Help windowsrestore - Page 2

Résolu
Précédent
  • 1
  • 2
  1. Utilisateur anonyme
     
    On va faire une vérification .
    Post un nouveau rapport zhpdiag.
    Héberge le rapport ZHPDiag.txt sur le site pjjoint.malekal.com ou cijoint.fr ou toofiles puis copie/colle le lien fournit dans ta prochaine réponse sur le forum
    0
  2. andrealphuse Messages postés 372 Statut Membre 10
     
    http://www.cijoint.fr/cjlink.php?file=cj201104/cijkZGiBLk.txt

    voila le lien
    0
  3. Utilisateur anonyme
     
    A faire dans l''ordre.

    1/ Copie/colle les lignes suivantes et place les dans ZHPFix :
    2/Lance ZHPFix (soit via le raccourci sur ton Bureau, soit via ZHPDiag)
    3/Clique sur l''icone représentant la lettre H (« coller les lignes Helper »)

    ----------------------------------------------------------
    O42 - Logiciel: Windows Genuine Advantage Validation 1.9.42.0 Cracked - (.Wocarson.) [HKLM] -- {EB1BE39D-4C36-40A0-8CFB-079A2D14CB79}
    [HKLM\Software\Wocarson]
    O69 - SBI: prefs.js [YANNICK - o10br65d.default] user_pref("extensions.snipit.askTbInstalled", true);
    MBRFix
    O43 - CFD: 30/07/2010 - 17:52:08 - [68] ----D- C:\Program Files\avsysinfo
    OPT:O4 - HKCU\..\Run: [Steam] . (.Valve Corporation - Steam.) -- c:\program files\steam\steam.exe
    OPT:O4 - HKUS\S-1-5-21-842925246-1123561945-682003330-1003\..\Run: [Steam] . (.Valve Corporation - Steam.) -- c:\program files\steam\steam.exe
    EmptyTemp


    --------------------------------------------------------

    - Clique sur le bouton « GO » pour lancer le nettoyage,
    - Copie/colle la totalité du rapport dans ta prochaine réponse
    0
  4. andrealphuse Messages postés 372 Statut Membre 10
     
    Rapport de ZHPFix 1.12.3273 par Nicolas Coolman, Update du 03/04/2011
    Fichier d'export Registre : C:\ZHPExportRegistry-04-04-2011-20-59-20.txt
    Run by YANNICK at 04/04/2011 20:59:20
    Windows XP Professional Service Pack 3 (Build 2600)
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

    ========== Logiciel(s) ==========
    O42 - Logiciel: Windows Genuine Advantage Validation 1.9.42.0 Cracked - (.Wocarson.) [HKLM] -- {EB1BE39D-4C36-40A0-8CFB-079A2D14CB79} => Logiciel déjà supprimé

    ========== Clé(s) du Registre ==========
    O42 - Logiciel: Windows Genuine Advantage Validation 1.9.42.0 Cracked - (.Wocarson.) [HKLM] -- {EB1BE39D-4C36-40A0-8CFB-079A2D14CB79} => Clé supprimée avec succès
    HKLM\Software\Wocarson => Clé supprimée avec succès

    ========== Valeur(s) du Registre ==========
    O4 - HKCU\..\Run: [Steam] . (.Valve Corporation - Steam.) -- c:\program files\steam\steam.exe => Valeur supprimée avec succès
    O4 - HKUS\S-1-5-21-842925246-1123561945-682003330-1003\..\Run: [Steam] . (.Valve Corporation - Steam.) -- c:\program files\steam\steam.exe => Valeur absente

    ========== Préférences navigateur ==========
    O69 - SBI: prefs.js [YANNICK - o10br65d.default] user_pref("extensions.snipit.askTbInstalled", true); => Valeur supprimée avec succès
    O69 - SBI: prefs.js [YANNICK - o10br65d.default] user_pref("extensions.snipit.askTbInstalled", true); => Valeur supprimée avec succès

    ========== Dossier(s) ==========
    Dossiers temporaires Windows supprimés: 0

    ========== Fichier(s) ==========
    Fichiers temporaires Windows supprimés : 2

    ========== Master Boot Record ==========
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: Hitachi_HDT725050VLA360 rev.V56OA7EA -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-19

    device: opened successfully
    user: MBR read successfully

    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A6321ED]<<
    1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8A696AB8]
    3 CLASSPNP[0xB8108FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000079[0x8A79D328]
    5 ACPI[0xB7F7E620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Ide\IdeDeviceP2T0L0-19[0x8A71F940]
    kernel: MBR read successfully
    detected disk devices:
    detected hooks:
    \Driver\atapi -> 0x8a6321ed
    user & kernel MBR OK
    Warning: possible MBR rootkit infection !

