Pb avec Virtumonde

Résolu
Bonjour,

Toute nouvelle adhérente, je ne sais pas trop comment marche ce forum. J'ai envoyé un msg pour un pb de virus Virtumonde. J'ai eu une réponse de philéa83 sur mon adresse email, et voilà mes rapports :

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 07:56:10 03/10/2007

Listing files found while scanning....

C:\windows\system32\hhkmp.bak1
C:\windows\system32\hhkmp.bak2
C:\windows\system32\hhkmp.ini
C:\windows\system32\jqyuxcxu.ini
C:\WINDOWS\system32\mdkbgxes.dll
C:\windows\system32\orqss.bak1
C:\windows\system32\orqss.bak2
C:\windows\system32\orqss.ini
C:\windows\system32\pmkhh.dll
C:\WINDOWS\system32\sexgbkdm.ini
C:\windows\system32\ssqro.dll
C:\windows\system32\uxcxuyqj.dll

Beginning removal...

Beginning removal...

Attempting to delete C:\windows\system32\hhkmp.bak1
C:\windows\system32\hhkmp.bak1 Has been deleted!

Attempting to delete C:\windows\system32\hhkmp.bak2
C:\windows\system32\hhkmp.bak2 Has been deleted!

Attempting to delete C:\windows\system32\hhkmp.ini
C:\windows\system32\hhkmp.ini Has been deleted!

Attempting to delete C:\windows\system32\jqyuxcxu.ini
C:\windows\system32\jqyuxcxu.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mdkbgxes.dll
C:\WINDOWS\system32\mdkbgxes.dll Could not be deleted.

Attempting to delete C:\windows\system32\orqss.bak1
C:\windows\system32\orqss.bak1 Has been deleted!

Attempting to delete C:\windows\system32\orqss.bak2
C:\windows\system32\orqss.bak2 Has been deleted!

Attempting to delete C:\windows\system32\orqss.ini
C:\windows\system32\orqss.ini Has been deleted!

Attempting to delete C:\windows\system32\pmkhh.dll
C:\windows\system32\pmkhh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sexgbkdm.ini
C:\WINDOWS\system32\sexgbkdm.ini Has been deleted!

Attempting to delete C:\windows\system32\ssqro.dll
C:\windows\system32\ssqro.dll Has been deleted!

Attempting to delete C:\windows\system32\uxcxuyqj.dll
C:\windows\system32\uxcxuyqj.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 08:05:05 03/10/2007

Listing files found while scanning....

No infected files were found.

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 08:29:27 12/10/2007

Listing files found while scanning....

C:\WINDOWS\system32\carvvpam.dll
C:\windows\system32\ihbqxpox.ini
C:\WINDOWS\system32\mapvvrac.ini
C:\windows\system32\xopxqbhi.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\carvvpam.dll
C:\WINDOWS\system32\carvvpam.dll Could not be deleted.

Attempting to delete C:\windows\system32\ihbqxpox.ini
C:\windows\system32\ihbqxpox.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mapvvrac.ini
C:\WINDOWS\system32\mapvvrac.ini Has been deleted!

Attempting to delete C:\windows\system32\xopxqbhi.dll
C:\windows\system32\xopxqbhi.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 08:33:41 12/10/2007

Listing files found while scanning....

No infected files were found.

Beginning removal...

VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 14:24:00 12/10/2007

Listing files found while scanning....

C:\WINDOWS\system32\akujogan.dll
C:\windows\system32\mswstr10.dll
C:\WINDOWS\system32\nagojuka.ini

Beginning removal...

Attempting to delete C:\WINDOWS\system32\akujogan.dll
C:\WINDOWS\system32\akujogan.dll Could not be deleted.

Attempting to delete C:\windows\system32\mswstr10.dll
C:\windows\system32\mswstr10.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nagojuka.ini
C:\WINDOWS\system32\nagojuka.ini Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\akujogan.dll
C:\WINDOWS\system32\akujogan.dll Has been deleted!

Attempting to delete C:\windows\system32\mswstr10.dll
C:\windows\system32\mswstr10.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\mdkbgxes.dll
C:\WINDOWS\system32\mdkbgxes.dll Has been deleted!

Performing Repairs to the registry.
Done!

