Virus Virtumonde

Fermé
mahnie Messages postés 8 Date d'inscription dimanche 11 mai 2008 Statut Membre Dernière intervention 13 mai 2008 - 11 mai 2008 à 12:06
 Utilisateur anonyme - 13 mai 2008 à 21:55
Bonjour,
Comme beaucoup, j'ai apparement ce virus (et des vers et des chevals de troies.......).
J'ai utilise spybot, et avast, mais bien sur, a part les mettre en quarantaine, ils ne font pas mieux.

Voici mon rapport Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:08:17, on 11/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Norman\Npm\bin\ELOGSVC.EXE
C:\Norman\Npm\Bin\Zanda.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\FileZilla Server\FileZilla Server.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Norman\Npm\bin\ZLH.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Norman\Npm\bin\NJEEVES.EXE
C:\Norman\Nvc\bin\nvcoas.exe
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Norman\Nvc\bin\cclaw.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Norman\npm\bin\niu.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.neuf.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\FICHIE~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: (no name) - {4C7A09B5-EE02-43B0-A02F-E76732AA5527} - C:\WINDOWS\system32\pmnnKCrO.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {C3E15DFE-D990-4C3F-9BE2-4CF4E3E007CE} - C:\WINDOWS\system32\khffgeEV.dll (file missing)
O2 - BHO: (no name) - {EC7FF04C-2505-48E5-A5FF-D834B7B5F298} - C:\WINDOWS\system32\wvUkLDWp.dll (file missing)
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\Npm\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BMbb971fa2] Rundll32.exe "C:\WINDOWS\system32\sbacamhk.dll",s
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE R…SEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: wkcalrem.LNK.disabled
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk.disabled
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk.disabled
O4 - Global Startup: Post-itÆ Software Notes Lite.lnk.disabled
O4 - Global Startup: Quantel Workstation.lnk = C:\WINDOWS\system32\QuantelWorkstation.exe
O8 - Extra context menu item: Convertir les liens sÈlectionnÈs en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.canalplay.com
O15 - Trusted Zone: *.canalplusactive.com
O15 - Trusted Zone: *.canalplay.com (HKLM)
O15 - Trusted Zone: *.canalplusactive.com (HKLM)
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - https://www.afternic.com/domains/drivecleaner.com
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097743015284
O16 - DPF: {6DB731A3-B074-4118-8B1C-32511C65D836} (FotovistaPhotoUploader.ctrFpu) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{038BCA3B-7B50-47D3-B0EF-F71EE4EC7640}: NameServer = 80.118.192.100,80.118.196.36
O17 - HKLM\System\CS1\Services\Tcpip\..\{038BCA3B-7B50-47D3-B0EF-F71EE4EC7640}: NameServer = 80.118.192.100,80.118.196.36
O20 - AppInit_DLLs: Runner.dll,Runner.dll
O20 - Winlogon Notify: khffgeEV - khffgeEV.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Norman\Npm\bin\ELOGSVC.EXE
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\Npm\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Norman ASA - C:\Norman\Npm\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
A voir également:

24 réponses

Utilisateur anonyme
12 mai 2008 à 01:05
pourquoi il m'a dit que la force soit avec toi le monsieur la-haut là.......????????????
0
Utilisateur anonyme
12 mai 2008 à 01:12
tu preferes ; que la faiblesse soit avec toi ? ^^

En plus c'est mal on est entrin de polluer le post lol (enfin vous xD)
0
mahnie Messages postés 8 Date d'inscription dimanche 11 mai 2008 Statut Membre Dernière intervention 13 mai 2008
12 mai 2008 à 01:45
salut,

J'ai fait:
-VundoFix, et il ne m'a rien trouvé, donc j'ai pas de rapport.
-VirtumondoBeGone, voici le log:

