Trojan TR/Vundo.gen repéré par Antivir

Résolu
hiwatari Messages postés 22 Statut Membre -  
 Tsume -
Bonjour,

J'ai vu qu'il y avait pas mal de sujets et de solutions pour ce trojan mais je crée un topic pour vous soumettre le rapport.
Antivir le détecte et il n'y a aucun moyen pour le supprimer, je vais donc suivre votre conseil et télécharger Hijackthis et vundofix.
Je vais procéder comme indiqué dans un topic pour essayer de le supprimer et ensuite je vous enverrais mon rapport.

Voila merci de pouvoir m'aider parce que mon ordinateur souffre énormément !!! et moi je peux plus rien faire, meme pas naviguer sur le net!!
Configuration: Windows XP
Internet Explorer 6.0

36 réponses

  • 1
  • 2
Résumé de la discussion

Plusieurs solutions permettent de traiter un cheval de Troie sous Windows XP et Internet Explorer 6, avec des outils comme HijackThis, VundoFix et Malwarebytes pour identifier et supprimer les composants malveillants. Des interventions successives recommandent d'exécuter HijackThis puis de cocher les entrées suspectes et de lancer MoveIt pour supprimer les fichiers malveillants, puis d'utiliser VundoFix ou ComboFix après avoir temporairement désactivé les protections. En complément, il est conseillé de vider la quarantaine de l’antivirus, désactiver puis réactiver la restauration système pour créer un point sain, et de vérifier les rapports des outils avec VirusTotal ou Malwarebytes.

Bobot (l'IA à votre service)
  1. jorginho67 Messages postés 15447 Statut Contributeur sécurité 1 169
     
    Ok !

    Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.

    double-clique sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous, ( en gras )

    C:\WINDOWS\system32\chosupdy.dll",b

    et colle-la dans le cadre de gauche de OTMoveIt : Paste List of Files/Folders to be moved.
    tutoriel en cas de doute

    clique sur MoveIt! pour lancer la suppression.
    Le résultat apparaitra dans le cadre Results à droite.
    Clique sur Exit pour fermer.
    Un rapport sera enregistré dans C:\\_OTMoveIt\MovedFiles.(xxxxxxxx_xxxxxx.log)
    Les x sont des chiffres qui correspondent à la date et l'heure du scan.
    il te sera peut-être demander de redémarrer le pc pour achever la suppression.
    si c'est le cas accepte par Yes.
    EN CAS DE DOUTE REGARDE ce TUTO
    ------------------------------------------------------------------------------------------------------------------------------------------------
    Relance HijackThis, choisis "do a scan only"
    coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

    O2 - BHO: (no name) - {09B46D85-5E69-493A-B8D2-A9C89511479C} - C:\WINDOWS\system32\jkkll.dll (file missing)
    O2 - BHO: {ad5e1d64-3706-928b-ee74-8b10321142be} - {eb241123-01b8-47ee-b829-607346d1e5da} - C:\WINDOWS\system32\hgpgqiqn.dll (file missing)
    O4 - HKLM\..\Run: [2c487cfc] rundll32.exe "C:\WINDOWS\system32\chosupdy.dll",b
    ---> si encore présente

    tuto en images
    ---------------------------------------------------------------------------------------------------
    Il va falloir analyser un fichier suspect !

    Il se peut qu'il se trouve dans les " dossiers cachés " du systeme. Il faut donc les rendre visibles pour le scan.
    Pour afficher les dossiers et fichiers cachés:
    Panneau de configuration > Options des dossiers > onglet Affichage.
    coche Afficher les fichiers et dossiers cachés,
    décoche Masquer les extensions de fichiers connus
    décoche Masquer les fichiers protégés du Système.
    Un message de mise en garde va apparaitre. Clique sur OK pour confirmer ton choix.
    Les fichiers et dossiers cachés du système apparaitront alors dans l'explorateur Windows en transparence.
    Lorsque tu aura fini d'intervenir dans les répertoires système, fait la manip inverse pour recacher les fichiers système.

    Rend toi chez Virus Total pour analyser ce fichier.

    Clik sur parcourir
    Recherche ceci :

    C:\WINDOWS\system32\nttpfrwi.dll

    Clik send et poste le rapport ici stp
    Comment faire <<< Aide toi de ce tuto.

    refais moi un log HJT's !

    @+
    1
  2. jorginho67 Messages postés 15447 Statut Contributeur sécurité 1 169
     
    Salut !