HIJACKTHIS

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:24:27, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 9323 bytes

BitDefender Online Scanner

Rapport d'analyse généré à: Fri, Oct 12, 2007 - 22:26:30

Voie d'analyse: C:\;D:\;F:\;

Statistiques

Temps

02:11:16

Fichiers

283411

Directoires

11351

Secteurs de boot

2

Archives

3186

Paquets programmes

14971

Résultats

Virus identifiés

8

Fichiers infectés

25

Fichiers suspects

0

Avertissements

0

Désinfectés

0

Fichiers effacés

24

Info sur les moteurs

Définition virus

826479

Version des moteurs

AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

Analyse des plugins

14

Archive des plugins

38

Unpack des plugins

7

E-mail plugins

6

Système plugins

1

Paramètres d'analyse

Première action

Désinfecté

Seconde Action

Supprimé

Heuristique

Oui

Acceptez les avertissements

Oui

Extensions analysées

*;

Excludez les extensions

Analyse d'emails

Oui

Analyse des Archives

Oui

Analyser paquets programmes

Oui

Analyse des fichiers

Oui

Analyse de boot

Oui

Fichier analysé

Statut

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 0)

Infecté par: Trojan.Downloader.Agent.ALR

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 0)

Echec de la désinfection

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 0)

Supprimé

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)

Echec de la mise à jour

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 15)

Infecté par: Trojan.Fakealert.BX

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 15)

Echec de la désinfection

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 15)

Supprimé

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)

Echec de la mise à jour

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 16)

Infecté par: Trojan.Fakealert.FB

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 16)

Echec de la désinfection

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)=>(Instyler Module 16)

Supprimé

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temp\WinAntiSpyware2006Setup.exe=>(Instyler o)

Echec de la mise à jour

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temporary Internet Files\Content.IE5\N6S4DPDZ\gepj[1]

Infecté par: Trojan.Vundo.DNR

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temporary Internet Files\Content.IE5\N6S4DPDZ\gepj[1]

Echec de la désinfection

C:\Documents and Settings\Etienne.USER-PC\Local Settings\Temporary Internet Files\Content.IE5\N6S4DPDZ\gepj[1]

Supprimé

C:\VundoFix Backups\mdkbgxes.dll.bad

Infecté par: Trojan.Vundo.DNR

C:\VundoFix Backups\mdkbgxes.dll.bad

Echec de la désinfection

C:\VundoFix Backups\mdkbgxes.dll.bad

Supprimé

C:\VundoFix Backups\pmkhh.dll.bad

Infecté par: DeepScan:Generic.Virtumonde.1.DCD3CD61

C:\VundoFix Backups\pmkhh.dll.bad

Echec de la désinfection

C:\VundoFix Backups\pmkhh.dll.bad

Supprimé

C:\VundoFix Backups\ssqro.dll.bad

Infecté par: DeepScan:Generic.Virtumonde.1.DCD3CD61

C:\VundoFix Backups\ssqro.dll.bad

Echec de la désinfection

C:\VundoFix Backups\ssqro.dll.bad

Supprimé

C:\VundoFix Backups\uxcxuyqj.dll.bad

Infecté par: Trojan.Vundo.DNR

C:\VundoFix Backups\uxcxuyqj.dll.bad

Echec de la désinfection

C:\VundoFix Backups\uxcxuyqj.dll.bad

Supprimé

C:\VundoFix Backups\xopxqbhi.dll.bad

Infecté par: Trojan.Vundo.DNR

C:\VundoFix Backups\xopxqbhi.dll.bad

Echec de la désinfection

C:\VundoFix Backups\xopxqbhi.dll.bad

Supprimé

C:\WINDOWS\system32\avjvstwu.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\avjvstwu.dll

Echec de la désinfection

C:\WINDOWS\system32\avjvstwu.dll

Supprimé

C:\WINDOWS\system32\cnkfuutu.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\cnkfuutu.dll

Echec de la désinfection

C:\WINDOWS\system32\cnkfuutu.dll

Supprimé

C:\WINDOWS\system32\cojalghu.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\cojalghu.dll