[05/12/2008, 1:02:29] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Mahnie\Bureau\VirtumundoBeGone.exe" )
[05/12/2008, 1:02:48] - Detected System Information:
[05/12/2008, 1:02:48] - Windows Version: 5.1.2600, Service Pack 2
[05/12/2008, 1:02:48] - Current Username: Mahnie (Admin)
[05/12/2008, 1:02:48] - Windows is in NORMAL mode.
[05/12/2008, 1:02:48] - Searching for Browser Helper Objects:
[05/12/2008, 1:02:48] - BHO 1: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[05/12/2008, 1:02:48] - BHO 2: {96367F29-207F-40DC-9C39-6D8E836B1AB3} ()
[05/12/2008, 1:02:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/12/2008, 1:02:48] - Checking for HKLM\...\Winlogon\Notify\pmnnKCrO
[05/12/2008, 1:02:48] - Key not found: HKLM\...\Winlogon\Notify\pmnnKCrO, continuing.
[05/12/2008, 1:02:48] - Finished Searching Browser Helper Objects
[05/12/2008, 1:02:48] - Finishing up...
[05/12/2008, 1:02:48] - Nothing found! Exiting...

-Combofix, voici le log:

ComboFix 08-05-11.1 - Mahnie 2008-05-12 1:36:08.1 - NTFSx86
Microsoft Windows XP …dition familiale 5.1.2600.2.1252.1.1036.18.457 [GMT 2:00]
Endroit: C:\Documents and Settings\Mahnie\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mahnie\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* CrÈation d'un nouveau point de restauration
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\fcadvice
C:\Program Files\fcadvice\patterns.dat
C:\Program Files\fcadvice\Uninstall.exe
C:\WINDOWS\pack.epk
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\gswgqvrn.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mnmlyigt.ini
C:\WINDOWS\system32\OrCKnnmp.ini
C:\WINDOWS\system32\OrCKnnmp.ini2
C:\WINDOWS\system32\pmnnKCrO.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\pWDLkUvw.ini
C:\WINDOWS\system32\pWDLkUvw.ini2
c:\WINDOWS\system32\zpjthwuyu.dat
c:\windows\system32\zpjthwuyu.exe
c:\WINDOWS\system32\zpjthwuyu_navps.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((((((( Fichiers crÇÇs 2008-04-11 to 2008-05-11 ))))))))))))))))))))))))))))))))))))
.

C:\ComboFix\CreateC00.bat .
2008-05-12 00:49 . 2008-05-12 00:49 <REP> d-------- C:\VundoFix Backups
2008-05-11 12:45 . 2008-05-11 12:45 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-11 12:45 . 2008-05-11 12:45 <REP> d-------- C:\Documents and Settings\Mahnie\Application Data\Malwarebytes
2008-05-11 12:45 . 2008-05-11 12:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-11 12:45 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-11 12:45 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-11 12:05 . 2008-05-11 12:05 <REP> d-------- C:\Program Files\Trend Micro
2008-05-09 15:34 . 2008-05-09 15:34 <REP> d-------- C:\Program Files\Alwil Software
2008-05-09 14:51 . 2008-05-09 14:51 2,048 --a------ C:\WINDOWS\system32\xucbhdhl.exe
2008-05-09 12:11 . 2008-05-09 12:11 2,048 --a------ C:\WINDOWS\system32\cyivgnhm.exe
2008-04-25 22:53 . 2008-05-04 13:04 443 --a------ C:\WINDOWS\wininit.ini
2008-04-21 00:55 . 2008-04-21 00:55 <REP> d-------- C:\Documents and Settings\Mahnie\Application Data\Canon
2008-04-21 00:50 . 2008-04-21 00:50 <REP> d-------- C:\Documents and Settings\Mahnie\Application Data\ZoomBrowser EX
2008-04-20 23:39 . 2008-04-20 23:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-04-20 23:37 . 2008-04-20 23:37 <REP> d-------- C:\Program Files\Fichiers communs\Canon
2008-04-20 23:37 . 2008-04-20 23:40 <REP> d-------- C:\Program Files\Canon
2008-04-20 15:35 . 2008-04-25 21:52 594 ---hs---- C:\WINDOWS\system32\oymmrnsb.ini
2008-04-20 15:30 . 2008-05-11 11:02 109,738 --a------ C:\WINDOWS\BMbb971fa2.xml
2008-04-19 23:38 . 2008-04-19 23:38 <REP> d-------- C:\Program Files\LaCieTools
2008-04-19 23:38 . 2005-10-19 08:34 15,872 --a------ C:\WINDOWS\system32\drivers\LaCieUSBFilter.sys
2008-04-19 23:38 . 2005-10-18 07:28 14,848 --a------ C:\WINDOWS\system32\drivers\LaCieFWFilter.sys
2008-04-19 23:38 . 2002-07-26 16:02 6,752 --a------ C:\UNWISE.INI
2008-04-19 23:38 . 2008-04-19 23:38 640 --a------ C:\WINDOWS\UndeviceUpd
2008-04-19 18:39 . 2008-04-19 18:39 <REP> d-------- C:\Program Files\Bonjour
2008-04-19 18:25 . 2008-04-19 18:25 <REP> d-------- C:\Program Files\Fichiers communs\Macrovision Shared
2008-04-19 15:50 . 2008-04-19 15:50 <REP> d-------- C:\Documents and Settings\Mahnie\.DownloadManager

