Bitdefender ne répond plus - Page 2

  1. Ok je vais faire ça ce soir, mais comme mon pc se bloque j'espère que ça se fera sans trop de problèmes.

    Au fait j'ai 2 questions (si tu as un peu de temps pour y répondre rapido) : qu'est ça t'as "révélé" le RIST ? et à quoi ça sert le List&Kill'em ?

    Merci :)
    0
    1. Salut, Merci pour ces précisions. Voici le rapport - comme mon pc plante, je l'ai fait sous ms dos.

      List'em by g3n-h@ckm@n 1.1.4.1

      Thx to Chiquitine29.....& CCM team

      User : Di (Administrateurs) # PC-DE-DI
      Update on 09/12/2009 by g3n-h@ckm@n ::::: 17:00
      Start at: 22:43:20 | 10/12/2009
      Contact : g3n-h@ckm@n sur CCM

      Intel(R) Pentium(R) Dual CPU T2390 @ 1.86GHz
      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
      Internet Explorer 8.0.6001.18828
      Windows Firewall Status : Disabled

      C:\ -> Disque fixe local | 100,6 Go (13,76 Go free) | NTFS
      D:\ -> Disque fixe local | 11,19 Go (2,32 Go free) [PRESARIO_RP] | NTFS
      E:\ -> Disque CD-ROM

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

      C:\Windows\System32\smss.exe 380
      C:\Windows\system32\csrss.exe 520
      C:\Windows\system32\csrss.exe 556
      C:\Windows\system32\wininit.exe 564
      C:\Windows\system32\winlogon.exe 608
      C:\Windows\system32\services.exe 636
      C:\Windows\system32\lsass.exe 652
      C:\Windows\system32\lsm.exe 660
      C:\Windows\system32\svchost.exe 808
      C:\Windows\system32\svchost.exe 864
      C:\Windows\System32\svchost.exe 1004
      C:\Windows\system32\svchost.exe 1032
      C:\Windows\System32\svchost.exe 1056
      C:\Windows\system32\svchost.exe 1108
      C:\Windows\system32\svchost.exe 1128
      C:\Windows\system32\svchost.exe 1304
      C:\Windows\system32\svchost.exe 1408
      C:\Windows\Explorer.EXE 1740
      C:\Program Files\Windows Media Player\wmpnscfg.exe 120
      C:\Windows\system32\igfxsrvc.exe 1052
      C:\Users\Di\Desktop\List_Killem\List_Kill'em.scr 940
      C:\Windows\system32\cmd.exe 1524
      C:\Windows\system32\wbem\wmiprvse.exe 832
      C:\Users\Di\AppData\Local\Temp\E5AC.tmp\pv.exe 304

      ======================
      Keys "Run"
      ======================
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      LightScribe Control Panel REG_SZ C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
      ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
      WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
      SWF Live Preview REG_SZ C:\Program Files\Eltima Software\SWF Live Preview\swf_lp.exe
      swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      Apoint REG_SZ C:\Program Files\Apoint2K\Apoint.exe
      IAAnotif REG_SZ "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
      QPService REG_SZ "C:\Program Files\HP\QuickPlay\QPService.exe"
      QlbCtrl REG_EXPAND_SZ %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
      UCam_Menu REG_SZ "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
      Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      HP Health Check Scheduler REG_SZ [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
      hpWirelessAssistant REG_SZ C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
      HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
      Persistence REG_SZ C:\Windows\system32\igfxpers.exe
      HP Software Update REG_SZ C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
      DellNSCST_GRNCH REG_SZ "C:\Program Files\Dell\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" /HIDEUI
      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      BitDefender Antiphishing Helper REG_SZ "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
      BDAgent REG_SZ "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
      SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

      =====================
      Other Keys
      =====================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
      ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
      EnableInstallerDetection REG_DWORD 1 (0x1)
      EnableLUA REG_DWORD 1 (0x1)
      EnableSecureUIAPaths REG_DWORD 1 (0x1)
      EnableVirtualization REG_DWORD 1 (0x1)
      PromptOnSecureDesktop REG_DWORD 1 (0x1)
      ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
      dontdisplaylastusername REG_DWORD 0 (0x0)
      legalnoticecaption REG_SZ
      legalnoticetext REG_SZ
      scforceoption REG_DWORD 0 (0x0)
      shutdownwithoutlogon REG_DWORD 1 (0x1)
      undockwithoutlogon REG_DWORD 1 (0x1)
      FilterAdministratorToken REG_DWORD 0 (0x0)
      EnableUIADesktopToggle REG_DWORD 0 (0x0)

