Bon ba je croit qu'on lui a cassé la guel à mr. vundo ( comme tu le dit notre pote navifix à été tres aimable de le balancer!!!!)
Remarque: lors du scan avec Vundo fix il n'arrive pas à supprimer Bixurol.dll ( preciser dans le rapport )
RAPPORT VUNDOFIX:
VundoFix V6.7.7
Checking Java version...
Sun Java not detected
Scan started at 19:54:53 31/01/2008
Listing files found while scanning....
C:\Program Files\Fichiers communs\Mediafour\MacDriveiTunesPatch.dll
C:\WINDOWS\system32\byxurol.dll
C:\WINDOWS\system32\ddccayv.dll
C:\WINDOWS\system32\ijllm.ini
C:\WINDOWS\system32\ijllm.ini2
C:\WINDOWS\system32\mllji.dll
C:\WINDOWS\system32\opnljjj.dll
Beginning removal...
Attempting to delete C:\Program Files\Fichiers communs\Mediafour\MacDriveiTunesPatch.dll
C:\Program Files\Fichiers communs\Mediafour\MacDriveiTunesPatch.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\byxurol.dll
C:\WINDOWS\system32\byxurol.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\ddccayv.dll
C:\WINDOWS\system32\ddccayv.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ijllm.ini
C:\WINDOWS\system32\ijllm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ijllm.ini2
C:\WINDOWS\system32\ijllm.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\mllji.dll
C:\WINDOWS\system32\mllji.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\opnljjj.dll
C:\WINDOWS\system32\opnljjj.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\byxurol.dll
C:\WINDOWS\system32\byxurol.dll Could not be deleted.
Performing Repairs to the registry.
Done!
VundoFix V6.7.7
Checking Java version...
Sun Java not detected
Scan started at 20:10:49 31/01/2008
Listing files found while scanning....
C:\Program Files\Fichiers communs\Mediafour\MacDriveiTunesPatch.dll
C:\WINDOWS\system32\byxurol.dll
C:\WINDOWS\system32\mllmn.dll
C:\WINDOWS\system32\nmllm.ini
C:\WINDOWS\system32\nmllm.ini2
Beginning removal...
Attempting to delete C:\WINDOWS\system32\byxurol.dll
C:\WINDOWS\system32\byxurol.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\mllmn.dll
C:\WINDOWS\system32\mllmn.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\nmllm.ini
C:\WINDOWS\system32\nmllm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\nmllm.ini2
C:\WINDOWS\system32\nmllm.ini2 Has been deleted!
Performing Repairs to the registry.
Done!
-------------------------------------------------------------------------------------
RAPPORT DE VirtumundoBeGone.exe
[01/31/2008, 20:22:33] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Gulli\Bureau\VirtumundoBeGone.exe" )
[01/31/2008, 20:22:41] - Detected System Information:
[01/31/2008, 20:22:41] - Windows Version: 5.1.2600, Service Pack 1
[01/31/2008, 20:22:41] - Current Username: Gulli (Admin)
[01/31/2008, 20:22:41] - Windows is in NORMAL mode.
[01/31/2008, 20:22:41] - Searching for Browser Helper Objects:
[01/31/2008, 20:22:41] - BHO 1: {031AA453-5089-4716-9A0E-5E57EED49280} ()
[01/31/2008, 20:22:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/31/2008, 20:22:41] - No filename found. Continuing.
[01/31/2008, 20:22:41] - BHO 2: {4E9A0766-A344-4D96-839F-404188091627} ()
[01/31/2008, 20:22:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/31/2008, 20:22:41] - No filename found. Continuing.
[01/31/2008, 20:22:41] - BHO 3: {56992BFB-46B5-4738-863A-5C45FEA0AEE1} ()
[01/31/2008, 20:22:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/31/2008, 20:22:41] - Checking for HKLM\...\Winlogon\Notify\mllji
[01/31/2008, 20:22:41] - Key not found: HKLM\...\Winlogon\Notify\mllji, continuing.
[01/31/2008, 20:22:41] - BHO 4: {67EDE3EB-3C04-4294-958A-9893A7DC5D59} ()
[01/31/2008, 20:22:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/31/2008, 20:22:41] - No filename found. Continuing.
[01/31/2008, 20:22:41] - BHO 5: {8C6291BA-326A-489E-8BB4-05170BB1D1A3} ()
[01/31/2008, 20:22:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/31/2008, 20:22:41] - Checking for HKLM\...\Winlogon\Notify\mllmn
[01/31/2008, 20:22:41] - Key not found: HKLM\...\Winlogon\Notify\mllmn, continuing.
[01/31/2008, 20:22:41] - BHO 6: {98663E21-9CCE-4CF6-863C-911A9523A66F} ()
[01/31/2008, 20:22:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/31/2008, 20:22:41] - Checking for HKLM\...\Winlogon\Notify\byxurol
[01/31/2008, 20:22:41] - Key not found: HKLM\...\Winlogon\Notify\byxurol, continuing.
[01/31/2008, 20:22:41] - BHO 7: {99BB910B-878D-4A89-9AEA-83D118467B38} ()
[01/31/2008, 20:22:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/31/2008, 20:22:41] - No filename found. Continuing.
[01/31/2008, 20:22:41] - BHO 8: {A1BD936F-923E-453D-96E8-278EF3D5C9A0} ()
[01/31/2008, 20:22:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/31/2008, 20:22:41] - No filename found. Continuing.
[01/31/2008, 20:22:41] - Finished Searching Browser Helper Objects
[01/31/2008, 20:22:41] - Finishing up...
[01/31/2008, 20:22:41] - Nothing found! Exiting...

(mais il nous m'en l'escro en faite

) PARCE QUE ET LA J'AIME:
------------------------------------------------------------------------------------
RAPPORT DU LOGICIEL DE SYMANTEC FIXVUNDO:
Symantec Trojan.Vundo Removal Tool 1.5.0
The process "IEXPLORE.EXE" might be affected by the threat. It has been suspended.
The process "IEXPLORE.EXE" might be affected by the threat. It has been terminated.
C:\System Volume Information: (not scanned)
E:\System Volume Information: (not scanned)
Trojan.Vundo has been successfully removed from your computer!
Here is the report:
The total number of the scanned files: 61102
The number of deleted files: 0
The number of viral processes terminated: 1
The number of viral processes suspended: 1
The number of viral threads terminated: 0
The number of registry entries fixed: 0
-------------------------------------------------------------------------------------
Voila sinon dans poste de travail depui le debut de l'infection je croi, il y a un fichier nommé key.shm (1ko) qui quand je le supprime revien quand je redemare. peut etre que se n'est rien.
bref je ne suis pa sur que se soit terminé
En Tout cas tu m'dit si je me trompe MAIS ON LUI A CASSER LA GUEL