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 23:42 13,440 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
2008-05-11 10:35 --------- d-----w C:\Program Files\freeCommander2006
2008-05-11 08:52 --------- d-----w C:\Program Files\ewido anti-malware
2008-05-11 08:43 --------- d-----w C:\Program Files\Boonty
2008-05-11 08:43 --------- d-----w C:\Program Files\BitTorrent
2008-05-09 16:15 --------- d-----w C:\Program Files\Lecteur CANALPLAY
2008-05-09 16:14 --------- d-----w C:\Program Files\PokerStars
2008-05-09 16:13 --------- d-----w C:\Program Files\RenMultiFiles Pro
2008-05-09 15:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-25 19:55 --------- d-----w C:\Program Files\3ds max
2008-04-20 21:11 --------- d-----w C:\Documents and Settings\Mahnie\Application Data\combustion4
2008-04-19 21:13 17,408 ----a-w C:\psapi.dll
2008-04-19 16:39 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-19 13:36 --------- d-----w C:\Documents and Settings\Mahnie\Application Data\Azureus
2008-04-06 11:26 --------- d-----w C:\Program Files\Fichiers communs\Sony MXF Filters
2008-04-06 11:25 --------- d-----w C:\Program Files\Quantel
2008-04-06 11:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Quantel
2008-03-14 11:07 --------- d-----w C:\Program Files\TomTom HOME 2
2008-03-14 11:07 --------- d-----w C:\Documents and Settings\Mahnie\Application Data\TomTom
2008-03-14 11:06 --------- d-----w C:\Program Files\TomTom HOME
2008-02-28 21:36 36,216 ----a-w C:\Documents and Settings\Mahnie\Application Data\wklnhst.dat
2006-05-22 21:30 67,008 ----a-w C:\Documents and Settings\Mahnie\Application Data\GDIPFONTCACHEV1.DAT
2005-07-01 21:58 4,096 ----a-w C:\Documents and Settings\Mahnie\log.dat
2005-01-18 02:21 1,416 ----a-w C:\Program Files\GenesisConfig.dat
2002-02-13 15:04 110,592 ----a-w C:\Program Files\internet explorer\plugins\CAPWebActiveX.dll
2006-10-11 10:35 56 --sh--r C:\WINDOWS\system32\95B28A1EE6.sys
2006-10-11 10:35 11,894 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ÇlÇments vides & les ÇlÇments initiaux lÇgitimes ne sont pas listÇs

