Re-bonjour Salwa5,
voici les rapports, j'ai encore Avast qui bloque DCOM exploit même si peu à peu cela devient propre grâce à toi,
[01/24/2007, 14:14:52] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Nico\Bureau\VirtumundoBeGone.exe" )
[01/24/2007, 14:15:01] - Detected System Information:
[01/24/2007, 14:15:01] - Windows Version: 5.1.2600,
[01/24/2007, 14:15:01] - Current Username: Nico (Admin)
[01/24/2007, 14:15:01] - Windows is in NORMAL mode.
[01/24/2007, 14:15:01] - Searching for Browser Helper Objects:
[01/24/2007, 14:15:03] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/24/2007, 14:15:03] - BHO 2: {3F76AA99-A45C-4635-8FE9-A6D186F46471} ()
[01/24/2007, 14:15:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/24/2007, 14:15:03] - Checking for HKLM\...\Winlogon\Notify\wvutrro
[01/24/2007, 14:15:03] - Found: HKLM\...\Winlogon\Notify\wvutrro - This is probably Virtumundo.
[01/24/2007, 14:15:03] - Assigning {3F76AA99-A45C-4635-8FE9-A6D186F46471} MSEvents Object
[01/24/2007, 14:15:03] - BHO list has been changed! Starting over...
[01/24/2007, 14:15:03] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/24/2007, 14:15:03] - BHO 2: {3F76AA99-A45C-4635-8FE9-A6D186F46471} (MSEvents Object)
[01/24/2007, 14:15:03] - ALERT: Found MSEvents Object!
[01/24/2007, 14:15:03] - BHO 3: {5A53333A-1455-4107-A46B-F316527F5601} ()
[01/24/2007, 14:15:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/24/2007, 14:15:03] - Checking for HKLM\...\Winlogon\Notify\iifcb
[01/24/2007, 14:15:03] - Found: HKLM\...\Winlogon\Notify\iifcb - This is probably Virtumundo.
[01/24/2007, 14:15:03] - Assigning {5A53333A-1455-4107-A46B-F316527F5601} MSEvents Object
[01/24/2007, 14:15:03] - BHO list has been changed! Starting over...
[01/24/2007, 14:15:03] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/24/2007, 14:15:03] - BHO 2: {3F76AA99-A45C-4635-8FE9-A6D186F46471} (MSEvents Object)
[01/24/2007, 14:15:03] - ALERT: Found MSEvents Object!
[01/24/2007, 14:15:03] - BHO 3: {5A53333A-1455-4107-A46B-F316527F5601} (MSEvents Object)
[01/24/2007, 14:15:03] - ALERT: Found MSEvents Object!
[01/24/2007, 14:15:03] - BHO 4: {682BA437-2ACD-4E69-A403-A098B1B75D95} ()
[01/24/2007, 14:15:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/24/2007, 14:15:03] - No filename found. Continuing.
[01/24/2007, 14:15:04] - BHO 5: {7DA39570-5FD2-4f18-94B4-20730CB3F727} ()
[01/24/2007, 14:15:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/24/2007, 14:15:04] - No filename found. Continuing.
[01/24/2007, 14:15:04] - BHO 6: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[01/24/2007, 14:15:04] - Finished Searching Browser Helper Objects
[01/24/2007, 14:15:04] - *** Detected MSEvents Object
[01/24/2007, 14:15:04] - Trying to remove MSEvents Object...
[01/24/2007, 14:15:05] - Terminating Process: IEXPLORE.EXE
[01/24/2007, 14:15:05] - Terminating Process: RUNDLL32.EXE
[01/24/2007, 14:15:06] - Disabling Automatic Shell Restart
[01/24/2007, 14:15:06] - Terminating Process: EXPLORER.EXE
[01/24/2007, 14:15:07] - Suspending the NT Session Manager System Service
[01/24/2007, 14:15:07] - Terminating Windows NT Logon/Logoff Manager
[01/24/2007, 14:15:11] - Re-enabling Automatic Shell Restart
[01/24/2007, 14:15:11] - File to disable: C:\WINDOWS\System32\wvutrro.dll
[01/24/2007, 14:15:11] - Renaming C:\WINDOWS\System32\wvutrro.dll -> C:\WINDOWS\System32\wvutrro.dll.vir
[01/24/2007, 14:15:11] - File successfully renamed!
[01/24/2007, 14:15:11] - Removing HKLM\...\Browser Helper Objects\{3F76AA99-A45C-4635-8FE9-A6D186F46471}
[01/24/2007, 14:15:11] - Removing HKCR\CLSID\{3F76AA99-A45C-4635-8FE9-A6D186F46471}
[01/24/2007, 14:15:11] - Adding Kill Bit for ActiveX for GUID: {3F76AA99-A45C-4635-8FE9-A6D186F46471}
[01/24/2007, 14:15:11] - Deleting ATLEvents/MSEvents Registry entries
[01/24/2007, 14:15:11] - Removing HKLM\...\Winlogon\Notify\wvutrro
[01/24/2007, 14:15:11] - Searching for Browser Helper Objects:
[01/24/2007, 14:15:11] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/24/2007, 14:15:11] - BHO 2: {5A53333A-1455-4107-A46B-F316527F5601} (MSEvents Object)
[01/24/2007, 14:15:11] - ALERT: Found MSEvents Object!
[01/24/2007, 14:15:11] - BHO 3: {682BA437-2ACD-4E69-A403-A098B1B75D95} ()
[01/24/2007, 14:15:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/24/2007, 14:15:11] - No filename found. Continuing.
