Analyse hijackthis - Page 2

Précédent
  • 1
  • 2
  1. otacon59 Messages postés 14 Statut Membre
     
    suite et fin :

    SR - | Auto 07/03/2011 43936 | (Updatesrv) . (.BitDefender S.R.L..) - C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe
    SR - | Auto 07/03/2011 2050864 | (VSSERV) . (.BitDefender S.R.L..) - C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe
    SR - | Auto 21/01/2008 21504 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\system32\svchost.exe

    ---\\ Recherche Master Boot Record Infection (MBR)(O80)
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Run by otacon at 18/06/2011 00:23:07

    device: opened successfully
    user: MBR read successfully

    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys
    C:\Windows\system32\DRIVERS\nvstor32.sys NVIDIA Corporation NVIDIA nForce(TM) SATA Driver
    1 ntkrnlpa!IofCallDriver[0x8245B912] -> \Device\Harddisk0\DR0[0x869FCAC8]
    3 CLASSPNP[0x8B3AE8B3] -> ntkrnlpa!IofCallDriver[0x8245B912] -> [0x85AE4240]
    5 acpi[0x8069C6BC] -> ntkrnlpa!IofCallDriver[0x8245B912] -> \Device\0000004f[0x85B37868]
    kernel: MBR read successfully
    user & kernel MBR OK

    ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
    Written by ad13, http://ad13.geekstog
    Run by otacon at 18/06/2011 00:23:09

    ********* Dump file Name *********
    C:\PhysicalDisk0_MBR.bin

    End of the scan (1252 lines in 04mn 27s)(0)
    0
  2. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    rhaaa si je demande d'héberger ton rapport c'est justement car il est trop long pour tenir dans un message ! :/

    refais un zhpfix avec ça :

    C:\Users\otacon\Appdata\Local\Temp\AskSearch
    O43 - CFD: 09/02/2011 - 11:40:40 - [234038] ---AD- C:\Program Files\SweetIM
    O43 - CFD: 09/02/2011 - 11:40:22 - [444080] ---AD- C:\ProgramData\SweetIM
    C:\Program Files\SweetIM
    C:\ProgramData\SweetIM
    C:\Users\otacon\Appdata\LocalLow\SweetIM


    colle le rapport
    0
Précédent
  • 1
  • 2