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-02-18 12:58 206184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 88209 C:\WINDOWS\AGRSMMSG.exe]
"Dit"="Dit.exe" [2004-04-02 13:31 86016 C:\WINDOWS\Dit.exe]
"ledpointer"="CNYHKey.exe" [2004-02-03 18:15 5794816 C:\WINDOWS\CNYHKey.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 22:10 339968]
"Norman ZANDA"="C:\Norman\Npm\bin\ZLH.exe" [2007-08-09 14:40 183352]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
"vidc.X264"= x264vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"CHotkey"=mHotkey.exe
"PCMService"="C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"SPAMfighter Agent"="C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
"TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"CanalPlayerHelper"=C:\Program Files\Lecteur CANALPLAY\CanalPlayerHelper.exe
"FileZilla Server Interface"="C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Outlook Express\\msimn.exe"=
"C:\\Program Files\\discreet\\combustion 3\\combustion.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\3ds max\\3dsmax.exe"=
"C:\\Program Files\\backburner 2\\manager.exe"=
"C:\\Program Files\\backburner 2\\monitor.exe"=
"C:\\Program Files\\backburner 2\\server.exe"=
"C:\\Program Files\\discreet\\combustion 4\\combustion.exe"=
"C:\\Program Files\\FileZilla\\FileZilla.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\neuf telecom\\MP9 Premium\\MP9Premium.exe"=
"C:\\Program Files\\Media Player Classic\\mplayerc.exe"=
"C:\\Program Files\\Fusion\\eyeonScript.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\TYPSoft FTP Server\\ftpserv.exe"=
"C:\Program Files\Neuf\Media Center\httpd\httpd.exe"= C:\Program Files\Neuf\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.2/255.255.255.255:Enabled:Serveur de partage Media Center (Player Neuf Cegetel)
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22002
"26180:TCP"= 26180:TCP:neuf telecom
"26181:TCP"= 26181:TCP:neuf telecom
"9876:TCP"= 9876:TCP:neuf telecom
"26190:UDP"= 26190:UDP:SesamTV PVR

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 Ndiskio;Ndiskio;C:\Norman\Nse\bin\NDISKIO.SYS [2007-01-02 10:55]
R3 Cap7134;MEDION (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2003-06-05 09:04]
R3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2008-05-12 01:42]
R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS\system32\drivers\cmudax.sys [2004-10-01 14:58]
R3 LaCieFWFilter;Silver 1394 Filter (1394 BUS Filter Driver);C:\WINDOWS\system32\DRIVERS\LaCieFWFilter.sys [2005-10-18 07:28]
R3 LaCieUSBFilter;Silver USB Filter (USB BUS Filter Driver);C:\WINDOWS\system32\DRIVERS\LaCieUSBFilter.sys [2005-10-19 08:34]
R3 NvcMFlt;NvcMFlt;C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys [2007-07-09 10:50]
R3 nvcoas;Norman Virus Control on-access component;C:\Norman\Nvc\bin\nvcoas.exe [2007-07-12 11:38]
R3 NVCScheduler;Norman Virus Control Scheduler;C:\Norman\Nvc\BIN\NVCSCHED.EXE [2007-05-23 13:23]
R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2003-06-12 09:47]
R3 PRISM_A00;CREATIX 802.11g Driver;C:\WINDOWS\system32\DRIVERS\PRISMA00.sys [2004-01-16 10:31]
R3 UKBFLT;UKBFLT;C:\WINDOWS\system32\DRIVERS\UKBFLT.sys [2003-12-19 18:13]
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-03-24 21:59]
S3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-05-05 20:46]
S3 nvcfsr;nvcfsr;C:\Norman\Nvc\bin\nvcfsr.sys [2007-01-09 15:25]
S3 nvcoafl51;nvcoafl51;C:\Norman\Nvc\bin\nvcoafl51.sys [2007-01-09 15:25]
S3 nvcoaft51;nvcoaft51;C:\Norman\Nvc\bin\nvcoaft51.sys [2007-01-09 15:25]
S3 nvcoarc51;nvcoarc51;C:\Norman\Nvc\bin\nvcoarc51.sys [2007-01-09 15:25]
S3 phil2vid;Appareil photo VGA USB Philips PCVC690;C:\WINDOWS\system32\DRIVERS\philcam2.sys [2001-08-17 23:04]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 16:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 16:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 16:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 16:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 16:50]
S3 xbreader;ActionReplay XBox Driver (xbreader.sys);C:\WINDOWS\system32\Drivers\xbreader.sys [2001-01-02 23:53]
S4 BackRenderServicev18;ColorFront Background Render v1.8;C:\Program Files\discreet\lustre\Service.exe []


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2348B595-E675-43E5-0601-010400040806}]
C:\WINDOWS\system32\yahoo.exe
.
Contenu du dossier 'Scheduled Tasks/TÉches planifiÇes'
"2008-03-12 10:58:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-07-30 16:34:32 C:\WINDOWS\Tasks\SesamTVMC.job"
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-12 01:42:47
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cachÇs ...

Balayage cachÇ autostart entries ...

Balayage des fichiers cachÇs ...

Scan terminÇ avec succäs
Les fichiers cachÇs: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Norman\npm\bin\elogsvc.exe
C:\Norman\npm\bin\Zanda.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\FileZilla Server\FileZilla server.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Norman\npm\bin\Njeeves.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Norman\NVC\bin\Nip.exe
C:\Norman\NVC\bin\CClaw.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-12 1:46:24 - machine was rebooted [Mahnie]
ComboFix-quarantined-files.txt 2008-05-11 23:46:18

Pre-Run: 19,258,015,744 octets libres
Post-Run: 19,327,913,984 octets libres

WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP êdition familiale" /fastdetect /NoExecute=OptOut
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

249 --- E O F --- 2008-02-27 16:46:43


Voila, j'espere qu'il est gueri!!!

Merci de votre aide

mahnie
0
mahnie Messages postés 8 Date d'inscription dimanche 11 mai 2008 Statut Membre Dernière intervention 13 mai 2008
12 mai 2008 à 20:18
Salut,

Comme je n'ai pas eue de reponses, je suppose qu'il n'y a plus de problemes. Pouvez vous juste me laisser un message pour que je sache si c'est ok?

Merci d'avance.

Encore merci.

mahnie
0
Utilisateur anonyme
12 mai 2008 à 22:13
salut

analyse ces fichiers sur virustotal 1 par 1 et colle le rapport de ces3 fichiers , voir ici :

https://www.virustotal.com/gui/


clicsur parcourir,1 fenetre va s'ouvrir et cherche ceci , le 1er ...clic sur envoyer le fichier ...patiente ...1 fois l'analyse faite colle le rapport etfais de même pour les 2 autres fichiers


fichiers :
C:\WINDOWS\system32\xucbhdhl.exe
C:\WINDOWS\system32\cyivgnhm.exe
C:\WINDOWS\system32\oymmrnsb.ini

bizz
0
mahnie Messages postés 8 Date d'inscription dimanche 11 mai 2008 Statut Membre Dernière intervention 13 mai 2008
13 mai 2008 à 21:30
Salut,
voici les 3 log dans le meme ordre que dans ton message :


Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.5.10.0 2008.05.13 -
AntiVir 7.8.0.17 2008.05.13 -
Authentium 5.1.0.4 2008.05.13 -
Avast 4.8.1169.0 2008.05.12 -
AVG 7.5.0.516 2008.05.12 Generic10.UDV
BitDefender 7.2 2008.05.08 -
CAT-QuickHeal 9.50 2008.05.12 -
ClamAV 0.92.1 2008.05.12 -
DrWeb 4.44.0.09170 2008.05.13 -
eSafe 7.0.15.0 2008.05.12 -
eTrust-Vet 31.4.5783 2008.05.12 -
Ewido 4.0 2008.05.12 -
F-Prot 4.4.2.54 2008.05.13 -
F-Secure 6.70.13260.0 2008.05.13 -
Fortinet 3.14.0.0 2008.05.13 W32/Vundou.ZAE!tr
GData 2.0.7306.1023 2008.05.13 -
Ikarus T3.1.1.26.0 2008.05.13 Trojan.Crypt.XPACK
Kaspersky 7.0.0.125 2008.05.13 -
McAfee 5293 2008.05.12 -
Microsoft 1.3408 2008.05.13 -
NOD32v2 3094 2008.05.12 Win32/PrivacySet.A
Norman 5.80.02 2008.05.09 W32/Smalltroj.EGXV
Panda 9.0.0.4 2008.05.12 Trj/Agent.ITR
Prevx1 V2 2008.05.13 Malicious Software
Rising 20.44.10.00 2008.05.13 -
Sophos 4.29.0 2008.05.13 Troj/PrivZone-A
Sunbelt 3.0.1114.0 2008.05.12 -
Symantec 10 2008.05.13 -
TheHacker 6.2.92.309 2008.05.13 -
VBA32 3.12.6.5 2008.05.12 -
VirusBuster 4.3.26:9 2008.05.12 -
Webwasher-Gateway 6.6.2 2008.05.13 Win32.Malware.gen!80 (suspicious)
Information additionnelle
File size: 2048 bytes
MD5...: 5a3b18025b98839909f0b549778d3cbf
SHA1..: 2aa51c6d57b2bb0d4b8b7f509a7e54961fc961e4
SHA256: a554b5b6fbf42e9a6614269c821aa33dbad9a956bdcf0246d6c433915e05df86
SHA512: d14abf3cb4d51216b31ae149badced932bcd4e516aff891783ccb6e564dee0d3
f782d11fd7cda6894b0eec0b23969421727698d02d712f42135abde4d0edac19
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4003bc
timedatestamp.....: 0x481efb0f (Mon May 05 12:18:23 2008)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x300 0x100 0x100 5.61 a41be52b475dfb013265b8b57025f995
.rdata 0x400 0x56 0x100 1.94 68d8c02b103700290ea8f3edd062f675
INIT 0x500 0x8e 0x100 2.56 0ea0b8b784d0ab9865f99165ef5808a7
.rsrc 0x600 0xb0 0x100 4.51 f69dace89ec47d43460b9c59b53ac76f
.reloc 0x700 0x20 0x100 0.47 919c4ebdb9f32d2f76bfdc55608301be

( 1 imports )
> KERNEL32.dll: LoadLibraryA, GetProcAddress, ExitProcess, GetModuleHandleA

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=55E8360A0031C9FB08AB0039378BBA00B79BCD14




Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.5.10.0 2008.05.13 -
AntiVir 7.8.0.17 2008.05.13 -
Authentium 5.1.0.4 2008.05.13 -
Avast 4.8.1169.0 2008.05.12 -
AVG 7.5.0.516 2008.05.12 Generic10.UDV
BitDefender 7.2 2008.05.08 -
CAT-QuickHeal 9.50 2008.05.12 -
ClamAV 0.92.1 2008.05.12 -
DrWeb 4.44.0.09170 2008.05.13 -
eSafe 7.0.15.0 2008.05.12 -
eTrust-Vet 31.4.5783 2008.05.12 -
Ewido 4.0 2008.05.12 -
F-Prot 4.4.2.54 2008.05.13 -
F-Secure 6.70.13260.0 2008.05.13 -
Fortinet 3.14.0.0 2008.05.13 W32/Vundou.ZAE!tr
GData 2.0.7306.1023 2008.05.13 -
Ikarus T3.1.1.26.0 2008.05.13 Trojan.Crypt.XPACK
Kaspersky 7.0.0.125 2008.05.13 -
McAfee 5293 2008.05.12 -
Microsoft 1.3408 2008.05.13 -
NOD32v2 3094 2008.05.12 Win32/PrivacySet.A
Norman 5.80.02 2008.05.09 W32/Smalltroj.EGXV
Panda 9.0.0.4 2008.05.12 Trj/Agent.ITR
Prevx1 V2 2008.05.13 Malicious Software
Rising 20.44.10.00 2008.05.13 -
Sophos 4.29.0 2008.05.13 Troj/PrivZone-A
Sunbelt 3.0.1114.0 2008.05.12 -
Symantec 10 2008.05.13 -
TheHacker 6.2.92.309 2008.05.13 -
VBA32 3.12.6.5 2008.05.12 -
VirusBuster 4.3.26:9 2008.05.12 -
Webwasher-Gateway 6.6.2 2008.05.13 Win32.Malware.gen!80 (suspicious)
Information additionnelle
File size: 2048 bytes
MD5...: 5a3b18025b98839909f0b549778d3cbf
SHA1..: 2aa51c6d57b2bb0d4b8b7f509a7e54961fc961e4
SHA256: a554b5b6fbf42e9a6614269c821aa33dbad9a956bdcf0246d6c433915e05df86
SHA512: d14abf3cb4d51216b31ae149badced932bcd4e516aff891783ccb6e564dee0d3
f782d11fd7cda6894b0eec0b23969421727698d02d712f42135abde4d0edac19
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4003bc
timedatestamp.....: 0x481efb0f (Mon May 05 12:18:23 2008)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x300 0x100 0x100 5.61 a41be52b475dfb013265b8b57025f995
.rdata 0x400 0x56 0x100 1.94 68d8c02b103700290ea8f3edd062f675
INIT 0x500 0x8e 0x100 2.56 0ea0b8b784d0ab9865f99165ef5808a7
.rsrc 0x600 0xb0 0x100 4.51 f69dace89ec47d43460b9c59b53ac76f
.reloc 0x700 0x20 0x100 0.47 919c4ebdb9f32d2f76bfdc55608301be