Echec de la désinfection

C:\WINDOWS\system32\cojalghu.dll

Supprimé

C:\WINDOWS\system32\geebb.dll

Détecté avec: Adware.Vundo.AU

C:\WINDOWS\system32\geebb.dll

Echec de la désinfection

C:\WINDOWS\system32\geebb.dll

Supprimé

C:\WINDOWS\system32\geeda.dll

Détecté avec: Adware.Vundo.AU

C:\WINDOWS\system32\geeda.dll

Echec de la désinfection

C:\WINDOWS\system32\geeda.dll

Supprimé

C:\WINDOWS\system32\kkmrqmgc.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\kkmrqmgc.dll

Echec de la désinfection

C:\WINDOWS\system32\kkmrqmgc.dll

Supprimé

C:\WINDOWS\system32\mljge.dll

Infecté par: Trojan.Vundo.DNO

C:\WINDOWS\system32\mljge.dll

Echec de la désinfection

C:\WINDOWS\system32\mljge.dll

Supprimé

C:\WINDOWS\system32\mlljg.dll

Détecté avec: Adware.Vundo.AU

C:\WINDOWS\system32\mlljg.dll

Echec de la désinfection

C:\WINDOWS\system32\mlljg.dll

Supprimé

C:\WINDOWS\system32\mllji.dll

Infecté par: Trojan.Vundo.DNO

C:\WINDOWS\system32\mllji.dll

Echec de la désinfection

C:\WINDOWS\system32\mllji.dll

Echec de la suppression

C:\WINDOWS\system32\ngmonkfe.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\ngmonkfe.dll

Echec de la désinfection

C:\WINDOWS\system32\ngmonkfe.dll

Supprimé

C:\WINDOWS\system32\ovypcabi.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\ovypcabi.dll

Echec de la désinfection

C:\WINDOWS\system32\ovypcabi.dll

Supprimé

C:\WINDOWS\system32\pmnlj.dll

Détecté avec: Adware.Vundo.AU

C:\WINDOWS\system32\pmnlj.dll

Echec de la désinfection

C:\WINDOWS\system32\pmnlj.dll

Supprimé

C:\WINDOWS\system32\ubodmbgx.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\ubodmbgx.dll

Echec de la désinfection

C:\WINDOWS\system32\ubodmbgx.dll

Supprimé

C:\WINDOWS\system32\vogcbyqt.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\vogcbyqt.dll

Echec de la désinfection

C:\WINDOWS\system32\vogcbyqt.dll

Supprimé

C:\WINDOWS\system32\wrsukdbp.dll

Infecté par: Trojan.Vundo.DNR

C:\WINDOWS\system32\wrsukdbp.dll

Echec de la désinfection

C:\WINDOWS\system32\wrsukdbp.dll

Supprimé

C:\WINDOWS\system32\xmdbdvgq.dll

Infecté par: Trojan.Vundo.DNP

C:\WINDOWS\system32\xmdbdvgq.dll

Supprimé

Merci de ton aide
Configuration: Windows XP
Firefox 2.0.0.7

18 réponses

  1. Contributeur sécurité
    de rien ce fût avec plaisir
    0
    1. OK et encore merci pour ton aide et ta patience.
      0
      1. Contributeur sécurité
        bonjour

        bon une bonne chose. Tout est ok maintenant côté infectieux, par contre pour ton message je ne sais pas du tout. Tu devrais poser la question sur le forum windows, tu aurais certainement plus de réponses.

        * Tu peux supprimer tous les logiciels que nous avons utilisés

        * démarrer-----------panneau de configuration------------système----------
        onglet Restauration système-----------coche la case (Désactiver la restauration système)--------------
        redémarre l'ordinateur
        réactive la ensuite

        * Pour améliorer la sécurité de ton PC prend quelques instants pour lire

        CECI

        * Dénonce ton infection pour faire condamner les auteurs.
        Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection :

        - Voir les règles du forum : https://malwarecomplaints.info/
        - Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
        Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
        Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

        Tu as alors sous forme de liste un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).
        La tienne = ******

        ---> https://malwarecomplaints.info/

        Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections
        conforme au règle du forum (age, ville, département etc..)

        Indique aussi le nom du Forum qui t'a aidé, CommentCaMarche

        0
        1. Par contre, j'ai viré l'anti virus Kaspersky que j'avais (Démo d'1 mois) avec lequel j'avais l'impression d'avoir bp de msg d'infections divers et qui me bloquait. J'ai réinstallé Avast. J'ai refais un scan avec CCleaner, Spybot, AdAware. Je te joins mon nouveau rapport Hijackthis. Apparemment, je n'ai plus de problème avec Virtumonde qui n'apparaît plus nulle part.

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 14:04:11, on 19/10/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16544)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\SearchIndexer.exe
          C:\WINDOWS\system32\RunDLL32.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
          C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
          C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\PROGRA~1\INCRED~1\bin\IMApp.exe
          C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\Logitech\SetPoint\KEM.exe
          C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
          C:\Program Files\Windows Desktop Search\WindowsSearch.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
          C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
          C:\WINDOWS\system32\SearchProtocolHost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\WINDOWS\system32\HPZipm12.exe

          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
          O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
          O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
          O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
          O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
          O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
          O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
          0
          1. Contributeur sécurité
            bonsoir

            non c'est pas vraiment pareil, la durée du scan n'est pas la même non +
            depuis le lien que je t'ai donné, tu arrives sur active scan, non sur total scan
            0
            1. Voici mon rapport Panda mais je n'ai pas exactement trouvé activescan, mais totalscan. Je ne pense pas qu'il y ait une grande différence.

              ;***********************************************************************************************************************************************************************************
              ANALYSIS: 2007-10-18 20:59:11
              PROTECTIONS: 1
              MALWARE: 10
              SUSPECTS: 0
              ;***********************************************************************************************************************************************************************************
              PROTECTIONS
              Description Version Active Updated
              ;===================================================================================================================================================================================
              Kaspersky Anti-Virus 7.0.0.123 No Yes
              ;===================================================================================================================================================================================
              MALWARE
              Id Description Type Active Severity Disinfectable Disinfected Location
              ;===================================================================================================================================================================================
              00032731 application/mywebsearch HackTools No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
              00032731 application/mywebsearch HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44cf-8957-5838F569A31D}
              00032731 application/mywebsearch HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
              00032731 application/mywebsearch HackTools No 0 Yes No hkey_classes_root\clsid\{9afb8248-617f-460d-9366-d71cdeda3179}
              00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@doubleclick[1].txt
              00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@atdmt[1].txt
              00139535 Application/Processor HackTools No 0 Yes No C:\WINDOWS\system32\Process.exe
              00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@xiti[1].txt
              00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Application Data\Mozilla\Firefox\Profiles\s59lfeoj.default\cookies.txt[.xiti.com/]
              00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@serving-sys[2].txt
              00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@bs.serving-sys[2].txt
              00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@weborama[2].txt
              00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@advertising[2].txt
              00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\AGUESSE\Cookies\aguesse@smartadserver[2].txt
              ;===================================================================================================================================================================================
              SUSPECTS
              Location
              ;===================================================================================================================================================================================
              ;===================================================================================================================================================================================

              Merci
              0
              1. Contributeur sécurité
                bonsoir,

                * lance hijackthis puis coche et fixe cette ligne :

                O2 - BHO: (no name) - {D6ADA9A0-6A5E-48BA-BA3D-2DA2C51F1B57} - C:\WINDOWS\system32\mllji.dll (file missing)

                puis

                * Fait un scan antivirus en ligne Panda et copie colle le résultat ici
                https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                (avec Internet Explorer et désactive ton Antivirus pendant le scan)

                * tuto en image
                http://pageperso.aol.fr/loraline60/panda_scan.htm

                0
                1. Voilà mes 2 rapports

                  VundoFix V6.5.9

                  Checking Java version...

                  Java version is 1.5.0.10

                  Java version is 1.5.0.11

                  Scan started at 07:56:10 03/10/2007

                  Listing files found while scanning....

                  C:\windows\system32\hhkmp.bak1
                  C:\windows\system32\hhkmp.bak2
                  C:\windows\system32\hhkmp.ini
                  C:\windows\system32\jqyuxcxu.ini
                  C:\WINDOWS\system32\mdkbgxes.dll
                  C:\windows\system32\orqss.bak1
                  C:\windows\system32\orqss.bak2
                  C:\windows\system32\orqss.ini
                  C:\windows\system32\pmkhh.dll
                  C:\WINDOWS\system32\sexgbkdm.ini
                  C:\windows\system32\ssqro.dll
                  C:\windows\system32\uxcxuyqj.dll

                  Beginning removal...

                  Beginning removal...

                  Attempting to delete C:\windows\system32\hhkmp.bak1
                  C:\windows\system32\hhkmp.bak1 Has been deleted!

                  Attempting to delete C:\windows\system32\hhkmp.bak2
                  C:\windows\system32\hhkmp.bak2 Has been deleted!

                  Attempting to delete C:\windows\system32\hhkmp.ini
                  C:\windows\system32\hhkmp.ini Has been deleted!

                  Attempting to delete C:\windows\system32\jqyuxcxu.ini
                  C:\windows\system32\jqyuxcxu.ini Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\mdkbgxes.dll
                  C:\WINDOWS\system32\mdkbgxes.dll Could not be deleted.

                  Attempting to delete C:\windows\system32\orqss.bak1
                  C:\windows\system32\orqss.bak1 Has been deleted!

                  Attempting to delete C:\windows\system32\orqss.bak2
                  C:\windows\system32\orqss.bak2 Has been deleted!

                  Attempting to delete C:\windows\system32\orqss.ini
                  C:\windows\system32\orqss.ini Has been deleted!

                  Attempting to delete C:\windows\system32\pmkhh.dll
                  C:\windows\system32\pmkhh.dll Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\sexgbkdm.ini
                  C:\WINDOWS\system32\sexgbkdm.ini Has been deleted!

                  Attempting to delete C:\windows\system32\ssqro.dll
                  C:\windows\system32\ssqro.dll Has been deleted!

                  Attempting to delete C:\windows\system32\uxcxuyqj.dll
                  C:\windows\system32\uxcxuyqj.dll Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  VundoFix V6.5.9

                  Checking Java version...

                  Java version is 1.5.0.10

                  Java version is 1.5.0.11

                  Scan started at 08:05:05 03/10/2007

                  Listing files found while scanning....

                  No infected files were found.

                  VundoFix V6.5.9

                  Checking Java version...

                  Java version is 1.5.0.10

                  Java version is 1.5.0.11

                  Scan started at 08:29:27 12/10/2007

                  Listing files found while scanning....

                  C:\WINDOWS\system32\carvvpam.dll
                  C:\windows\system32\ihbqxpox.ini
                  C:\WINDOWS\system32\mapvvrac.ini
                  C:\windows\system32\xopxqbhi.dll

                  Beginning removal...

                  Attempting to delete C:\WINDOWS\system32\carvvpam.dll
                  C:\WINDOWS\system32\carvvpam.dll Could not be deleted.

                  Attempting to delete C:\windows\system32\ihbqxpox.ini
                  C:\windows\system32\ihbqxpox.ini Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\mapvvrac.ini
                  C:\WINDOWS\system32\mapvvrac.ini Has been deleted!

                  Attempting to delete C:\windows\system32\xopxqbhi.dll
                  C:\windows\system32\xopxqbhi.dll Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  VundoFix V6.5.9

                  Checking Java version...

                  Java version is 1.5.0.10

                  Java version is 1.5.0.11

                  Scan started at 08:33:41 12/10/2007

                  Listing files found while scanning....

                  No infected files were found.

                  Beginning removal...

                  VundoFix V6.5.9

                  Checking Java version...

                  Java version is 1.5.0.10

                  Java version is 1.5.0.11

                  Scan started at 14:24:00 12/10/2007

                  Listing files found while scanning....

                  C:\WINDOWS\system32\akujogan.dll
                  C:\windows\system32\mswstr10.dll
                  C:\WINDOWS\system32\nagojuka.ini

                  Beginning removal...

                  Attempting to delete C:\WINDOWS\system32\akujogan.dll
                  C:\WINDOWS\system32\akujogan.dll Could not be deleted.

                  Attempting to delete C:\windows\system32\mswstr10.dll
                  C:\windows\system32\mswstr10.dll Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\nagojuka.ini
                  C:\WINDOWS\system32\nagojuka.ini Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  Beginning removal...

                  Attempting to delete C:\WINDOWS\system32\akujogan.dll
                  C:\WINDOWS\system32\akujogan.dll Has been deleted!

                  Attempting to delete C:\windows\system32\mswstr10.dll
                  C:\windows\system32\mswstr10.dll Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  Beginning removal...

                  Attempting to delete C:\WINDOWS\system32\mdkbgxes.dll
                  C:\WINDOWS\system32\mdkbgxes.dll Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  Beginning removal...

                  Attempting to delete C:\WINDOWS\system32\mllji.dll
                  C:\WINDOWS\system32\mllji.dll Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  VundoFix V6.5.9

                  Checking Java version...

                  Java version is 1.5.0.10

                  Java version is 1.5.0.11

                  Scan started at 18:41:59 17/10/2007

                  Listing files found while scanning....

                  No infected files were found.

                  Beginning removal...

                  VundoFix V6.5.9

                  Checking Java version...

                  Java version is 1.5.0.10

                  Java version is 1.5.0.11

                  Scan started at 18:46:12 17/10/2007

                  Listing files found while scanning....

                  No infected files were found.

                  Beginning removal...

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 19:08:58, on 17/10/2007
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\SearchIndexer.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\WINDOWS\system32\RunDLL32.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                  C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                  C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                  C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Logitech\SetPoint\KEM.exe
                  C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
                  C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                  C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
                  C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                  C:\WINDOWS\system32\SearchProtocolHost.exe
                  C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O2 - BHO: (no name) - {D6ADA9A0-6A5E-48BA-BA3D-2DA2C51F1B57} - C:\WINDOWS\system32\mllji.dll (file missing)
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                  O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                  O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                  O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                  O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                  O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
                  O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
                  O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                  O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
                  O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                  0
                  1. Contributeur sécurité
                    bonjour,

                    ok, c'est bon cela me suffit pour l'instant

                    poste les rapports vundo et hijackthis stp
                    0
                    1. J'ai recommencé en cliquant sur OTMoveIt.exe. J'ai collé dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved. C:\WINDOWS\system32\epctcsxj.dll
                      J'ai cliqué sur Movelt! Le résultat apparut dans Result est

                      File/Folder C:\WINDOWS\system32\epctcsxj.dll not found.

                      Created on 10/17/2007 07:50:33

                      et j'ai le msg "cannot create file C:\_OTMoveIt\MovedFiles\10172007_075448.log"

                      Est-ce que cela a un rapport au fait que je ne le trouve pas ?

                      A+
                      0
                      1. Contributeur sécurité
                        bonsoir,

                        laisse tomber la ligne que tu ne trouves pas

                        pour OTMoveIt, normalement tu devrais trouver le rapport
                        dans C, puis dans le dossier
                        C:\_OTMoveIt\MovedFiles.

                        0
                        1. Bonsoir,

                          J'ai fait en partie ce que tu m'as demandé. Mon 1er pb est que je ne trouve pas la ligne

                          O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\epctcsxj.dll",sitypnow

                          Mon 2ème pb est que sur OTMovelt je ne sais pas où trouver

                          C:\\\_OTMoveIt\MovedFiles.

                          Help
                          0
                          1. Contributeur sécurité
                            on continue sur celui ci de post.

                            * désactive le résident de spybot
                            clic droit sur l'icone (à côté de l'horloge) du résident, puis quitter le résident.

                            ensuite

                            * Relance Vundofix
                            * Ne clique pas sur "Scan for a vundo"
                            * Clique droit au milieu de la fenêtre
                            * Clique sur Add more files ?
                            * Copie/colle le fichier ci-dessous :

                            C:\WINDOWS\system32\mllji.dll

                            * Clique sur Add files
                            * Ensuite clique sur Close Windows
                            * Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaitre dans la fenêtre principale)
                            * Si l'outils demande un redémarrage, accepte
                            * Poste le rapport Vundofix

                            puis

                            * lance hijackthis puis coche ces lignes :

                            O2 - BHO: (no name) - {080B98D0-2D30-4D17-A435-DFC5002A25B9} - (no file)
                            O2 - BHO: (no name) - {20B70D8A-A71A-404E-88F8-AC47426F004A} - (no file)
                            O2 - BHO: (no name) - {330D348A-0201-4935-8823-25F5D6D237BA} - (no file)
                            O2 - BHO: (no name) - {36D2931D-6607-4674-A1F0-ADCF5B49B880} - (no file)
                            O2 - BHO: (no name) - {4C7A882F-BA53-474B-B73A-159CDB5EDB01} - (no file)
                            O2 - BHO: (no name) - {4D711114-978F-40EB-884A-3A30FBDADD79} - (no file)
                            O2 - BHO: (no name) - {4EECA7FC-AC15-43D1-B499-5805428D4AD7} - (no file)
                            O2 - BHO: (no name) - {5B85E697-A87C-4BA9-896C-93B8A58B7180} - C:\WINDOWS\system32\mllji.dll
                            O2 - BHO: (no name) - {7D4450AB-A000-426E-B923-45B3003D92B9} - (no file)
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O2 - BHO: (no name) - {8A879199-9F43-4F90-AD1C-A642E5704E28} - C:\WINDOWS\system32\mljgd.dll (file missing)
                            O2 - BHO: (no name) - {8EEF3E73-E004-4B21-B966-3E0D455C1656} - (no file)
                            O2 - BHO: (no name) - {8F545755-1512-4C73-B539-CDAD49C31CE7} - (no file)
                            O2 - BHO: (no name) - {961E3A9E-F964-4583-8A4E-4FFB67C734F0} - (no file)
                            O2 - BHO: (no name) - {966B5B0C-B38E-404D-8F7B-58870F164DD8} - (no file)
                            O2 - BHO: (no name) - {9673FC4C-F20E-4F8F-9B66-3B8C60008089} - (no file)
                            O2 - BHO: (no name) - {9AF31604-F5D0-4D3F-AC62-450734D230BE} - (no file)
                            O2 - BHO: (no name) - {ADED34D6-3316-4A3A-8B25-25BDE5A6A867} - (no file)
                            O2 - BHO: (no name) - {B30CA938-866C-4C78-B354-F38B726C1C20} - (no file)
                            O2 - BHO: (no name) - {B63AF71A-ABDB-4E65-9A5E-C31995151FF8} - (no file)
                            O2 - BHO: (no name) - {BB0E6747-7324-478E-9E51-4A16AD6604ED} - (no file)
                            O2 - BHO: (no name) - {BF942B28-B5B8-4910-A9AB-D64CC44A99F2} - (no file)
                            O2 - BHO: (no name) - {D5C23C31-3C9E-44BA-A62C-59B0DDAA58E8} - (no file)
                            O2 - BHO: (no name) - {D7E8DC20-29B3-435B-B949-7EF93740EEBA} - (no file)
                            O2 - BHO: (no name) - {E7E890F0-6C73-4A50-8D1D-0AEDDD90A2CA} - (no file)
                            O2 - BHO: (no name) - {F619794D-B14A-42F4-89BB-25EB2A6F0A99} - C:\WINDOWS\system32\pmkhi.dll (file missing)
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\epctcsxj.dll",sitypnow
                            O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                            O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

                            * toutes applications fermées et hors connexion, clique sur "fix checked"

                            Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.
                            http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                            double-clique sur OTMoveIt.exe pour le lancer.
                            copie la ligne qui se trouve en citation ci-dessous,
                            et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
                            C:\WINDOWS\system32\epctcsxj.dll


                            clique sur MoveIt! pour lancer la suppression.
                            le résultat apparaitra dans le cadre Results.
                            clique sur Exit pour fermer.
                            poste le rapport situé dans C:\\\_OTMoveIt\MovedFiles.

                            il te sera peut-être demander de redémarrer le pc pour achever la suppression.
                            si c'est le cas accepte par Yes.

                            reviens avec le rapport vundo, otmoveit, et un nouveau rapport hijackthis

                            0
                            1. Contributeur sécurité
                              OK

                              alors si tu es toujours là, je regarde les rapports, et je reviens
                              0
                              1. Oui, je suis toujours là, mais je ne sais pas trop comme ça marche le forum de "comment ça marche", j'ai du faire une erreur.
                                0
                                1. Contributeur sécurité
                                  bonjour

                                  tu as 2 sujets pour le même problème, je t'ai d'ailleurs répondu sur les 2
                                  je préfèrerais continuer sur celui ci

                                  es tu encore là ?

