J'ai déjà poster un message hier, et eu une réponsse de Darckiller. Mais en vein, je n'arrive pas à décontaminé mon PC portable.
Tout à commencer avec l'attaque de TratBHO sur Avast il y a deux semaines.
Ensuite, je me suis renseigner sur ce forum et j'ai éffectuer plusieurs manipulations qui n'ont pas marchées. J'ai changer Avast pour Antivir, mais celui-ci me signale des fichiers menacés dans le systeme32 à chaque démarage. J'ai beau supprimer ces fichiers, ils reviennent sans cesse. Les messages d'erreur ne cesse de m'avertir sur les meme fichiers lors du démarage de Windows. Je suis donc obliger de désactiver Antivir pour être tranquil. En effet, je travail en permanence sur mon ordinateur, et je ne peut m'en séparer.
Cerait-ce possible d'avoir quelques conseils qui me permettrais de résoudre définitivement ces problèmes?
je poste en meme temps des rapports que j'ai effectués avec différents logiciel:
Dans l'ordre: Totalscan puis Antivir.
Scanning for 1004794 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: SYSTEM
Computer name: XAVIER
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: mardi 8 janvier 2008 09:32
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'searchfilterhost.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'SPUVolumeWatcher.exe' - '1' Module(s) have been scanned
Scan process 'ONENOTEM.EXE' - '1' Module(s) have been scanned
Scan process 'WindowsSearch.exe' - '1' Module(s) have been scanned
Scan process 'OSD.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr .exe' - '1' Module(s) have been scanned
Scan process 'MouseAp.exe' - '1' Module(s) have been scanned
Scan process 'Magickey.exe' - '1' Module(s) have been scanned
Scan process 'ApntEx.exe' - '1' Module(s) have been scanned
Scan process 'TeaTimer .exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr .exe' - '1' Module(s) have been scanned
Scan process 'Apoint .exe' - '1' Module(s) have been scanned
Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe'
Scan process 'atiptaxx .exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'CeEKey .exe' - '1' Module(s) have been scanned
Scan process 'tfswctrl .exe' - '1' Module(s) have been scanned
Scan process 'agrsmmsg.exe' - '1' Module(s) have been scanned
Scan process 'Apoint.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\Apoint2K\Apoint.exe'
Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe'
Scan process 'ElkCtrl .exe' - '1' Module(s) have been scanned
Scan process 'CameraAssistant .exe' - '1' Module(s) have been scanned
Scan process 'CeEKey.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe'
Scan process 'tfswctrl.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\WINDOWS\system32\dla\tfswctrl.exe'
Scan process 'Ltmoh .exe' - '1' Module(s) have been scanned
Scan process 'hpgs2wnf.exe' - '1' Module(s) have been scanned
Scan process 'LVCOMSX .EXE' - '1' Module(s) have been scanned
Scan process 'CameraAssistant.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\Logitech\Video\CameraAssistant.exe'
Scan process 'PadExe .exe' - '1' Module(s) have been scanned
Scan process 'ElkCtrl.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\WINDOWS\system32\ElkCtrl.exe'
Scan process 'Ltmoh.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\ltmoh\Ltmoh.exe'
Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
Module is infected -> 'C:\WINDOWS\system32\LVCOMSX.EXE'
Scan process 'hpgs2wnd .exe' - '1' Module(s) have been scanned
Scan process 'SmoothView .exe' - '1' Module(s) have been scanned
Scan process 'PadExe.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe'
Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
Scan process 'hpgs2wnd.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe'
Scan process 'realsched .exe' - '1' Module(s) have been scanned
Scan process 'SmoothView.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe'
Scan process 'TPSBattM.exe' - '1' Module(s) have been scanned
Scan process 'TCtrlIOHook.exe' - '1' Module(s) have been scanned
Scan process 'TPTray .exe' - '1' Module(s) have been scanned
Scan process 'TFncKy.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe'
Scan process 'TvsTray .exe' - '1' Module(s) have been scanned
Scan process 'TPTray.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\TOSHIBA\TouchPad\TPTray.exe'
Scan process 'TPSMain.exe' - '1' Module(s) have been scanned
Scan process 'TvsTray.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\Program Files\TOSHIBA\Tvs\TvsTray.exe'
Scan process 'ZoomingHook.exe' - '1' Module(s) have been scanned
Scan process 'searchprotocolhost.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'PMSHost.exe' - '1' Module(s) have been scanned
Scan process 'searchindexer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sqlservr.exe' - '1' Module(s) have been scanned
Scan process 'CFSvcs.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'LVPrcSrv.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
Process 'TeaTimer.exe' has been terminated
Process 'Apoint.exe' has been terminated
Process 'atiptaxx.exe' has been terminated
Process 'CeEKey.exe' has been terminated
Process 'tfswctrl.exe' has been terminated
Process 'CameraAssistant.exe' has been terminated
Process 'ElkCtrl.exe' has been terminated
Process 'Ltmoh.exe' has been terminated
Process 'LVCOMSX.EXE' has been terminated
Process 'PadExe.exe' has been terminated
Process 'hpgs2wnd.exe' has been terminated
Process 'SmoothView.exe' has been terminated
Process 'realsched.exe' has been terminated
Process 'TPTray.exe' has been terminated
Process 'TvsTray.exe' has been terminated
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\Apoint2K\Apoint.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\WINDOWS\system32\dla\tfswctrl.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\Logitech\Video\CameraAssistant.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\WINDOWS\system32\ElkCtrl.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\ltmoh\Ltmoh.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\WINDOWS\system32\LVCOMSX.EXE
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
94 processes with 79 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
C:\WINDOWS\system32\PSDrvCheck.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\WINDOWS\system32\PSDrvCheck.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
C:\WINDOWS\system32\ljjkljj.dll
[DETECTION] Is the Trojan horse TR/Drop.Swizzor.A
[WARNING] The file could not be deleted!
C:\WINDOWS\system32\ljjkljj.dll
[DETECTION] Is the Trojan horse TR/Drop.Swizzor.A
The registry was scanned ( '46' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX6D.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX73.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX76.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX78.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX79.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX7F.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX80.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX82.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX84.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX88.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX89.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX8B.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX8E.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX92.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX93.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX94.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX95.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX97.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX99.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX9B.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX9C.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX9D.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX9E.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCX9F.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXA1.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXA3.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXA5.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXA6.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXA7.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXA8.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXA9.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXAA.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXAC.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXAF.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXB0.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXB2.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXB5.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXB6.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXB9.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXBB.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXBC.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXBE.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXBF.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXC4.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXCA.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXCD.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXD0.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temp\RCXD3.tmp