      ===============
      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      NoDriveTypeAutoRun REG_BINARY 95000000

      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      AppInit_DLLS REG_SZ

      ===============
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

      ===============
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      C:\Program Files\BitTorrent\bittorrent.exe REG_SZ C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

      ===============
      BHO :
      ======
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

      ================
      Internet Explorer :
      ================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.google.fr/?gws_rd=ssl

      ========
      Services
      ========
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

      Ndisuio : 0x3
      EapHost : 0x3
      Wlansvc : 0x2
      SharedAccess : 0x3
      windefend : 0x2
      wuauserv : 0x2
      wscsvc : 0x2

      =========

      =======
      Drive :
      =======

      D‚fragmenteur de disque Windows
      Copyright (c) 2006 Microsoft Corp.

      Rapport d'analyse pour le volume C:

      Taille du volume = 101 Go
      Espace libre = 13.76 Go
      tendue d'espace libre la plus grande = 1.99 Go
      Pourcentage de fragmentation des fichiers = 2 %

      Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

      Il n'est pas n‚cessaire de d‚fragmenter ce volume.

      ==========
      Programs
      ==========

      Activation Assistant for the 2007 Microsoft Office suites
      Adobe
      AIM6
      Apoint2K
      Atheros
      Audacity 1.3 Beta (Unicode)
      Axure
      Belkin
      BitDefender
      BitTorrent
      Bonjour
      Common Files
      CONEXANT
      CyberLink
      DELL
      desktop.ini
      DivX
      DNA
      EarMaster Pro 5
      Electronic Arts
      Elo TouchSystems
      EloTouchSystems
      Eltima Software
      eMule
      Fichiers communs
      FileZilla FTP Client
      Fit3DLiveDecathlon
      Futuroscope La Rencontre
      GlassesDirectMirror
      Google
      Hewlett-Packard
      Hp
      HP Games
      HPQ
      InstallShield Installation Information
      Intel
      Internet Explorer
      Inventel
      Java
      Malwarebytes' Anti-Malware
      McAfee Security Scan
      Microsoft
      Microsoft Games
      Microsoft Office
      Microsoft Silverlight
      Microsoft Visual Studio
      Microsoft Visual Studio 8
      Microsoft Works
      Microsoft.NET
      Movie Maker
      Mozilla Firefox
      MSBuild
      MSXML 4.0
      muvee Technologies
      M‚thode de Guitare - DEMO Volume I
      M‚thode de Guitare - DEMO Volume I82
      Navilog1
      NetWaiting
      Nokia
      Online Services
      Opera
      PC Connectivity Solution
      PDFCreator
      PhotoFiltre
      RaybanMirror
      Realtek
      Reference Assemblies
      RegCure
      Securitoo
      Skype
      Symantec
      Uninstall Information
      VideoLAN
      Viewpoint
      Wanadoo
      Winamp
      Windows Calendar
      Windows Collaboration
      Windows Defender
      Windows Journal
      Windows Live
      Windows Live SkyDrive
      Windows Mail
      Windows Media Player
      Windows NT
      Windows Photo Gallery
      Windows Portable Devices
      Windows Sidebar
      WinRAR

      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

      C:\Program Files\Mozilla FireFox\Components\AskSearch.js
      C:\Windows\system32\logs
      C:\Windows\system32\x64

      ¤¤¤¤¤¤¤¤¤¤ Keys :

      HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar "{66886C4D-B307-4ECA-A228-52CA9B9851A4}"
      "HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}"
      HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
      HKLM\Software\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}

      =========
      Rootkits
      =========

      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-12-10 22:48:42
      Windows 6.0.6002 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

      device: opened successfully
      user: MBR read successfully
      kernel: MBR read successfully
      user & kernel MBR OK

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
      0
      1. salut pour avancer :

        ▶ Relance List&Kill'em comme tu as fait pour l'option 1 (soit en clic droit pour vista),

        mais cette fois-ci :

        ▶ choisis l'option 2 = Mode Destruction

        laisse travailler l'outil.

        en fin de scan un rapport s'ouvre

        ▶ colle le contenu dans ta reponse

        ▹ Redemarre ton PC.
        0
        Précédent
        • 1
        • 2