Re,
Ci-dessous les deux rapports :
Je n'ai pas réussi à renommer Hijackthis en scanvundo.exe car je ne dispose que de 5 secondes maxi avant que tout disparaisse de mon écran à chaque fois. Y aurait-il une autre astuce ?
En fait, les différents les virus réappraraissent dès qu'ils sont détruits. et les fichiers détruits par Vundo sont de nouveau présents.
J'ai mis à jour Java.
Cordialement.
Jacques
Rapport de VirtumundoBeGone :
[01/09/2008, 14:11:21] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\jean-jacques\Bureau\VirtumundoBeGone.exe" )
[01/09/2008, 14:11:49] - Detected System Information:
[01/09/2008, 14:11:49] - Windows Version: 5.1.2600, Service Pack 2
[01/09/2008, 14:11:49] - Current Username: jean-jacques (Admin)
[01/09/2008, 14:11:49] - Windows is in NORMAL mode.
[01/09/2008, 14:11:49] - Searching for Browser Helper Objects:
[01/09/2008, 14:11:49] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[01/09/2008, 14:11:49] - BHO 2: {3049C3E9-B461-4BC5-8870-4C09146192CA} (RealPlayer Download and Record Plugin for Internet Explorer)
[01/09/2008, 14:11:49] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[01/09/2008, 14:11:49] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/09/2008, 14:11:49] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[01/09/2008, 14:11:49] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[01/09/2008, 14:11:49] - BHO 4: {549B5CA7-4A86-11D7-A4DF-000874180BB3} ()
[01/09/2008, 14:11:49] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/09/2008, 14:11:49] - No filename found. Continuing.
[01/09/2008, 14:11:49] - BHO 5: {5A88849F-F3F2-419D-A206-4500D0AA9E7C} ()
[01/09/2008, 14:11:49] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/09/2008, 14:11:49] - Checking for HKLM\...\Winlogon\Notify\ddayw
[01/09/2008, 14:11:49] - Key not found: HKLM\...\Winlogon\Notify\ddayw, continuing.
[01/09/2008, 14:11:49] - BHO 6: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[01/09/2008, 14:11:49] - BHO 7: {64F56FC1-1272-44CD-BA6E-39723696E350} (EoBho Class)
[01/09/2008, 14:11:49] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[01/09/2008, 14:11:49] - BHO 9: {AB3D8B79-97F6-4158-9AA5-2123CA6FBF26} ()
[01/09/2008, 14:11:49] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/09/2008, 14:11:49] - Checking for HKLM\...\Winlogon\Notify\geede
[01/09/2008, 14:11:49] - Key not found: HKLM\...\Winlogon\Notify\geede, continuing.
[01/09/2008, 14:11:49] - BHO 10: {CBFA0E8E-7489-4A16-8D6E-0D58BFFB6134} ()
[01/09/2008, 14:11:50] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/09/2008, 14:11:50] - Checking for HKLM\...\Winlogon\Notify\ssqnmll
[01/09/2008, 14:11:50] - Key not found: HKLM\...\Winlogon\Notify\ssqnmll, continuing.
[01/09/2008, 14:11:50] - BHO 11: {EA6E0C1F-4858-4BF3-9ED6-496E17252744} ()
[01/09/2008, 14:11:50] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/09/2008, 14:11:50] - Checking for HKLM\...\Winlogon\Notify\gebyy
[01/09/2008, 14:11:50] - Key not found: HKLM\...\Winlogon\Notify\gebyy, continuing.
[01/09/2008, 14:11:50] - BHO 12: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} ()
[01/09/2008, 14:11:50] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/09/2008, 14:11:50] - No filename found. Continuing.
[01/09/2008, 14:11:50] - Finished Searching Browser Helper Objects
[01/09/2008, 14:11:50] - Finishing up...
[01/09/2008, 14:11:50] - Nothing found! Exiting...
Et celui de Hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:40:42, on 09/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Harrap's Multimédia\Shorter\bin\HiHarrapsTray.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\explorer.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.free.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [Mobipocket Web Companion] C:\Program Files\Fichiers communs\Mobipocket Shared\webcomp.exe -m
O4 - HKCU\..\Run: [E06FXLRD_7795437] "C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [Mobipocket Reader Notifications] C:\Program Files\Mobipocket.com\Mobipocket Reader\readernotify.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - Global Startup: Ask Harrap's Shorter.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.univ-lyon3.fr
O15 - Trusted IP range: 127.0.0.1
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ad.univ-lyon3.fr
O17 - HKLM\Software\..\Telephony: DomainName = ad.univ-lyon3.fr
O17 - HKLM\System\CCS\Services\Tcpip\..\{428793EB-6876-454F-98C2-E920E3923822}: Domain = ad.univ-lyon3.fr
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ad.univ-lyon3.fr
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = 192.168.47.212
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ad.univ-lyon3.fr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = 192.168.47.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = 192.168.47.212
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
End of file - 8197 bytes