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temporary Internet Files\Content.IE5\UBSPMO4O\css4[1]
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Documents and Settings\Mesmacque\Local Settings\Temporary Internet Files\Content.IE5\VLHEO42I\ptch[1]
[DETECTION] Is the Trojan horse TR/Vundo.dvc.3
[INFO] The file was deleted!
C:\Program Files\D-Tools\daemon.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\Logitech\Video\InstallHelper.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\Toshiba\TOSHIBA Applet\HWSetup.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000046.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000048.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000049.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000050.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000051.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000052.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000053.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000054.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000055.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000056.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000057.EXE
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000058.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000059.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000060.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000061.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000062.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000063.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000064.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000065.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000066.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0000067.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001046.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001048.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001049.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001050.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001051.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001052.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001053.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001054.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001055.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001056.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001057.EXE
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001058.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001059.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001060.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001061.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001062.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001063.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001064.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001065.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001066.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001067.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001130.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001133.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001134.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001135.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001136.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001137.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001138.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001139.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001140.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001141.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001142.EXE
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001143.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001144.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001145.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001146.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001147.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001148.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001149.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001150.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001151.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001152.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001198.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001201.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001202.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001203.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001204.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001205.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001206.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001207.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001208.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001209.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001210.EXE
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001211.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001212.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001213.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001214.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001215.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001216.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001217.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001218.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001219.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001220.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001325.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001327.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001328.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001329.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001330.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001331.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001332.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001333.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001334.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001335.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001336.EXE
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001337.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001338.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001339.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001340.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001341.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001342.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001343.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001344.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001345.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP1\A0001346.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP2\A0001413.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO] The file was deleted!
C:\System Volume Information\_restore{ECB3AD12-64E1-4857-9A37-361E4DEA76A5}\RP2\A0001415.exe
[DETECTION] Is the Trojan horse TR/Vundo.DVD
[INFO]
Je continue, je viens de refaire une analyse Totalscan, il me dit qu'il n'y a plus d'infections.
J'ai refais une analyse complète avec Hijack This. Voici le rapport:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:09:24, on 09/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal