Virtumonde/vundo quoi faire??

jojo32100 Messages postés 14 Statut Membre -  
g!rly Messages postés 18462 Statut Contributeur -
Bonjour,
J'ai essayé de supprimer ce virus qui m'enerve enormément!!Voici le rapport de hijackthis!!Est -il parti ce virus??
Merci de votre réponse

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:04:06, on 06/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
F:\Azureus\Azureus.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\Sanner\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [780c125a] rundll32.exe "C:\WINDOWS\system32\atauimfq.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe

24 réponses

jojo32100 Messages postés 14 Statut Membre
 
BitDefender Online Scanner

Scan report generated at: Fri, Dec 07, 2007 - 00:16:12

Scan path: A:\;C:\;D:\;E:\;F:\;G:\;H:\;I:\;

Statistics

Time
00:29:13

Files
142061

Folders
4321

Boot Sectors
5

Archives
884

Packed Files
5492

Results

Identified Viruses
1

Infected Files
10

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
10

Engines Info

Virus Definitions
880592

Engine build
AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

Scan plugins
14

Archive plugins
38

Unpack plugins
7

E-mail plugins
6

System plugins
1

Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions

Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes

Scanned File
Status

C:\qoobox\Quarantine\C\WINDOWS\system32\atauimfq.dll.vir
Infected with: Trojan.Vundo.DRQ

C:\qoobox\Quarantine\C\WINDOWS\system32\atauimfq.dll.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\atauimfq.dll.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\bxbbxulq.dll.vir
Infected with: Trojan.Vundo.DRQ

C:\qoobox\Quarantine\C\WINDOWS\system32\bxbbxulq.dll.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\bxbbxulq.dll.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\mmbysqag.dll.vir
Infected with: Trojan.Vundo.DRQ

C:\qoobox\Quarantine\C\WINDOWS\system32\mmbysqag.dll.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\mmbysqag.dll.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\nwtytojh.dll.vir
Infected with: Trojan.Vundo.DRQ

C:\qoobox\Quarantine\C\WINDOWS\system32\nwtytojh.dll.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\nwtytojh.dll.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\xusmtlwi.dll.vir
Infected with: Trojan.Vundo.DRQ

C:\qoobox\Quarantine\C\WINDOWS\system32\xusmtlwi.dll.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\xusmtlwi.dll.vir
Deleted

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000037.dll
Infected with: Trojan.Vundo.DRQ

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000037.dll
Disinfection failed

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000037.dll
Deleted

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000039.dll
Infected with: Trojan.Vundo.DRQ

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000039.dll
Disinfection failed

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000039.dll
Deleted

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000045.dll
Infected with: Trojan.Vundo.DRQ

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000045.dll
Disinfection failed

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000045.dll
Deleted

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000046.dll
Infected with: Trojan.Vundo.DRQ

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000046.dll
Disinfection failed

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000046.dll
Deleted

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000053.dll
Infected with: Trojan.Vundo.DRQ

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000053.dll
Disinfection failed

C:\System Volume Information\_restore{3F943C36-4E94-4C62-AC7C-5B14862F9522}\RP2\A0000053.dll
Deleted

Ca a l'air bon la non????
0
g!rly Messages postés 18462 Statut Contributeur 406
 
salut jojo,

Désactive ta restauration système:
pour cela :
Click droit sur poste de travail, dans l´arborescence sur propriétés;
dans la nouvelle fenettre click sur l´onglet restauration système;
coche la case désactiver la restauration systèm et applique.
puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
dans la nouvelle fenettre click sur l´onglet restauration systèm
décoche la case désactiver la restauration systèm et applique.

comment va ton pc maintenant?

@+
0
jojo32100
 
Vraiment merci beaucoup pour ton aide et ta persévérance avec moi qui ne gére pas trop niveau pc!!!Je sais pas comment te remercier!!!!Mon pc tourne comme une montre, plus aucune fenetre itntempestive!!!Tout seul j'aurais amené mon pc a formater!!!
Ce forum est vraiment sympa pour l'aide!!
Encore merci
Envoie moi la facture!!!!:):):)
Merci beaucoup bonne continuation
0
g!rly Messages postés 18462 Statut Contributeur 406
 
salut jojo

bon et bien j´suis bien contente pour toi;-)

repost un dernier hijack this stp

je doit encore te donner quelques trucs a faire

@+
0