( 1 imports )
> KERNEL32.dll: LoadLibraryA, GetProcAddress, ExitProcess, GetModuleHandleA

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=55E8360A0031C9FB08AB0039378BBA00B79BCD14




Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.5.10.0 2008.05.13 -
AntiVir 7.8.0.17 2008.05.13 -
Authentium 5.1.0.4 2008.05.13 -
Avast 4.8.1195.0 2008.05.13 -
AVG 7.5.0.516 2008.05.13 -
BitDefender 7.2 2008.05.08 -
CAT-QuickHeal 9.50 2008.05.13 -
ClamAV 0.92.1 2008.05.13 -
DrWeb 4.44.0.09170 2008.05.13 -
eSafe 7.0.15.0 2008.05.13 -
eTrust-Vet 31.4.5784 2008.05.13 -
Ewido 4.0 2008.05.13 -
F-Prot 4.4.2.54 2008.05.13 -
F-Secure 6.70.13260.0 2008.05.13 -
Fortinet 3.14.0.0 2008.05.13 -
GData 2.0.7306.1023 2008.05.13 -
Ikarus T3.1.1.26.0 2008.05.13 -
Kaspersky 7.0.0.125 2008.05.13 -
McAfee 5294 2008.05.13 -
Microsoft 1.3520 2008.05.13 -
NOD32v2 3096 2008.05.13 -
Norman 5.80.02 2008.05.13 -
Panda 9.0.0.4 2008.05.12 -
Prevx1 V2 2008.05.13 -
Rising 20.44.12.00 2008.05.13 -
Sophos 4.29.0 2008.05.13 -
Sunbelt 3.0.1114.0 2008.05.12 -
Symantec 10 2008.05.13 -
TheHacker 6.2.92.309 2008.05.13 -
VBA32 3.12.6.6 2008.05.13 -
VirusBuster 4.3.26:9 2008.05.13 -
Webwasher-Gateway 6.6.2 2008.05.13 -
Information additionnelle
File size: 594 bytes
MD5...: ff152eb35374d4ea8ae9a33f1b93d163
SHA1..: 7183a8718a3f14602fd501573c8d7caae5496c49
SHA256: a4ab86f36865e7eba2dc5331001b068f138c5a3b7493ebd00a89519b1898986f
SHA512: f72035fd067bc8723b30819dfb573b9233e44024a58c71284f85133a00cab551
b234275c2266b3a4f19f713e8989c95adda8d35a0ffb3fb6b9efab800fa03a45
PEiD..: -
PEInfo: -




Merci de ton aide.

Mahnie
0
Utilisateur anonyme > mahnie Messages postés 8 Date d'inscription dimanche 11 mai 2008 Statut Membre Dernière intervention 13 mai 2008
13 mai 2008 à 21:55
salut

lance ceci stp:


Télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
Double-clique sur OTMoveIt.exe pour le lancer.
Copie la liste qui se trouve en citation ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous Paste List of Files/Folders to move.


Citation :

C:\WINDOWS\system32\xucbhdhl.exe
C:\WINDOWS\system32\cyivgnhm.exe
C:\WINDOWS\system32\oymmrnsb.ini


clique sur MoveIt! pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.


bises
0