    Alors déjà tu pourrais dire bonjour, et concernant ceci tu n'as pas essaié ce que je t'avais proposer

    tu lui as proposé ou ? pas sur ce topic, je n'ai rien vu.....
    Si tu le fais par MP, c'est pas bien.......
    se n'est pas dans la politique de la maison........
    de plus, si tu vois qu'il y a déjà quelqu'un sur la désinfection, tu peux y participer mais sur le topic, pas en cachette car je ne sais pas ce que tu lui dis de faire, ce qui peut gener à la procedure.
    Merci.
    1
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      BONJOUR jorginho67, il sait très bien ce que je lui dit puisque suite à l'ouverture d'un autre spot sur le même sujet auquel j'ai répondu et pour lequel je me suis fais remettre en place parce que je lui répondais au lieu de le retourner sur son premier sujet ,que je n'avais pas vu, et vu que pour l'instant ça tourne en rond je posais juste la question pour savoir si il avais essaié ceci http://search.atomz.com/...@+
      0
      1. hiwatari Messages postés 22 Statut Membre > jacques.gache Messages postés 34829 Statut Contributeur sécurité
         
        Pour votre information, je suis une fille et ensuite comme vous m'avez dit de ne pas continuer le nouveau tuto que j'avais créé, je suis revenue sur l'ancien et je n'ai pas essayé ce que vous m'avez proposé.
        Encore désolé d'en avoir créé un nouveau .....
        0
      2. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645 > hiwatari Messages postés 22 Statut Membre
         
        bonjour, désolé pour ce mal entendu ce n'est pas moi qui t'es dit de retourner sur ton premier envoi mais un modérateur mais que tu sois un fille ou pas sa change rien j'aurais du te refaire une proposition ici de toute façon l'ancien n'existe plus il a été sensurer j'espère que tu vas résoudre ton problème
        0
  3. jorginho67 Messages postés 15447 Statut Contributeur sécurité 1 169
     
    Salut !
    essayons de voir çà !

    IMPORTANT : Ne désactive pas la restauration système, tant que le pc n'est pas propre.
    Ne pas oublier de décrire le plus précisément possible les dysfonctionnements que rencontre le PC au fur et à mesure des interventions !
    -----------------------------------------------------------------------------------------------------------
    Télécharge HIJACKTHIS HIJACKTHIS <--- ici.
    Enregistre HJTInstall.exe sur ton bureau. Double-clique sur HJTInstall.exe pour lancer le programme
    Par défaut, il s'installera là : C:\Program Files\HijackThis\HijackThis.exe
    Accepte la license en cliquant sur le bouton "I Accept"

    Relance Hijackthis en double cliquant sur son raccourci sur le Bureau.
    Choisis l'option "Do a system scan and save a log file"
    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
    Clique sur "Edition" ->> "Sélectionner tout", puis sur "Edition" ->> Copier" pour copier tout le contenu du rapport
    Comment fixer les lignes et générer un rapport <---- voir ici
    Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

    IMPERATIF !! Avant de lancer HIJACKTHIS , il faut fermer tous les programmes ouverts, se déconnecter d' INTERNET !!

    </gras> Télécharge VundoFix.exe par Atribune sur ton Bureau.

    # Double-clique sur VundoFix.exe afin de le lancer
    Clique sur le bouton Scan for Vundo
    Lorsque le scan est terminé, clique sur le bouton Remove Vundo
    Une invite te demandera si tu veux supprimer les fichiers, clique YES
    Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
    Tu verras une invite qui t'annonce que ton PC va redémarrer; clique sur OK

    Le rapport est situé dans C:\vundofix.txt

    Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage.
    Il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".

    Télécharge virtumondebegone

    # Double clique ensuite sur VirtumundoBeGone.exe et suis les instructions.

    Une fois terminé, redémarre et poste le rapport VBG.TXT créé sur le bureau, celui de vundofix situé dans C:\vundofix.txt et un nouveau rapport HijackThis dans ta prochaine réponse.
    0
  4. hiwatari Messages postés 22 Statut Membre
     
    Merci de pouvoir m'aider !!

    Voici mon premier rapport Hijackthis :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:07:52, on 01/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\SteamKeyFr\SteamKeyFr.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [EPSON Stylus DX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [BM2f7b4f60] Rundll32.exe "C:\WINDOWS\system32\nttpfrwi.dll",s
    O4 - HKLM\..\Run: [2c487cfc] rundll32.exe "C:\WINDOWS\system32\chosupdy.dll",b
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [SteamKeyFr] "C:\Program Files\SteamKeyFr\SteamKeyFr.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
    O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9EC68E1B-7179-4D30-9CB7-D3F21A672CE5}: NameServer = 212.27.32.5,213.228.0.168
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. jorginho67 Messages postés 15447 Statut Contributeur sécurité 1 169
     
    Avant tout,

    Fais un clic droit sur hijackthis,
    choisis "renommer" marque (tu écris) : ccm.exe

    Pourquoi renommer Hijackthis ?
    Parce que certaines infections Vundo ont la particularité de se "cacher" à la
    détection de HJT proprement dite ou à son analyse .
    la modification du nom de l'exe pallie ce problème...

    Poste moi un nouveau log après avoir renommé HJT's !
    Choisis l'option "Do a system scan and save a log file"
    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
    Clique sur "Edition" ->> "Sélectionner tout", puis sur "Edition" -> Copier" pour copier tout le contenu du rapport
    0
  7. hiwatari Messages postés 22 Statut Membre
     
    J'ai un petit problème, j'ai exécuter vundofix et mon PC a redémarré (en cliquant sur ma session, ça a pris quelques secondes..) Et la mon bureau est vide, plus aucun fichier n'apparait et il y a la fenetre Vundofix avec le fichier C:\WINDOWS\system32\qebbaxv.dll et je me demande si je dois faire un scan ou le supprimer (remove vundo) ???

    Merci de m'aider , j'ai peur de planter mon PC !!
    0
  8. hiwatari Messages postés 22 Statut Membre
     
    Ah je n'ai pas vu votre réponse alors du coup je n'ai pas renommé HJT....
    0
  9. jorginho67 Messages postés 15447 Statut Contributeur sécurité 1 169
     
    (remove vundo) << clic sur remove....
    poste Le rapport qui est situé dans C:\vundofix.txt

    0
  10. hiwatari Messages postés 22 Statut Membre
     
    Alors j'ai fait ce que vous m'avez dit et lors de l'ouverture de la session il y a un message d'erreur:
    Erreur de chargement de C:\WINDOWS\sytem32\nttpfrwi Le module spécifié est introuvable
    Savez-vous ce que c'est ???

    Et voici mon rapport vundofix :

    VundoFix V6.7.10

    Checking Java version...

    Scan started at 20:15:42 01/03/2008

    Listing files found while scanning....

    C:\WINDOWS\system32\bcmegfgm.dll
    C:\WINDOWS\system32\bhsmedxf.dll
    C:\WINDOWS\system32\chosupdy.dll
    C:\WINDOWS\system32\flwasdhl.dll
    C:\WINDOWS\system32\ftreicjq.dll
    C:\WINDOWS\system32\gebbaxv.dll
    C:\WINDOWS\system32\hbygvqkn.dll
    C:\WINDOWS\system32\hgpgqiqn.dll
    C:\WINDOWS\system32\jkkll.dll
    C:\windows\system32\llkkj.ini
    C:\windows\system32\llkkj.ini2
    C:\WINDOWS\system32\mljgded.dll
    C:\WINDOWS\system32\nttpfrwi.dll
    C:\WINDOWS\system32\qftlegnu.dll
    C:\WINDOWS\system32\wryudchu.dll
    C:\WINDOWS\system32\ydpusohc.ini

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\bcmegfgm.dll
    C:\WINDOWS\system32\bcmegfgm.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\bhsmedxf.dll
    C:\WINDOWS\system32\bhsmedxf.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\chosupdy.dll
    C:\WINDOWS\system32\chosupdy.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\flwasdhl.dll
    C:\WINDOWS\system32\flwasdhl.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ftreicjq.dll
    C:\WINDOWS\system32\ftreicjq.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\gebbaxv.dll
    C:\WINDOWS\system32\gebbaxv.dll Could not be deleted.

    Attempting to delete C:\WINDOWS\system32\hbygvqkn.dll
    C:\WINDOWS\system32\hbygvqkn.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\hgpgqiqn.dll
    C:\WINDOWS\system32\hgpgqiqn.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\jkkll.dll
    C:\WINDOWS\system32\jkkll.dll Has been deleted!

    Attempting to delete C:\windows\system32\llkkj.ini
    C:\windows\system32\llkkj.ini Has been deleted!

    Attempting to delete C:\windows\system32\llkkj.ini2
    C:\windows\system32\llkkj.ini2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\mljgded.dll
    C:\WINDOWS\system32\mljgded.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\nttpfrwi.dll
    C:\WINDOWS\system32\nttpfrwi.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\qftlegnu.dll
    C:\WINDOWS\system32\qftlegnu.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\wryudchu.dll
    C:\WINDOWS\system32\wryudchu.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ydpusohc.ini
    C:\WINDOWS\system32\ydpusohc.ini Has been deleted!

    Performing Repairs to the registry.
    Done!

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\gebbaxv.dll
    C:\WINDOWS\system32\gebbaxv.dll Has been deleted!

    Performing Repairs to the registry.
    Done!
    0
  11. hiwatari Messages postés 22 Statut Membre
     
    Est-ce que quelqu'un peut m'aider s'il vous plait ??????
    Mon ordinateur est mon outil de travail .... merci de répondre !!!
    0
  12. jorginho67 Messages postés 15447 Statut Contributeur sécurité 1 169
     
    Fais un clic droit sur hijackthis,
    choisis "renommer" marque (tu écris) : ccm.exe

    Pourquoi renommer Hijackthis ?
    Parce que certaines infections Vundo ont la particularité de se "cacher" à la
    détection de HJT proprement dite ou à son analyse .
    la modification du nom de l'exe pallie ce problème...

    Poste moi un nouveau log après avoir renommé HJT's !
    Choisis l'option "Do a system scan and save a log file"
    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
    Clique sur "Edition" ->> "Sélectionner tout", puis sur "Edition" -> Copier" pour copier tout le contenu du rapport
    0
  13. hiwatari Messages postés 22 Statut Membre
     
    J'ai renommé HJT en ccm.exe et voici le rapport :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:22:12, on 01/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Eset\nod32kui.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\SteamKeyFr\SteamKeyFr.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {09B46D85-5E69-493A-B8D2-A9C89511479C} - C:\WINDOWS\system32\jkkll.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O2 - BHO: {ad5e1d64-3706-928b-ee74-8b10321142be} - {eb241123-01b8-47ee-b829-607346d1e5da} - C:\WINDOWS\system32\hgpgqiqn.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [EPSON Stylus DX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [BM2f7b4f60] Rundll32.exe "C:\WINDOWS\system32\nttpfrwi.dll",s
    O4 - HKLM\..\Run: [2c487cfc] rundll32.exe "C:\WINDOWS\system32\chosupdy.dll",b
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [SteamKeyFr] "C:\Program Files\SteamKeyFr\SteamKeyFr.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
    O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9EC68E1B-7179-4D30-9CB7-D3F21A672CE5}: NameServer = 212.27.32.5,213.228.0.168
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    0
  14. jorginho67 Messages postés 15447 Statut Contributeur sécurité 1 169
     
    Télécharge Combofix à partir d'un de ces liens :

    ComboFix bleepingcomputer
    ComboFix forospyware
    Et important, enregistre le sur le bureau.

    Si ton antivirus te signale un trojan , risktools ou quoi que ce soit, il faut choisir ignorer car c'est une erreur de detection.
    Il detecte en fait un composant de l'outil de nettoyage.

    Avant d'utiliser ComboFix :
    Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
    Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

    Une fois fait, sur ton bureau double-clic sur Combofix.exe.
    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
    Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt

    -Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
    - Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message ainsi qu'un nouvel Hijackthis...
    0
  15. hiwatari Messages postés 22 Statut Membre
     
    Voila c'est fait, ce qui est bizarre c'est que Internet est super long
    enfin sinon quand Combofix a redémarrer le PC , mes 2 antivirus se sont déclenchés donc j'ai du les désactivez, le message d'erreur que j'ai indiqué avant est apparu donc j'ai du le fermer, je ne sais pas si a changé quelque chose ds le rapport ..; Voici le log de Combofix :

    ComboFix 08-03-01.3 - Juliette 2008-03-01 21:55:30.1 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.262 [GMT 1:00]
    Endroit: C:\Documents and Settings\Juliette\Bureau\ComboFix.exe
    * Création d'un nouveau point de restauration

    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\cookies.ini
    C:\WINDOWS\system32\dhcxkkuw.ini
    C:\WINDOWS\system32\fniijabs.ini
    C:\WINDOWS\system32\jcpolduq.ini
    C:\WINDOWS\system32\jtnmggij.ini
    C:\WINDOWS\system32\mltwvtdq.ini
    C:\WINDOWS\system32\qticpipp.ini
    C:\WINDOWS\system32\ygckhiqs.dll
    C:\WINDOWS\system32\ylsgssdf.dll
    F:\MS32DLL.dll.vbs . . . . Echec de suppression

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-02-01 to 2008-03-01 ))))))))))))))))))))))))))))))))))))
    .

    2008-03-01 20:15 . 2008-03-01 20:31 <REP> d-------- C:\VundoFix Backups
    2008-03-01 20:07 . 2008-03-01 20:07 <REP> d-------- C:\Program Files\Trend Micro
    2008-03-01 20:07 . 2008-03-01 20:07 15 --a------ C:\WINDOWS\system32\2c486e72
    2008-03-01 19:31 . 2008-03-01 19:31 <REP> d-------- C:\Program Files\Avira
    2008-03-01 19:31 . 2008-03-01 19:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-02-26 12:23 . 2008-02-26 12:23 26,048 --a------ C:\WINDOWS\system32\byxywxy.dll
    2008-02-24 18:57 . 2008-02-24 18:57 90,176 --a------ C:\WINDOWS\system32\cyoihimv.dll
    2008-02-24 17:57 . 2008-02-24 17:57 90,176 --a------ C:\WINDOWS\system32\wutfntrb.dll
    2008-02-24 14:36 . 2008-02-24 14:36 <REP> d-------- C:\Program Files\Audacity
    2008-02-23 17:53 . 2008-02-28 16:49 147 --a------ C:\WINDOWS\BM2f7b4f60.xml
    2008-02-23 17:53 . 2008-03-01 19:22 21 --a------ C:\WINDOWS\pskt.ini
    2008-02-22 16:36 . 2008-02-22 16:55 <REP> d-------- C:\Documents and Settings\Juliette\Application Data\U3
    2008-02-16 03:54 . 2008-02-16 03:58 19,753,395 --a------ C:\smap.tmp0
    2008-02-16 03:54 . 2008-02-16 03:58 11,458,995 --a------ C:\smsk.tmp0
    2008-02-16 03:20 . 2008-02-16 03:20 <REP> d-------- C:\Program Files\GameTribe
    2008-02-04 21:08 . 2008-02-04 21:08 244 --ah----- C:\sqmnoopt02.sqm
    2008-02-04 21:08 . 2008-02-04 21:08 232 --ah----- C:\sqmdata02.sqm
    2008-02-02 20:39 . 2008-02-02 20:39 <REP> d-------- C:\Documents and Settings\Juliette\Application Data\Cakewalk
    2008-02-02 20:37 . 2008-02-02 20:37 <REP> d-------- C:\Program Files\Cakewalk
    2008-02-02 20:37 . 2004-05-05 01:00 180,224 --a------ C:\WINDOWS\system32\ReWire.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-02-29 04:27 --------- d-----w C:\Program Files\eMule
    2008-02-26 18:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
    2008-02-26 16:09 --------- d-----w C:\Documents and Settings\Juliette\Application Data\Azureus
    2008-02-24 12:40 --------- d-----w C:\Documents and Settings\Juliette\Application Data\LimeWire
    2008-02-23 20:05 --------- d-----w C:\Program Files\FlashGet
    2008-02-15 20:05 --------- d-----w C:\Program Files\Fichiers communs\Adobe
    2008-02-14 12:52 219,763 ----a-w C:\WINDOWS\Fonts\scolaire.zip
    2008-02-14 12:51 533,755 ----a-w C:\WINDOWS\Fonts\verchery.zip
    2008-02-10 20:07 --------- d-----w C:\Program Files\Steam
    2008-02-07 22:31 --------- d-----w C:\Program Files\ESET
    2008-01-26 21:19 32,764 ----a-w C:\WINDOWS\17PHolmes572.exe
    2008-01-07 18:29 --------- d-----w C:\Program Files\DVD Shrink
    2007-12-22 18:54 460,979 ----a-w C:\Documents and Settings\Juliette\data.bin
    2007-11-18 11:30 19,176 ----a-w C:\Documents and Settings\Juliette\Application Data\GDIPFONTCACHEV1.DAT
    .

    ------- Sigcheck -------

    de43b7f2d8b37ca03f7794bb7f3275f7 C:\WINDOWS\system32\wininet.dll
    ----a-w 1,220,096 2004-08-03 22:54:46 C:\WINDOWS\system32\wininet.dll
    -c--a-w 1,220,096 2004-08-03 22:54:46 C:\WINDOWS\system32\dllcache\wininet.dll

    6a603809f598332dbedd535bdbce313e C:\WINDOWS\system32\drivers\tcpip.sys
    -c--a-w 359,040 2004-08-03 21:14:42 C:\WINDOWS\system32\dllcache\tcpip.sys
    ----a-w 359,040 2004-08-03 21:14:42 C:\WINDOWS\system32\drivers\tcpip.sys

    90e794c5d2d368686fe71b4a0354462c C:\WINDOWS\explorer.exe
    ----a-w 1,884,672 2004-08-03 22:54:50 C:\WINDOWS\explorer.exe
    -c--a-w 1,884,672 2004-08-03 22:54:50 C:\WINDOWS\system32\dllcache\explorer.exe
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09B46D85-5E69-493A-B8D2-A9C89511479C}]
    C:\WINDOWS\system32\jkkll.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{eb241123-01b8-47ee-b829-607346d1e5da}]
    C:\WINDOWS\system32\hgpgqiqn.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:54 15360]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-20 20:36 68856]
    "SteamKeyFr"="C:\Program Files\SteamKeyFr\SteamKeyFr.exe" [2004-01-28 21:49 212992]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-11-08 22:41 949376]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
    "EPSON Stylus DX4800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.exe" [2005-02-02 05:00 98304]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
    "BM2f7b4f60"="C:\WINDOWS\system32\nttpfrwi.dll" [ ]
    "2c487cfc"="C:\WINDOWS\system32\chosupdy.dll" [ ]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-03-01 19:34 249896]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:54 15360]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=
    "C:\\Program Files\\Azureus\\Azureus.exe"=
    "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "C:\\Program Files\\Steam\\steamapps\\kilazur\\counter-strike\\hl.exe"=
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=
    "C:\\WINDOWS\\system32\\dpvsetup.exe"=
    "C:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "80:TCP"= 80:TCP:tcp azureus
    "6112:UDP"= 6112:UDP:udp azureus

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9eaed4e-e15b-11dc-b51c-0008543eb15d}]
    \Shell\AutoRun\command - F:\LaunchU3.exe -a

    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-01 22:00:21
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************
    .
    --------------------- DLLs a chargé sous des processus courants ---------------------

    PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
    -> C:\Program Files\Eset\pr_imon.dll

    PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
    -> C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\DockShellHook.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
    C:\WINDOWS\system32\devldr32.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-03-01 22:02:16 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-03-01 21:02:12
    0
    1. jorginho67 Messages postés 15447 Statut Contributeur sécurité 1 169
       
      enfin sinon quand Combofix a redémarrer le PC , mes 2 antivirus se sont déclenchés donc j'ai du les désactivez,

      c'etait bien expliqué plus haut :
      Avant d'utiliser ComboFix :
      Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
      Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.


      je regarde ça en détail....
      0
  16. hiwatari Messages postés 22 Statut Membre
     
    et le nouveau rapport d'HJT :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:04:12, on 01/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\SteamKeyFr\SteamKeyFr.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {09B46D85-5E69-493A-B8D2-A9C89511479C} - C:\WINDOWS\system32\jkkll.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O2 - BHO: {ad5e1d64-3706-928b-ee74-8b10321142be} - {eb241123-01b8-47ee-b829-607346d1e5da} - C:\WINDOWS\system32\hgpgqiqn.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [EPSON Stylus DX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [BM2f7b4f60] Rundll32.exe "C:\WINDOWS\system32\nttpfrwi.dll",s
    O4 - HKLM\..\Run: [2c487cfc] rundll32.exe "C:\WINDOWS\system32\chosupdy.dll",b
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [SteamKeyFr] "C:\Program Files\SteamKeyFr\SteamKeyFr.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
    O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9EC68E1B-7179-4D30-9CB7-D3F21A672CE5}: NameServer = 212.27.32.5,213.228.0.168
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    0
  17. hiwatari Messages postés 22 Statut Membre
     
    Que dois-je faire ensuite ??
    0
  18. hiwatari Messages postés 22 Statut Membre
     
    Désolé de vous importuner tout le temps mais le virus est éradiqué ??? Je dois exécuter VirtumundoBeGone ?
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      salut, sur ton rapport hijackthis je vois que tu utilises antivir mais une trace de nod32 aurais tu un deuxième antivirus
      0
  19. hiwatari Messages postés 22 Statut Membre
     
    Vraiment désolé de m'impatienter autant mais comme je dois travailler sur un logiciel de programmatin (eclipse) et que j'ai un devoir a faire pour mardi,j'étais un peu paniqué...
    Donc je n'écris plus rien dans l'autre topic et je vous colle ce que j'ai fait Encore pardon, surtout que votre site est génial donc excusez mon impatience..

    Bonjour,

    J'ai posté un message hier et je n'ai obtenu aucune réponse lors de mon dernier rapport avec HJT et Combofix.
    Voila j'ai exécuter vundofix et j'ai envoyé un rapport vundofix et HJT, on m'a alors recommandé d'exécuter Combofix, ce que j'ai fait mais j'avais oublié de désactiver mes 2 antivirus et mon pare-feu alors j'ai réintérer l'exécution ce matin dont voici le rapport :

    ComboFix 08-03-01.3 - Juliette 2008-03-02 10:34:12.2 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.328 [GMT 1:00]
    Endroit: C:\Documents and Settings\Juliette\Bureau\ComboFix.exe

    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\Nircmd.exe
    C:\WINDOWS\system32\cyoihimv.dll
    C:\WINDOWS\system32\wutfntrb.dll
    F:\MS32DLL.dll.vbs

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-02-02 to 2008-03-02 ))))))))))))))))))))))))))))))))))))
    .