[01/24/2007, 14:15:11] - BHO 4: {7DA39570-5FD2-4f18-94B4-20730CB3F727} ()
[01/24/2007, 14:15:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/24/2007, 14:15:11] - No filename found. Continuing.
[01/24/2007, 14:15:12] - BHO 5: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[01/24/2007, 14:15:12] - Finished Searching Browser Helper Objects
[01/24/2007, 14:15:12] - *** Detected MSEvents Object
[01/24/2007, 14:15:12] - Trying to remove MSEvents Object...
[01/24/2007, 14:15:13] - Terminating Process: IEXPLORE.EXE
[01/24/2007, 14:15:13] - Terminating Process: RUNDLL32.EXE
[01/24/2007, 14:15:13] - Disabling Automatic Shell Restart
[01/24/2007, 14:15:13] - Terminating Process: EXPLORER.EXE
[01/24/2007, 14:15:13] - Suspending the NT Session Manager System Service
[01/24/2007, 14:15:13] - Terminating Windows NT Logon/Logoff Manager
[01/24/2007, 14:15:14] - Re-enabling Automatic Shell Restart
[01/24/2007, 14:15:14] - File to disable: C:\WINDOWS\System32\iifcb.dll
[01/24/2007, 14:15:14] - Renaming C:\WINDOWS\System32\iifcb.dll -> C:\WINDOWS\System32\iifcb.dll.vir
[01/24/2007, 14:15:14] - File successfully renamed!
[01/24/2007, 14:15:14] - Removing HKLM\...\Browser Helper Objects\{5A53333A-1455-4107-A46B-F316527F5601}
[01/24/2007, 14:15:14] - Removing HKCR\CLSID\{5A53333A-1455-4107-A46B-F316527F5601}
[01/24/2007, 14:15:14] - Adding Kill Bit for ActiveX for GUID: {5A53333A-1455-4107-A46B-F316527F5601}
[01/24/2007, 14:15:14] - Deleting ATLEvents/MSEvents Registry entries
[01/24/2007, 14:15:14] - Removing HKLM\...\Winlogon\Notify\iifcb
[01/24/2007, 14:15:14] - Searching for Browser Helper Objects:
[01/24/2007, 14:15:14] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/24/2007, 14:15:14] - BHO 2: {682BA437-2ACD-4E69-A403-A098B1B75D95} ()
[01/24/2007, 14:15:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/24/2007, 14:15:14] - No filename found. Continuing.
[01/24/2007, 14:15:14] - BHO 3: {7DA39570-5FD2-4f18-94B4-20730CB3F727} ()
[01/24/2007, 14:15:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/24/2007, 14:15:14] - No filename found. Continuing.
[01/24/2007, 14:15:14] - BHO 4: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[01/24/2007, 14:15:14] - Finished Searching Browser Helper Objects
[01/24/2007, 14:15:14] - Finishing up...
[01/24/2007, 14:15:14] - A restart is needed.
[01/24/2007, 14:15:31] - Attempting to Restart via STOP error (Blue Screen!)
et le Hijackthis!
Logfile of HijackThis v1.99.1
Scan saved at 14:19:54, on 24/01/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.
EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\mozilla.org\Mozilla\Mozilla.exe
C:\Program Files\Adobe\Acrobat
7.0\Reader\reader_sl.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\oodag.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil
Software\Avast4\setup\avast.setup
C:\Documents and Settings\Nico\Bureau\oijfxd.exe
R1 - HKCU\Software\Microsoft\Internet Connection
Wizard,ShellNext =
http://windowsupdate.microsoft.com/
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Intern
et Settings,ProxyServer = proxy.free.fr:3128
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) -
{682BA437-2ACD-4E69-A403-A098B1B75D95} - (no file)
O2 - BHO: (no name) -
{7DA39570-5FD2-4f18-94B4-20730CB3F727} - (no file)
O2 - BHO: EpsonToolBandKicker Class -
{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program
Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page -
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program
Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SmcService]
C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.
EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB002" /M
"Stylus DX3800"
O4 - HKLM\..\Run: [avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [UserFaultCheck]
%systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE]
C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program
Files\mozilla.org\Mozilla\Mozilla.exe" -turbo
O4 - HKCU\..\Run: [BitTorrent] "C:\Program
Files\BitTorrent\bittorrent.exe"
--force_start_minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program
Files\Fichiers communs\Adobe\Calibration\Adobe Gamma
Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe
Reader.lnk = C:\Program Files\Adobe\Acrobat
7.0\Reader\reader_sl.exe
O4 - Global Startup: LG Sync Manager.lnk = ?
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk =
C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft
Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O18 - Protocol: livecall -
{828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim -
{828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: nnlif -
C:\WINDOWS\System32\nnlif.dll (file missing)
O20 - Winlogon Notify: WBSrv - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems -
C:\Program Files\Fichiers communs\Adobe Systems
Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service
(aswUpdSv) - Unknown owner - C:\Program Files\Alwil
Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner -
C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner -
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe"
/service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner -
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe"
/service (file missing)
O23 - Service: Creative Service for CDROM Access -
Creative Technology Ltd -
C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: O&O Defrag - O&O Software GmbH -
C:\WINDOWS\System32\oodag.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel,
Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Sygate Personal Firewall (SmcService)
- Sygate Technologies, Inc. - C:\Program
Files\Sygate\SPF\smc.exe
Merci, à plus