    Resultat après le fix :
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: Hitachi_HDT725050VLA360 rev.V56OA7EA -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-19

    device: opened successfully
    user: MBR read successfully

    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A6321ED]<<
    1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8A696AB8]
    3 CLASSPNP[0xB8108FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000079[0x8A79D328]
    5 ACPI[0xB7F7E620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Ide\IdeDeviceP2T0L0-19[0x8A71F940]
    kernel: MBR read successfully
    detected disk devices:
    detected hooks:
    \Driver\atapi -> 0x8a6321ed
    user & kernel MBR OK
    Warning: possible MBR rootkit infection !
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: Hitachi_HDT725050VLA360 rev.V56OA7EA -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-19

    device: opened successfully
    user: MBR read successfully

    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A6321ED]<<
    1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8A696AB8]
    3 CLASSPNP[0xB8108FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000079[0x8A79D328]
    5 ACPI[0xB7F7E620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Ide\IdeDeviceP2T0L0-19[0x8A71F940]
    kernel: MBR read successfully
    detected disk devices:
    detected hooks:
    \Driver\atapi -> 0x8a6321ed
    user & kernel MBR OK
    Warning: possible MBR rootkit infection !

    Resultat après le fix :
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: Hitachi_HDT725050VLA360 rev.V56OA7EA -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-19

    device: opened successfully
    user: MBR read successfully

    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A6321ED]<<
    1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8A696AB8]
    3 CLASSPNP[0xB8108FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000079[0x8A79D328]
    5 ACPI[0xB7F7E620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Ide\IdeDeviceP2T0L0-19[0x8A71F940]
    kernel: MBR read successfully
    detected disk devices:
    detected hooks:
    \Driver\atapi -> 0x8a6321ed
    user & kernel MBR OK
    Warning: possible MBR rootkit infection !

    ========== Récapitulatif ==========
    2 : Clé(s) du Registre
    2 : Valeur(s) du Registre
    1 : Dossier(s)
    1 : Fichier(s)
    1 : Logiciel(s)
    2 : Préférences navigateur
    1 : Master Boot Record

    End of the scan
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    * Télécharger aswMBR.exe sur votre bureau.
    * Double cliquez sur le aswMBR.exe pour l'exécuter
    * Cliquez sur le bouton «Scan» pour commencer le balayage
    * Cliquez sur Save log pour sauvegarder le rapport
    * Enregistrez le aswASW.log sur le bureau
    * Poster le rapport sur le forum.

    0
  7. andrealphuse Messages postés 372 Statut Membre 10
     
    aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software
    Run date: 2011-04-04 21:14:43
    -----------------------------
    21:14:43.234 OS Version: Windows 5.1.2600 Service Pack 3
    21:14:43.234 Number of processors: 2 586 0xF0B
    21:14:43.234 ComputerName: E6750-6AC5E2889 UserName: YANNICK
    21:14:43.765 Initialize success
    21:14:46.046 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-19
    21:14:46.046 Disk 0 Vendor: Hitachi_HDT725050VLA360 V56OA7EA Size: 476940MB BusType: 3
    21:14:48.062 Disk 0 MBR read successfully
    21:14:48.062 Disk 0 MBR scan
    21:14:50.062 Disk 0 scanning sectors +976752000
    21:14:50.078 Disk 0 scanning C:\WINDOWS\system32\drivers
    21:14:53.203 Service scanning
    21:14:54.406 Disk 0 trace - called modules:
    21:14:54.406 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8a6321ed]<<
    21:14:54.406 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a696ab8]
    21:14:54.406 3 CLASSPNP.SYS[b8108fd7] -> nt!IofCallDriver -> \Device\00000079[0x8a79d328]
    21:14:54.406 5 ACPI.sys[b7f7e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-19[0x8a71f940]
    21:14:54.406 \Driver\atapi[0x8a72e630] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x8a6321ed
    21:14:54.406 Scan finished successfully
    0
  8. Utilisateur anonyme
     
    * Relancer aswMBR.exe pour l'exécuter
    * Cliquez sur le bouton «Scan» pour commencer le balayage
    * Cliquez sur "FixMbr"
    * Enregistrez le aswASW.log sur le bureau
    * Poster le rapport sur le forum.
    0
Précédent
  • 1
  • 2