    2008-03-01 20:15 . 2008-03-01 20:31 <REP> d-------- C:\VundoFix Backups
    2008-03-01 20:07 . 2008-03-01 20:07 <REP> d-------- C:\Program Files\Trend Micro
    2008-03-01 20:07 . 2008-03-01 20:07 15 --a------ C:\WINDOWS\system32\2c486e72
    2008-03-01 19:31 . 2008-03-01 19:31 <REP> d-------- C:\Program Files\Avira
    2008-03-01 19:31 . 2008-03-01 19:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-02-26 12:23 . 2008-02-26 12:23 26,048 --a------ C:\WINDOWS\system32\byxywxy.dll
    2008-02-23 17:53 . 2008-02-28 16:49 147 --a------ C:\WINDOWS\BM2f7b4f60.xml
    2008-02-23 17:53 . 2008-03-01 19:22 21 --a------ C:\WINDOWS\pskt.ini
    2008-02-22 16:36 . 2008-02-22 16:55 <REP> d-------- C:\Documents and Settings\Juliette\Application Data\U3
    2008-02-16 03:54 . 2008-02-16 03:58 19,753,395 --a------ C:\smap.tmp0
    2008-02-16 03:54 . 2008-02-16 03:58 11,458,995 --a------ C:\smsk.tmp0
    2008-02-16 03:20 . 2008-02-16 03:20 <REP> d-------- C:\Program Files\GameTribe
    2008-02-04 21:08 . 2008-02-04 21:08 244 --ah----- C:\sqmnoopt02.sqm
    2008-02-04 21:08 . 2008-02-04 21:08 232 --ah----- C:\sqmdata02.sqm
    2008-02-02 20:39 . 2008-02-02 20:39 <REP> d-------- C:\Documents and Settings\Juliette\Application Data\Cakewalk
    2008-02-02 20:37 . 2008-02-02 20:37 <REP> d-------- C:\Program Files\Cakewalk
    2008-02-02 20:37 . 2004-05-05 01:00 180,224 --a------ C:\WINDOWS\system32\ReWire.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-03-02 09:18 --------- d-----w C:\Program Files\ESET
    2008-02-29 04:27 --------- d-----w C:\Program Files\eMule
    2008-02-26 18:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
    2008-02-26 16:09 --------- d-----w C:\Documents and Settings\Juliette\Application Data\Azureus
    2008-02-24 12:40 --------- d-----w C:\Documents and Settings\Juliette\Application Data\LimeWire
    2008-02-23 20:05 --------- d-----w C:\Program Files\FlashGet
    2008-02-15 20:05 --------- d-----w C:\Program Files\Fichiers communs\Adobe
    2008-02-10 20:07 --------- d-----w C:\Program Files\Steam
    2008-01-07 18:29 --------- d-----w C:\Program Files\DVD Shrink
    2007-12-22 18:54 460,979 ----a-w C:\Documents and Settings\Juliette\data.bin
    2007-11-18 11:30 19,176 ----a-w C:\Documents and Settings\Juliette\Application Data\GDIPFONTCACHEV1.DAT
    .

    ------- Sigcheck -------

    de43b7f2d8b37ca03f7794bb7f3275f7 C:\WINDOWS\system32\wininet.dll
    ----a-w 1,220,096 2004-08-03 22:54:46 C:\WINDOWS\system32\wininet.dll
    -c--a-w 1,220,096 2004-08-03 22:54:46 C:\WINDOWS\system32\dllcache\wininet.dll

    6a603809f598332dbedd535bdbce313e C:\WINDOWS\system32\drivers\tcpip.sys
    -c--a-w 359,040 2004-08-03 21:14:42 C:\WINDOWS\system32\dllcache\tcpip.sys
    ----a-w 359,040 2004-08-03 21:14:42 C:\WINDOWS\system32\drivers\tcpip.sys

    90e794c5d2d368686fe71b4a0354462c C:\WINDOWS\explorer.exe
    ----a-w 1,884,672 2004-08-03 22:54:50 C:\WINDOWS\explorer.exe
    -c--a-w 1,884,672 2004-08-03 22:54:50 C:\WINDOWS\system32\dllcache\explorer.exe
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09B46D85-5E69-493A-B8D2-A9C89511479C}]
    C:\WINDOWS\system32\jkkll.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{eb241123-01b8-47ee-b829-607346d1e5da}]
    C:\WINDOWS\system32\hgpgqiqn.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:54 15360]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-20 20:36 68856]
    "SteamKeyFr"="C:\Program Files\SteamKeyFr\SteamKeyFr.exe" [2004-01-28 21:49 212992]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
    "EPSON Stylus DX4800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.exe" [2005-02-02 05:00 98304]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
    "BM2f7b4f60"="C:\WINDOWS\system32\nttpfrwi.dll" [ ]
    "2c487cfc"="C:\WINDOWS\system32\chosupdy.dll" [ ]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-03-01 19:34 249896]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:54 15360]

    C:\Documents and Settings\Juliette\Menu D‚marrer\Programmes\D‚marrage\
    Stardock ObjectDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe [2005-02-21 14:56:00 1826885]
    Y'z ToolBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-09-29 14:41:00 90112]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplicat­ions\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=
    "C:\\Program Files\\Azureus\\Azureus.exe"=
    "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "C:\\Program Files\\Steam\\steamapps\\kilazur\\counter-strike\\hl.exe"=
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=
    "C:\\WINDOWS\\system32\\dpvsetup.exe"=
    "C:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\­List]
    "80:TCP"= 80:TCP:tcp azureus
    "6112:UDP"= 6112:UDP:udp azureus

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9eaed­4e-e15b-11dc-b51c-0008543eb15d}]
    \Shell\AutoRun\command - F:\LaunchU3.exe -a

    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-02 10:35:51
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************
    .
    Temps d'accomplissement: 2008-03-02 10:36:51
    ComboFix-quarantined-files.txt 2008-03-02 09:36:43
    ComboFix2.txt 2008-03-01 21:02:16

    Ensuite j'ai exécuter virtumundobegone qui n'a rien signalé et ensuite le scan d'antivir qui m'a re détecter le virus Vundo.gen et voici le rapport :