                                  0
                                  1. Bonjour,

                                    Voici mon nouveau rapport hijakthis

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 10:53:02, on 14/10/2007
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\SearchIndexer.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\wscntfy.exe
                                    C:\WINDOWS\system32\RunDLL32.exe
                                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                                    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                                    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                                    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                                    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                                    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\Messenger\msmsgs.exe
                                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                    C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                    C:\Program Files\Logitech\SetPoint\KEM.exe
                                    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
                                    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                    C:\Program Files\WinZip\WZQKPICK.EXE
                                    C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                                    C:\WINDOWS\system32\SearchProtocolHost.exe
                                    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\WINDOWS\system32\HPZipm12.exe
                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: (no name) - {080B98D0-2D30-4D17-A435-DFC5002A25B9} - (no file)
                                    O2 - BHO: (no name) - {20B70D8A-A71A-404E-88F8-AC47426F004A} - (no file)
                                    O2 - BHO: (no name) - {330D348A-0201-4935-8823-25F5D6D237BA} - (no file)
                                    O2 - BHO: (no name) - {36D2931D-6607-4674-A1F0-ADCF5B49B880} - (no file)
                                    O2 - BHO: (no name) - {4C7A882F-BA53-474B-B73A-159CDB5EDB01} - (no file)
                                    O2 - BHO: (no name) - {4D711114-978F-40EB-884A-3A30FBDADD79} - (no file)
                                    O2 - BHO: (no name) - {4EECA7FC-AC15-43D1-B499-5805428D4AD7} - (no file)
                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: (no name) - {5B85E697-A87C-4BA9-896C-93B8A58B7180} - C:\WINDOWS\system32\mllji.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                    O2 - BHO: (no name) - {7D4450AB-A000-426E-B923-45B3003D92B9} - (no file)
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: (no name) - {8A879199-9F43-4F90-AD1C-A642E5704E28} - C:\WINDOWS\system32\mljgd.dll (file missing)
                                    O2 - BHO: (no name) - {8EEF3E73-E004-4B21-B966-3E0D455C1656} - (no file)
                                    O2 - BHO: (no name) - {8F545755-1512-4C73-B539-CDAD49C31CE7} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: (no name) - {961E3A9E-F964-4583-8A4E-4FFB67C734F0} - (no file)
                                    O2 - BHO: (no name) - {966B5B0C-B38E-404D-8F7B-58870F164DD8} - (no file)
                                    O2 - BHO: (no name) - {9673FC4C-F20E-4F8F-9B66-3B8C60008089} - (no file)
                                    O2 - BHO: (no name) - {9AF31604-F5D0-4D3F-AC62-450734D230BE} - (no file)
                                    O2 - BHO: (no name) - {ADED34D6-3316-4A3A-8B25-25BDE5A6A867} - (no file)
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                                    O2 - BHO: (no name) - {B30CA938-866C-4C78-B354-F38B726C1C20} - (no file)
                                    O2 - BHO: (no name) - {B63AF71A-ABDB-4E65-9A5E-C31995151FF8} - (no file)
                                    O2 - BHO: (no name) - {BB0E6747-7324-478E-9E51-4A16AD6604ED} - (no file)
                                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O2 - BHO: (no name) - {BF942B28-B5B8-4910-A9AB-D64CC44A99F2} - (no file)
                                    O2 - BHO: (no name) - {D5C23C31-3C9E-44BA-A62C-59B0DDAA58E8} - (no file)
                                    O2 - BHO: (no name) - {D7E8DC20-29B3-435B-B949-7EF93740EEBA} - (no file)
                                    O2 - BHO: (no name) - {E7E890F0-6C73-4A50-8D1D-0AEDDD90A2CA} - (no file)
                                    O2 - BHO: (no name) - {F619794D-B14A-42F4-89BB-25EB2A6F0A99} - C:\WINDOWS\system32\pmkhi.dll (file missing)
                                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                                    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                                    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
                                    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
                                    O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\epctcsxj.dll",sitypnow
                                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                                    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
                                    O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
                                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                    O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                    O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
                                    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
                                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                                    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
                                    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                    O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                                    0
                                    1. Contributeur sécurité
                                      bonsoir,

                                      pas mal :)

                                      peux tu reposter un nouveau rapport hijackthis stp

                                      0