Gros probleme! virtumonde

Fermé
link - 6 sept. 2008 à 15:52
plm69 Messages postés 527 Date d'inscription dimanche 27 juillet 2008 Statut Membre Dernière intervention 8 septembre 2008 - 6 sept. 2008 à 18:56
Bonjour,
Voila, je sais que ça été posté plusieurs fois mais je me sens perdu sur la procédure à suivre pour supprimer ce spyware...

En effet, une fois que j'ai fait un scan avec hijackthis je ne sais pas quoi faire, si certain d'entre vous peuvent m'aider je leurs en serait grandement reconnaissant.

Merci d'avance

27 réponses

plm69 Messages postés 527 Date d'inscription dimanche 27 juillet 2008 Statut Membre Dernière intervention 8 septembre 2008 17
6 sept. 2008 à 18:20
oui supprime tout le temps
0
ca va mettre un temps long donc tes pas obligé de rester !!!

Merci énormément pour ton aide, sincèrement !!

PS: à 5.5% il m'a déjà fait 6 détections :/
0
plm69 Messages postés 527 Date d'inscription dimanche 27 juillet 2008 Statut Membre Dernière intervention 8 septembre 2008 17
6 sept. 2008 à 18:27
je reste car j'aide aussi des gens ici^^ poste le rapport a la fin du scan ici
0
Avira AntiVir Personal
Report file date: samedi 6 septembre 2008 18:12

Scanning for 1599979 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: LINK

Version information:
BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
ANTIVIR2.VDF : 7.0.6.94 2998784 Bytes 31/08/2008 15:51:14
ANTIVIR3.VDF : 7.0.6.124 202240 Bytes 05/09/2008 15:51:15
Engineversion : 8.1.1.28
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.70 319866 Bytes 06/09/2008 15:51:21
AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:49
AERDL.DLL : 8.1.1.1 397683 Bytes 06/09/2008 15:51:20
AEPACK.DLL : 8.1.2.1 364917 Bytes 15/07/2008 12:58:35
AEOFFICE.DLL : 8.1.0.23 196987 Bytes 06/09/2008 15:51:19
AEHEUR.DLL : 8.1.0.51 1397111 Bytes 06/09/2008 15:51:19
AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:48
AEGEN.DLL : 8.1.0.36 315764 Bytes 06/09/2008 15:51:17
AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:21
AECORE.DLL : 8.1.1.11 172406 Bytes 06/09/2008 15:51:16
AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:48
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 06/09/2008 15:51:16
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, E:, F:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: samedi 6 septembre 2008 18:12

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'OSE.EXE' - '1' Module(s) have been scanned
Scan process 'DiskCleaner.exe' - '1' Module(s) have been scanned
Scan process 'RegistryCleaner.exe' - '1' Module(s) have been scanned
Scan process 'SystemOptimizer.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'ADSL Autoconnect.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'StarWindService.exe' - '1' Module(s) have been scanned
Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'DkService.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'AOLacsd.exe' - '1' Module(s) have been scanned
Scan process 'schedul2.exe' - '1' Module(s) have been scanned
Scan process 'companion.exe' - '1' Module(s) have been scanned
Scan process 'aoltray.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'QTTask.exe' - '1' Module(s) have been scanned
Scan process 'schedhlp.exe' - '1' Module(s) have been scanned
Scan process 'TrueImageMonitor.exe' - '1' Module(s) have been scanned
Scan process 'AOLDial.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'smax4pnp.exe' - '1' Module(s) have been scanned
Scan process 'dragdiag.exe' - '1' Module(s) have been scanned
Scan process 'StartMessager.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'wfsjcbcb.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
52 processes with 52 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'E:\'
[INFO] No virus was found!
Boot sector 'F:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '66' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Christophe\loads.exe
[DETECTION] Is the TR/Crypt.XDR.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\Christophe\Local Settings\temp\5.tmp
[DETECTION] Is the TR/Crypt.QV Trojan
[NOTE] The file was deleted!
C:\Program Files\TuneUp Utilities 2006\SDShelEx.dll
[DETECTION] Is the TR/Muldrop.6045.A Trojan
[NOTE] The file was deleted!
C:\Programmes Christophe\Winrar\WinRAR.v3.51.WinALL.Cracked-CORE.zip
[0] Archive type: ZIP
--> crack.exe
[DETECTION] Is the TR/Crypt.FSPM.Gen Trojan
[NOTE] The file was deleted!
C:\System Volume Information\_restore{A152F389-7C48-4C18-9BFC-645775CCBE61}\RP134\A0048259.exe
[DETECTION] Is the TR/Crypt.XDR.Gen Trojan
[NOTE] The file was deleted!
C:\System Volume Information\_restore{A152F389-7C48-4C18-9BFC-645775CCBE61}\RP134\A0048260.dll
[DETECTION] Is the TR/Muldrop.6045.A Trojan
[NOTE] The file was deleted!
C:\WINDOWS\system32\netd.dll
[DETECTION] Is the TR/Dldr.Small.acsk Trojan
[NOTE] The file was deleted!
C:\WINDOWS\system32\protect.dll
[DETECTION] Is the TR/Crypt.QV Trojan
[NOTE] The file was deleted!
C:\WINDOWS\system32\ptco.dll
[DETECTION] Is the TR/Dldr.Small.acvi Trojan
[NOTE] The file was deleted!
Begin scan in 'E:\' <Multimédias>
Begin scan in 'F:\' <Jeux>


End of the scan: samedi 6 septembre 2008 18:44
Used time: 32:07 Minute(s)

The scan has been done completely.

6671 Scanning directories
302992 Files were scanned
9 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
9 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
302982 Files not concerned
1602 Archives were scanned
1 Warnings
9 Notes
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
plm69 Messages postés 527 Date d'inscription dimanche 27 juillet 2008 Statut Membre Dernière intervention 8 septembre 2008 17
6 sept. 2008 à 18:50
ok coment çava de ton coté ?
0
J'ai juste un petit rhume, sinon ca va !

Non sérieusement tous est nickel.

Dois je configurer quelque chose pour le coupe feu ??
0
plm69 Messages postés 527 Date d'inscription dimanche 27 juillet 2008 Statut Membre Dernière intervention 8 septembre 2008 17
6 sept. 2008 à 18:56
Non laisse comme c'est. Met le topic en résolu si plus de problèmes.

a+
0