    AntiVir PersonalEdition Classic
    Report file date: dimanche 2 mars 2008 10:41

    Scanning for 1129035 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: SYSTEM
    Computer name: PCJULIETTE

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
    ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 18:34:57
    ANTIVIR2.VDF : 7.0.2.181 1993728 Bytes 24/02/2008 18:34:57
    ANTIVIR3.VDF : 7.0.2.215 117248 Bytes 29/02/2008 18:34:57
    AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 01/03/2008 18:34:58
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVPACK32.DLL : 7.6.0.3 360488 Bytes 01/03/2008 18:34:58
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: E:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: dimanche 2 mars 2008 10:41

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'devldr32.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'mdm.exe' - '1' Module(s) have been scanned
    Scan process 'ObjectDock.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'SteamKeyFr.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'E_FATIADE.EXE' - '1' Module(s) have been scanned
    Scan process 'jusched.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    28 processes with 28 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!
    Boot sector 'E:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '23' files ).

    Starting the file scan:

    Begin scan in 'C:\'
    C:\hiberfil.sys
    [WARNING] The file could not be opened!
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\QooBox\Quarantine\catchme2008-03-01_215947.78.zip
    [0] Archive type: ZIP
    --> MS32DLL.dll.vbs
    [DETECTION] Contains detection pattern of the VBS script virus VBS/IETitle.C
    [INFO] The file was moved to '483e7ab7.qua'!
    C:\QooBox\Quarantine\C\WINDOWS\system32\cyoihimv.dll.vir
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was deleted!
    C:\QooBox\Quarantine\C\WINDOWS\system32\wutfntrb.dll.vir
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was deleted!
    C:\QooBox\Quarantine\C\WINDOWS\system32\ygckhiqs.dll.vir
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was deleted!
    C:\QooBox\Quarantine\C\WINDOWS\system32\ylsgssdf.dll.vir
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was deleted!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP101\A0019698.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7ac2.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP101\A0020698.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [WARNING] The file was ignored!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021740.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [WARNING] The file was ignored!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021747.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [WARNING] The file was ignored!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021748.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7ae6.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021749.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7af6.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021750.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b12.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021751.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b24.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021752.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b33.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021753.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '436cdfd4.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021754.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b35.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021756.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b34.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021757.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '436cdfd5.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP103\A0021758.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b36.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP104\A0021776.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '436cdfd6.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP104\A0021777.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b37.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP104\A0021919.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b3a.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP104\A0021920.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '436cdfdb.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP99\A0017565.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b5f.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP99\A0017566.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47fa7b60.qua'!
    C:\System Volume Information\_restore{6541CB06-8D60-433D-8AEA-037CED5A4059}\RP99\A0018565.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '436cdf81.qua'!
    C:\VundoFix Backups\bcmegfgm.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '48377b97.qua'!
    C:\VundoFix Backups\bhsmedxf.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '483d7b9d.qua'!
    C:\VundoFix Backups\chosupdy.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '48397b9d.qua'!
    C:\VundoFix Backups\flwasdhl.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '48417ba1.qua'!
    C:\VundoFix Backups\ftreicjq.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '483c7baa.qua'!
    C:\VundoFix Backups\hbygvqkn.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '48437b98.qua'!
    C:\VundoFix Backups\hgpgqiqn.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '483a7b9d.qua'!
    C:\VundoFix Backups\jkkll.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '48357ba2.qua'!
    C:\VundoFix Backups\nttpfrwi.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '483e7bab.qua'!
    C:\VundoFix Backups\qftlegnu.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '483e7b9d.qua'!
    C:\VundoFix Backups\wryudchu.dll.bad
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '48437baa.qua'!
    Begin scan in 'E:\'

    End of the scan: dimanche 2 mars 2008 11:21
    Used time: 40:06 min

    The scan has been done completely.

    3649 Scanning directories
    251307 Files were scanned
    37 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    4 files were deleted
    0 files were repaired
    30 files were moved to quarantine
    0 files were renamed
    2 Files cannot be scanned
    251270 Files not concerned
    1653 Archives were scanned
    5 Warnings
    1 Notes
    0
  20. hiwatari Messages postés 22 Statut Membre
     
    Et pour répondre à votre question j'avais NOD32 hier mais je l'ai supprimé alors il me reste que Antivir !!
    0
  21. ••RiverToo•• Messages postés 1098 Statut Membre 53
     
    Bonjour à vous 2

    ''enfin sinon quand Combofix a redémarrer le PC , mes 2 antivirus se sont déclenchés donc j'ai du les désactivez,''

    Donc il a 2 anti-virus !!
    hiwa si tu as Acheter nod32 garde le !!! largement plus efficasse

    Ou sinon si tu veux garde antivir il est gratuit ..

    Voila

    ••RiverToo••
    0
  • 1
  • 2