Infecté par Virtumonde et Virtumonde.dll
Résolu/Fermé
A voir également:
- Infecté par Virtumonde et Virtumonde.dll
- L'ordinateur d'arthur a été infecté par un virus répertorié récemment. son anti-virus ne l'a pas détecté. qu'a-t-il pu se passer ? ✓ - Forum Antivirus
- L'ordinateur de samantha a été infecté par un virus répertorié récemment. son anti-virus ne l'a pas détecté. qu'a-t-il pu se passer ? - Forum Virus
- Mon ordinateur a été infecté par un virus ou - Forum Virus
- Infection par : ONLYPC Flow.co.in ✓ - Forum Virus
- Alerte windows ordinateur infecté - Accueil - Arnaque
5 réponses
geoffrey5
Messages postés
13732
Date d'inscription
dimanche 20 mai 2007
Statut
Contributeur sécurité
Dernière intervention
21 mai 2010
10
10 juin 2008 à 23:55
10 juin 2008 à 23:55
Salut !!
Télécharge sur le bureau virtumundobegone :
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
déconnecte internet et désactive ton antivirus le temps de la manipulation
=> Double clic sur VirtumundoBeGone.exe
=> Clic Continue ==> clic Start
=> Clic Oui
=> A la fin si Vundo est présent , le PC s’éteint et redémarre
- Si Ecran bleu et message : Erreur fatale .. pas de problème
=> Poster le rapport VBG.TXT qui est sur le bureau
Télécharge sur le bureau virtumundobegone :
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
déconnecte internet et désactive ton antivirus le temps de la manipulation
=> Double clic sur VirtumundoBeGone.exe
=> Clic Continue ==> clic Start
=> Clic Oui
=> A la fin si Vundo est présent , le PC s’éteint et redémarre
- Si Ecran bleu et message : Erreur fatale .. pas de problème
=> Poster le rapport VBG.TXT qui est sur le bureau
geoffrey5
Messages postés
13732
Date d'inscription
dimanche 20 mai 2007
Statut
Contributeur sécurité
Dernière intervention
21 mai 2010
10
10 juin 2008 à 23:57
10 juin 2008 à 23:57
ensuite :
Télécharger sur le Bureau vundofix : http://www.atribune.org/ccount/click.php?id=4
- Double-clic VundoFix.exe.
-Clic Scan for Vundo
- le scan peut être assez long (1à2h) comme très rapide , à la fin
-Clic Fix Vundo
- Puis yes
- Le Bureau disparaît un moment lors de la suppression des fichiers.
-Message shutdown
-clic oui
-Redémarrage auto
Note : il peut y avoir plusieurs redémarrages
-copier le rapport qui est dans C:\vundofix.txt
et refait un hijack
Télécharger sur le Bureau vundofix : http://www.atribune.org/ccount/click.php?id=4
- Double-clic VundoFix.exe.
-Clic Scan for Vundo
- le scan peut être assez long (1à2h) comme très rapide , à la fin
-Clic Fix Vundo
- Puis yes
- Le Bureau disparaît un moment lors de la suppression des fichiers.
-Message shutdown
-clic oui
-Redémarrage auto
Note : il peut y avoir plusieurs redémarrages
-copier le rapport qui est dans C:\vundofix.txt
et refait un hijack
geoffrey5
Messages postés
13732
Date d'inscription
dimanche 20 mai 2007
Statut
Contributeur sécurité
Dernière intervention
21 mai 2010
10
11 juin 2008 à 11:30
11 juin 2008 à 11:30
Salut !!
Refais un rapport hijackthis pour vérifier stp
Refais un rapport hijackthis pour vérifier stp
J'ai lancé Virtumondobegone voici le log :
[07/09/2008, 22:44:21] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Egg\Bureau\VirtumundoBeGone.exe" )
[07/09/2008, 22:44:26] - Detected System Information:
[07/09/2008, 22:44:27] - Windows Version: 5.1.2600, Service Pack 2
[07/09/2008, 22:44:27] - Current Username: Egg (Admin)
[07/09/2008, 22:44:27] - Windows is in NORMAL mode.
