32\mswstr10.dll Has been deleted!

                        Attempting to delete C:\WINDOWS\system32\nagojuka.ini
                        C:\WINDOWS\system32\nagojuka.ini Has been deleted!

                        Performing Repairs to the registry.
                        Done!

                        Beginning removal...

                        Attempting to delete C:\WINDOWS\system32\akujogan.dll
                        C:\WINDOWS\system32\akujogan.dll Has been deleted!

                        Attempting to delete C:\windows\system32\mswstr10.dll
                        C:\windows\system32\mswstr10.dll Has been deleted!

                        Performing Repairs to the registry.
                        Done!

                        Beginning removal...

                        Attempting to delete C:\WINDOWS\system32\mdkbgxes.dll
                        C:\WINDOWS\system32\mdkbgxes.dll Has been deleted!

                        Performing Repairs to the registry.
                        Done!

                        Beginning removal...

                        Attempting to delete C:\WINDOWS\system32\mllji.dll
                        C:\WINDOWS\system32\mllji.dll Has been deleted!

                        Performing Repairs to the registry.
                        Done!

                        VundoFix V6.5.9

                        Checking Java version...

                        Java version is 1.5.0.10

                        Java version is 1.5.0.11

                        Scan started at 18:41:59 17/10/2007

                        Listing files found while scanning....

                        No infected files were found.

                        Beginning removal...

                        VundoFix V6.5.9

                        Checking Java version...

                        Java version is 1.5.0.10

                        Java version is 1.5.0.11

                        Scan started at 18:46:12 17/10/2007

                        Listing files found while scanning....

                        No infected files were found.

                        Beginning removal...

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 19:08:58, on 17/10/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                        C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\SearchIndexer.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\wscntfy.exe
                        C:\WINDOWS\system32\RunDLL32.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                        C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                        C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                        C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Program Files\Logitech\SetPoint\KEM.exe
                        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                        C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
                        C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                        C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
                        C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                        C:\WINDOWS\system32\SearchProtocolHost.exe
                        C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O2 - BHO: (no name) - {D6ADA9A0-6A5E-48BA-BA3D-2DA2C51F1B57} - C:\WINDOWS\system32\mllji.dll (file missing)
                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                        O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                        O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                        O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                        O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                        O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                        O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
                        O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
                        O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                        O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                        O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
                        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
                        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                        O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
                        O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                        O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                        O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                        0
                        1. Contributeur sécurité
                          bonsoir,

                          * lance hijackthis puis coche et fixe cette ligne :

                          O2 - BHO: (no name) - {D6ADA9A0-6A5E-48BA-BA3D-2DA2C51F1B57} - C:\WINDOWS\system32\mllji.dll (file missing)

                          puis

                          * Fait un scan antivirus en ligne Panda et copie colle le résultat ici
                          https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                          (avec Internet Explorer et désactive ton Antivirus pendant le scan)

                          * tuto en image
                          http://pageperso.aol.fr/loraline60/panda_scan.htm

                          0
                          1. Voici mon rapport Panda mais je n'ai pas exactement trouvé activescan, mais totalscan. Je ne pense pas qu'il y ait une grande différence.

                            ;***********************************************************************************************************************************************************************************
                            ANALYSIS: 2007-10-18 20:59:11
                            PROTECTIONS: 1
                            MALWARE: 10
                            SUSPECTS: 0
                            ;***********************************************************************************************************************************************************************************
                            PROTECTIONS
                            Description Version Active Updated
                            ;===================================================================================================================================================================================
                            Kaspersky Anti-Virus 7.0.0.123 No Yes
                            ;===================================================================================================================================================================================
                            MALWARE
                            Id Description Type Active Severity Disinfectable Disinfected Location
                            ;===================================================================================================================================================================================
                            00032731 application/mywebsearch HackTools No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
                            00032731 application/mywebsearch HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44cf-8957-5838F569A31D}
                            00032731 application/mywebsearch HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
                            00032731 application/mywebsearch HackTools No 0 Yes No hkey_classes_root\clsid\{9afb8248-617f-460d-9366-d71cdeda3179}
                            00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@doubleclick[1].txt
                            00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@atdmt[1].txt
                            00139535 Application/Processor HackTools No 0 Yes No C:\WINDOWS\system32\Process.exe
                            00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@xiti[1].txt
                            00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Application Data\Mozilla\Firefox\Profiles\s59lfeoj.default\cookies.txt[.xiti.com/]
                            00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@serving-sys[2].txt
                            00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@bs.serving-sys[2].txt
                            00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@weborama[2].txt
                            00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@advertising[2].txt
                            00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@smartadserver[2].txt
                            ;===================================================================================================================================================================================
                            SUSPECTS
                            Location
                            ;===================================================================================================================================================================================
                            ;===================================================================================================================================================================================

                            Merci
                            0
                            1. Contributeur sécurité
                              bonsoir

                              non c'est pas vraiment pareil, la durée du scan n'est pas la même non +
                              depuis le lien que je t'ai donné, tu arrives sur active scan, non sur total scan
                              0
                              1. Par contre, j'ai viré l'anti virus Kaspersky que j'avais (Démo d'1 mois) avec lequel j'avais l'impression d'avoir bp de msg d'infections divers et qui me bloquait. J'ai réinstallé Avast. J'ai refais un scan avec CCleaner, Spybot, AdAware. Je te joins mon nouveau rapport Hijackthis. Apparemment, je n'ai plus de problème avec Virtumonde qui n'apparaît plus nulle part.

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 14:04:11, on 19/10/2007
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\SearchIndexer.exe
                                C:\WINDOWS\system32\RunDLL32.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                                C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                                C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                                C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Program Files\Messenger\msmsgs.exe
                                C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                C:\Program Files\Logitech\SetPoint\KEM.exe
                                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
                                C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                                C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                                C:\WINDOWS\system32\SearchProtocolHost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                C:\WINDOWS\system32\HPZipm12.exe

                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                                O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                                O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                                O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                                O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
                                O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
                                O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
                                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
                                O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                                0
                                1. Contributeur sécurité
                                  bonjour

                                  bon une bonne chose. Tout est ok maintenant côté infectieux, par contre pour ton message je ne sais pas du tout. Tu devrais poser la question sur le forum windows, tu aurais certainement plus de réponses.

                                  * Tu peux supprimer tous les logiciels que nous avons utilisés

                                  * démarrer-----------panneau de configuration------------système----------
                                  onglet Restauration système-----------coche la case (Désactiver la restauration système)--------------
                                  redémarre l'ordinateur
                                  réactive la ensuite

                                  * Pour améliorer la sécurité de ton PC prend quelques instants pour lire

                                  CECI

                                  * Dénonce ton infection pour faire condamner les auteurs.
                                  Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection :

                                  - Voir les règles du forum : https://malwarecomplaints.info/
                                  - Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
                                  Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
                                  Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

                                  Tu as alors sous forme de liste un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).
                                  La tienne = ******

                                  ---> https://malwarecomplaints.info/

                                  Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections
                                  conforme au règle du forum (age, ville, département etc..)

                                  Indique aussi le nom du Forum qui t'a aidé, CommentCaMarche

                                  0
                                  1. OK et encore merci pour ton aide et ta patience.
                                    0
                                    1. Contributeur sécurité
                                      de rien ce fût avec plaisir
                                      0