OK merci bcp je vous tiens au courant!
Ajout du 15-12-2007 à 09:32:
Le rapport de VBG:
[12/15/2007, 9:27:41] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Alex\Bureau\VirtumundoBeGone.exe" )
[12/15/2007, 9:27:46] - Detected System Information:
[12/15/2007, 9:27:46] - Windows Version: 5.1.2600, Service Pack 2
[12/15/2007, 9:27:46] - Current Username: Alex (Admin)
[12/15/2007, 9:27:46] - Windows is in NORMAL mode.
[12/15/2007, 9:27:46] - Searching for Browser Helper Objects:
[12/15/2007, 9:27:46] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[12/15/2007, 9:27:46] - BHO 2: {5BE79A2A-D038-4775-82D7-589DB9999714} ()
[12/15/2007, 9:27:46] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2007, 9:27:46] - Checking for HKLM\...\Winlogon\Notify\gebca
[12/15/2007, 9:27:46] - Key not found: HKLM\...\Winlogon\Notify\gebca, continuing.
[12/15/2007, 9:27:46] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[12/15/2007, 9:27:46] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[12/15/2007, 9:27:46] - BHO 5: {AEBF6926-DBA6-4100-A838-1CED0169AB78} ()
[12/15/2007, 9:27:46] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2007, 9:27:46] - Checking for HKLM\...\Winlogon\Notify\pmnmmnn
[12/15/2007, 9:27:46] - Found: HKLM\...\Winlogon\Notify\pmnmmnn - This is probably Virtumundo.
[12/15/2007, 9:27:46] - Assigning {AEBF6926-DBA6-4100-A838-1CED0169AB78} MSEvents Object
[12/15/2007, 9:27:46] - BHO list has been changed! Starting over...
[12/15/2007, 9:27:46] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[12/15/2007, 9:27:46] - BHO 2: {5BE79A2A-D038-4775-82D7-589DB9999714} ()
[12/15/2007, 9:27:46] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2007, 9:27:46] - Checking for HKLM\...\Winlogon\Notify\gebca
[12/15/2007, 9:27:46] - Key not found: HKLM\...\Winlogon\Notify\gebca, continuing.
[12/15/2007, 9:27:46] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[12/15/2007, 9:27:46] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[12/15/2007, 9:27:46] - BHO 5: {AEBF6926-DBA6-4100-A838-1CED0169AB78} (MSEvents Object)
[12/15/2007, 9:27:46] - ALERT: Found MSEvents Object!
[12/15/2007, 9:27:46] - Finished Searching Browser Helper Objects
[12/15/2007, 9:27:46] - *** Detected MSEvents Object
[12/15/2007, 9:27:46] - Trying to remove MSEvents Object...
[12/15/2007, 9:27:47] - Terminating Process: IEXPLORE.EXE
[12/15/2007, 9:27:47] - Terminating Process: RUNDLL32.EXE
[12/15/2007, 9:27:48] - Disabling Automatic Shell Restart
[12/15/2007, 9:27:48] - Terminating Process: EXPLORER.EXE
[12/15/2007, 9:27:48] - Suspending the NT Session Manager System Service
[12/15/2007, 9:27:48] - Terminating Windows NT Logon/Logoff Manager
[12/15/2007, 9:27:49] - Re-enabling Automatic Shell Restart
[12/15/2007, 9:27:49] - File to disable: C:\WINDOWS\system32\pmnmmnn.dll
[12/15/2007, 9:27:49] - Renaming C:\WINDOWS\system32\pmnmmnn.dll -> C:\WINDOWS\system32\pmnmmnn.dll.vir
[12/15/2007, 9:27:49] - File successfully renamed!
[12/15/2007, 9:27:49] - Removing HKLM\...\Browser Helper Objects\{AEBF6926-DBA6-4100-A838-1CED0169AB78}
[12/15/2007, 9:27:49] - Removing HKCR\CLSID\{AEBF6926-DBA6-4100-A838-1CED0169AB78}
[12/15/2007, 9:27:49] - Adding Kill Bit for ActiveX for GUID: {AEBF6926-DBA6-4100-A838-1CED0169AB78}
[12/15/2007, 9:27:49] - Deleting ATLEvents/MSEvents Registry entries
[12/15/2007, 9:27:49] - Removing HKLM\...\Winlogon\Notify\pmnmmnn
[12/15/2007, 9:27:49] - Searching for Browser Helper Objects:
[12/15/2007, 9:27:49] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[12/15/2007, 9:27:49] - BHO 2: {5BE79A2A-D038-4775-82D7-589DB9999714} ()
[12/15/2007, 9:27:49] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2007, 9:27:49] - Checking for HKLM\...\Winlogon\Notify\gebca
[12/15/2007, 9:27:49] - Key not found: HKLM\...\Winlogon\Notify\gebca, continuing.
[12/15/2007, 9:27:49] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[12/15/2007, 9:27:49] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[12/15/2007, 9:27:49] - Finished Searching Browser Helper Objects
[12/15/2007, 9:27:49] - Finishing up...
[12/15/2007, 9:27:49] - A restart is needed.
[12/15/2007, 9:28:01] - Attempting to Restart via STOP error (Blue Screen!)
Il semble avoir trouveé mes 2 fichiers suspects gebca.dll et et pmnmmnn.dll qu'il a renommé et que jais pouvoir supprimé manuellement à ce que je vois
Ajout du 15-12-2007 à 09:44:
MERCI beaucoup unefois que ces 2 logiciels ont réussis à les isoler en les renommant et les déplacant j'ai put les supprimer manuellement! J'utilise Processexplorer et je ne les vois plus!
MERCI pour votre détermination et votre patience Monsieur et bonne journée