[07/09/2008, 22:44:28] - Searching for Browser Helper Objects:
[07/09/2008, 22:44:28] - BHO 1: {0ED49734-0923-4BB8-8121-9A920BB0772A} ()
[07/09/2008, 22:44:28] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:28] - No filename found. Continuing.
[07/09/2008, 22:44:29] - BHO 2: {33DA9E3C-935E-4EC2-977D-AFE3A3B5E727} ()
[07/09/2008, 22:44:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:29] - Checking for HKLM\...\Winlogon\Notify\yayaaBUN
[07/09/2008, 22:44:29] - Found: HKLM\...\Winlogon\Notify\yayaaBUN - This is probably Virtumundo.
[07/09/2008, 22:44:30] - Assigning {33DA9E3C-935E-4EC2-977D-AFE3A3B5E727} MSEvents Object
[07/09/2008, 22:44:30] - BHO list has been changed! Starting over...
[07/09/2008, 22:44:30] - BHO 1: {0ED49734-0923-4BB8-8121-9A920BB0772A} ()
[07/09/2008, 22:44:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:31] - No filename found. Continuing.
[07/09/2008, 22:44:31] - BHO 2: {33DA9E3C-935E-4EC2-977D-AFE3A3B5E727} (MSEvents Object)
[07/09/2008, 22:44:31] - ALERT: Found MSEvents Object!
[07/09/2008, 22:44:31] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[07/09/2008, 22:44:31] - BHO 4: {693E6478-BEC4-4256-9278-38E1230063E1} ()
[07/09/2008, 22:44:32] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:32] - No filename found. Continuing.
[07/09/2008, 22:44:32] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[07/09/2008, 22:44:32] - BHO 6: {7A98F607-2B09-46F6-9889-DA6F3ADDFB1E} ()
[07/09/2008, 22:44:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:33] - No filename found. Continuing.
[07/09/2008, 22:44:33] - BHO 7: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[07/09/2008, 22:44:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:34] - No filename found. Continuing.
[07/09/2008, 22:44:34] - BHO 8: {E1C9F102-EBE0-4678-9684-F25518B6128B} ()
[07/09/2008, 22:44:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:34] - Checking for HKLM\...\Winlogon\Notify\pmnKCuSj
[07/09/2008, 22:44:34] - Key not found: HKLM\...\Winlogon\Notify\pmnKCuSj, continuing.
[07/09/2008, 22:44:35] - Finished Searching Browser Helper Objects
[07/09/2008, 22:44:35] - *** Detected MSEvents Object
[07/09/2008, 22:44:35] - Trying to remove MSEvents Object...
[07/09/2008, 22:44:36] - Terminating Process: IEXPLORE.EXE
[07/09/2008, 22:44:37] - Terminating Process: RUNDLL32.EXE
[07/09/2008, 22:44:38] - Disabling Automatic Shell Restart
[07/09/2008, 22:44:38] - Terminating Process: EXPLORER.EXE
[07/09/2008, 22:44:39] - Suspending the NT Session Manager System Service
[07/09/2008, 22:44:40] - Terminating Windows NT Logon/Logoff Manager
[07/09/2008, 22:44:40] - Re-enabling Automatic Shell Restart
[07/09/2008, 22:44:41] - File to disable: C:\WINDOWS\system32\yayaaBUN.dll
[07/09/2008, 22:44:41] - Removing HKLM\...\Browser Helper Objects\{33DA9E3C-935E-4EC2-977D-AFE3A3B5E727}
[07/09/2008, 22:44:41] - Removing HKCR\CLSID\{33DA9E3C-935E-4EC2-977D-AFE3A3B5E727}
[07/09/2008, 22:44:41] - Adding Kill Bit for ActiveX for GUID: {33DA9E3C-935E-4EC2-977D-AFE3A3B5E727}
[07/09/2008, 22:44:42] - Deleting ATLEvents/MSEvents Registry entries
[07/09/2008, 22:44:42] - Removing HKLM\...\Winlogon\Notify\yayaaBUN
[07/09/2008, 22:44:42] - Searching for Browser Helper Objects:
[07/09/2008, 22:44:42] - BHO 1: {0ED49734-0923-4BB8-8121-9A920BB0772A} ()
[07/09/2008, 22:44:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:43] - No filename found. Continuing.
[07/09/2008, 22:44:43] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[07/09/2008, 22:44:43] - BHO 3: {693E6478-BEC4-4256-9278-38E1230063E1} ()
[07/09/2008, 22:44:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:44] - No filename found. Continuing.
[07/09/2008, 22:44:44] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[07/09/2008, 22:44:44] - BHO 5: {7A98F607-2B09-46F6-9889-DA6F3ADDFB1E} ()
[07/09/2008, 22:44:44] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:45] - No filename found. Continuing.
[07/09/2008, 22:44:45] - BHO 6: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[07/09/2008, 22:44:45] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:45] - No filename found. Continuing.
[07/09/2008, 22:44:46] - BHO 7: {E1C9F102-EBE0-4678-9684-F25518B6128B} ()
[07/09/2008, 22:44:46] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:46] - Checking for HKLM\...\Winlogon\Notify\pmnKCuSj
[07/09/2008, 22:44:46] - Key not found: HKLM\...\Winlogon\Notify\pmnKCuSj, continuing.
[07/09/2008, 22:44:46] - Finished Searching Browser Helper Objects
[07/09/2008, 22:44:47] - Finishing up...
[07/09/2008, 22:44:47] - A restart is needed.
[07/09/2008, 22:44:47] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[07/09/2008, 22:45:01] - Attempting to Restart via STOP error (Blue Screen!)
[07/09/2008, 22:44:21] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Egg\Bureau\VirtumundoBeGone.exe" )
[07/09/2008, 22:44:26] - Detected System Information:
[07/09/2008, 22:44:27] - Windows Version: 5.1.2600, Service Pack 2
[07/09/2008, 22:44:27] - Current Username: Egg (Admin)
[07/09/2008, 22:44:27] - Windows is in NORMAL mode.
[07/09/2008, 22:44:28] - Searching for Browser Helper Objects:
[07/09/2008, 22:44:28] - BHO 1: {0ED49734-0923-4BB8-8121-9A920BB0772A} ()
[07/09/2008, 22:44:28] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:28] - No filename found. Continuing.
[07/09/2008, 22:44:29] - BHO 2: {33DA9E3C-935E-4EC2-977D-AFE3A3B5E727} ()
[07/09/2008, 22:44:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:29] - Checking for HKLM\...\Winlogon\Notify\yayaaBUN
[07/09/2008, 22:44:29] - Found: HKLM\...\Winlogon\Notify\yayaaBUN - This is probably Virtumundo.
[07/09/2008, 22:44:30] - Assigning {33DA9E3C-935E-4EC2-977D-AFE3A3B5E727} MSEvents Object
[07/09/2008, 22:44:30] - BHO list has been changed! Starting over...
[07/09/2008, 22:44:30] - BHO 1: {0ED49734-0923-4BB8-8121-9A920BB0772A} ()
[07/09/2008, 22:44:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:31] - No filename found. Continuing.
[07/09/2008, 22:44:31] - BHO 2: {33DA9E3C-935E-4EC2-977D-AFE3A3B5E727} (MSEvents Object)
[07/09/2008, 22:44:31] - ALERT: Found MSEvents Object!
[07/09/2008, 22:44:31] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[07/09/2008, 22:44:31] - BHO 4: {693E6478-BEC4-4256-9278-38E1230063E1} ()
[07/09/2008, 22:44:32] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:32] - No filename found. Continuing.
[07/09/2008, 22:44:32] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[07/09/2008, 22:44:32] - BHO 6: {7A98F607-2B09-46F6-9889-DA6F3ADDFB1E} ()
[07/09/2008, 22:44:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:33] - No filename found. Continuing.
[07/09/2008, 22:44:33] - BHO 7: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[07/09/2008, 22:44:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:34] - No filename found. Continuing.
[07/09/2008, 22:44:34] - BHO 8: {E1C9F102-EBE0-4678-9684-F25518B6128B} ()
[07/09/2008, 22:44:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:34] - Checking for HKLM\...\Winlogon\Notify\pmnKCuSj
[07/09/2008, 22:44:34] - Key not found: HKLM\...\Winlogon\Notify\pmnKCuSj, continuing.
[07/09/2008, 22:44:35] - Finished Searching Browser Helper Objects
[07/09/2008, 22:44:35] - *** Detected MSEvents Object
[07/09/2008, 22:44:35] - Trying to remove MSEvents Object...
[07/09/2008, 22:44:36] - Terminating Process: IEXPLORE.EXE
[07/09/2008, 22:44:37] - Terminating Process: RUNDLL32.EXE
[07/09/2008, 22:44:38] - Disabling Automatic Shell Restart
[07/09/2008, 22:44:38] - Terminating Process: EXPLORER.EXE
[07/09/2008, 22:44:39] - Suspending the NT Session Manager System Service
[07/09/2008, 22:44:40] - Terminating Windows NT Logon/Logoff Manager
[07/09/2008, 22:44:40] - Re-enabling Automatic Shell Restart
[07/09/2008, 22:44:41] - File to disable: C:\WINDOWS\system32\yayaaBUN.dll
[07/09/2008, 22:44:41] - Removing HKLM\...\Browser Helper Objects\{33DA9E3C-935E-4EC2-977D-AFE3A3B5E727}
[07/09/2008, 22:44:41] - Removing HKCR\CLSID\{33DA9E3C-935E-4EC2-977D-AFE3A3B5E727}
[07/09/2008, 22:44:41] - Adding Kill Bit for ActiveX for GUID: {33DA9E3C-935E-4EC2-977D-AFE3A3B5E727}
[07/09/2008, 22:44:42] - Deleting ATLEvents/MSEvents Registry entries
[07/09/2008, 22:44:42] - Removing HKLM\...\Winlogon\Notify\yayaaBUN
[07/09/2008, 22:44:42] - Searching for Browser Helper Objects:
[07/09/2008, 22:44:42] - BHO 1: {0ED49734-0923-4BB8-8121-9A920BB0772A} ()
[07/09/2008, 22:44:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:43] - No filename found. Continuing.
[07/09/2008, 22:44:43] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[07/09/2008, 22:44:43] - BHO 3: {693E6478-BEC4-4256-9278-38E1230063E1} ()
[07/09/2008, 22:44:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:44] - No filename found. Continuing.
[07/09/2008, 22:44:44] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[07/09/2008, 22:44:44] - BHO 5: {7A98F607-2B09-46F6-9889-DA6F3ADDFB1E} ()
[07/09/2008, 22:44:44] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:45] - No filename found. Continuing.
[07/09/2008, 22:44:45] - BHO 6: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[07/09/2008, 22:44:45] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:45] - No filename found. Continuing.
[07/09/2008, 22:44:46] - BHO 7: {E1C9F102-EBE0-4678-9684-F25518B6128B} ()
[07/09/2008, 22:44:46] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/09/2008, 22:44:46] - Checking for HKLM\...\Winlogon\Notify\pmnKCuSj
[07/09/2008, 22:44:46] - Key not found: HKLM\...\Winlogon\Notify\pmnKCuSj, continuing.
[07/09/2008, 22:44:46] - Finished Searching Browser Helper Objects
[07/09/2008, 22:44:47] - Finishing up...
[07/09/2008, 22:44:47] - A restart is needed.
[07/09/2008, 22:44:47] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[07/09/2008, 22:45:01] - Attempting to Restart via STOP error (Blue Screen!)
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question