r@in | b0w a écrit:Fais [Ctrl]+[Alt]+[Suppr] et lances une nouvelle tâche, explorer.exe.
C:WINDOWSsystem32cbXPfGww.dll
Almost done... This window will close in a short while
Please wait a few seconds for the report log to pop up
ComboFix's log shall be located at C:ComboFix.txt
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:WINDOWSsystem32cbXPfGww.dll
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-20 18:19:02
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
C:WINDOWSsystem32wwGfPXbc.ini 538828 bytes
C:WINDOWSsystem32wwGfPXbc.ini2 538828 bytes
Scan terminé avec succès
Fichiers cachés: 2
r@in | b0w a écrit:Tu télécharges Gmer en version .ZIP que tu décompresses ensuite sur le Bureau.
Tu double-cliques sur l'icône Gmer.exe pour le lancer.
Tu cliques ensuite sur l'onglet Rootkit puis sur Scan pour démarrer l'analyse.
Si Gmer trouve un rootkit, il affichera la ligne en rouge.
Tu cliques droit sur la ligne puis sur Kill the process si cette option est disponible puis dans tous les cas tu cliques droit sur Delete the service pour supprimer le rootkit.
Si tu hésites ou que tu veux une confirmation sur les suppressions, tu suis ces deux tutoriaux:
_ le guide pour faire une impression écran;
_ comment l'héberger sur internet.
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1316
Windows 5.1.2600 Service Pack 2
25/10/2008 12:33:05
mbam-log-2008-10-25 (12-33-05).txt
Type de recherche: Examen complet (C:|D:|G:|I:|)
Eléments examinés: 231177
Temps écoulé: 1 hour(s), 44 minute(s), 40 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 4
Clé(s) du Registre infectée(s): 9
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 46
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:WINDOWSsystem32iocltubb.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32
xbsqz.dll (Trojan.Vundo) -> Delete on reboot.
C:WINDOWSsystem32abdqsj.dll (Trojan.Vundo) -> Delete on reboot.
C:WINDOWSsystem32ostjzt.dll (Trojan.Vundo) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOTCLSID{8dadf436-50ec-4c86-8c4a-eed0c831d16f} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{c4c8033f-6a8a-4895-aa57-10eaad4b11d0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{8555ffec-5e83-407c-a760-379133d08784} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftMS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftcontim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftMS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoft dfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftFCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:WINDOWSsystem32iocltubb.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32butlcoi.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32mdlsdrxn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32
xrdsldm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32sbiwdosd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32dsodwibs.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32ucbfvcdw.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32wdcvfbcu.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32wljxqmpq.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32qpmqxjlw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32
xbsqz.dll (Trojan.Vundo) -> Delete on reboot.
C:WINDOWSsystem32abdqsj.dll (Trojan.Vundo) -> Delete on reboot.
C:WINDOWSsystem32ostjzt.dll (Trojan.Vundo) -> Delete on reboot.
C:!KillBoxcbXPfGww.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:!KillBoxcbXPfGww.dll( 1) (Trojan.Vundo) -> Quarantined and deleted successfully.
C:Documents and SettingsSebLocal SettingsTemporary Internet FilesContent.IE5JBDQTDJSupd105320[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32bgffd.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32dsilrrm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32pffuq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32cggpodpo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32ctyowysm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32dledgibq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32exxbqr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32fbvocbmg.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32fjyfol.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32fysicwyc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32jprybz.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32kxufqh.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32
huwbgwh.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32
ijjdjua.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32oxgyykli.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32oxpvgw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32pmnlmkHY.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32 glmrn.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32svenixfx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32 xhjbl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32wpgcwstv.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32wpsdslbx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32xcdvlkpw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32xyonvrjt.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:QooboxQuarantineCWINDOWSsystem32zrfwwg.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:System Volume Information\_restore{BC7EC9A3-B774-49C7-A188-7C4C1A4E0569}RP475A0162388.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSsystem32amgrdlhk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSsystem32okiadrkk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSsystem32 rz2.tmp (Trojan.Vundo) -> Delete on reboot.
C:WINDOWSsystem32ygpfejjr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 5 invités
.: Nous contacter :: Flux RSS :: Données personnelles :. |