Pc infecté, aide HITJAKIS

Fermé
majda -  
 majda -
Bonjour,

je suis infecté par 1 virus et 3 chevaux de troie, mon avg n'arrive pas à tout supprimer, et je ne sais plus comment poster et utiliser hitjakis et ou le trouver merci de me venir en aide (urgent)

4 réponses

  1. g3n-h@ckm@n
     
    bonjour on peut avoir plus de precisions sur ces virus ? leur chemin ? les fichiers infectés ? le nom des virus ?
    ¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    _Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    0
    1. majda
       
      merci pour la rapidité:)

      j'ai copié collé le rapport avg

      "C:\WINDOWS\temp\vmdwue\setup.exe";"Cheval de Troie : Generic26.APIZ";"Placé en quarantaine"
      "C:\WINDOWS\temp\vdqchp\setup.exe";"Virus identifié Win32/Cryptor";"Placé en quarantaine"
      "C:\WINDOWS\system32\svchost.exe (1576):\memory_13140000";"Cheval de Troie : Generic22.CGZA";"L'objet n'est pas accessible."
      "C:\WINDOWS\system32\svchost.exe (1576)";"Cheval de Troie : Generic22.CGZA";""
      0
  2. g3n-h@ckm@n
     
    ok :)

    ▶ Télécharge Reload_TDSSKiller

    ▶ Lance le

    choisis : lancer le nettoyage

    l'outil va automatiquement télécharger la derniere version puis

    TDSSKiller va s'ouvrir , clique sur "Start Scan"

    Si TDSS.tdl2 est détecté l''option delete sera cochée par défaut.
    Si TDSS.tdl3 est détecté assure toi que Cure est bien cochée.
    Si TDSS.tdl4(\HardDisk0\MBR) est détecté assure toi que Cure est bien cochée.
    Si Suspicious file est indiqué, laisse l''option cochée sur Skip
    Si Rootkit.Win32.ZAccess.* est détecté règle sur "cure" en haut , et "delete" en bas

    une fois qu'il a terminé , redemarre s'il te le demande pour finir de nettoyer

    sinon , ferme tdssKiller et le rapport s'affichera sur le bureau

    ▶ Copie/Colle son contenu dans ta prochaine réponse.
    0
    1. majda
       
      voilà le rapport, c ok?


      12:35:04.0093 2944 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
      12:35:04.0281 2944 ============================================================
      12:35:04.0281 2944 Current date / time: 2011/12/28 12:35:04.0281
      12:35:04.0281 2944 SystemInfo:
      12:35:04.0281 2944
      12:35:04.0281 2944 OS Version: 5.1.2600 ServicePack: 2.0
      12:35:04.0281 2944 Product type: Workstation
      12:35:04.0281 2944 ComputerName: TITANIUM
      12:35:04.0281 2944 UserName: Administrateur
      12:35:04.0281 2944 Windows directory: C:\WINDOWS
      12:35:04.0281 2944 System windows directory: C:\WINDOWS
      12:35:04.0281 2944 Processor architecture: Intel x86
      12:35:04.0281 2944 Number of processors: 2
      12:35:04.0281 2944 Page size: 0x1000
      12:35:04.0281 2944 Boot type: Normal boot
      12:35:04.0281 2944 ============================================================
      12:35:07.0328 2944 Initialize success
      12:35:12.0484 0796 ============================================================
      12:35:12.0484 0796 Scan started
      12:35:12.0484 0796 Mode: Manual;
      12:35:12.0484 0796 ============================================================
      12:35:16.0187 0796 Aavmker4 (31a8ab3deb93e3d90717ad8fb0974c3f) C:\WINDOWS\system32\drivers\Aavmker4.sys
      12:35:16.0187 0796 Aavmker4 - ok
      12:35:16.0296 0796 Abiosdsk - ok
      12:35:16.0359 0796 abp480n5 - ok
      12:35:16.0453 0796 ACPI (0bd94fbfc14ea3606cd6ca4c0255baa3) C:\WINDOWS\system32\DRIVERS\ACPI.sys
      12:35:16.0546 0796 ACPI - ok
      12:35:16.0875 0796 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
      12:35:16.0890 0796 ACPIEC - ok
      12:35:17.0187 0796 adpu160m - ok
      12:35:17.0578 0796 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
      12:35:17.0625 0796 aec - ok
      12:35:17.0828 0796 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
      12:35:17.0843 0796 AFD - ok
      12:35:17.0937 0796 Aha154x - ok
      12:35:17.0953 0796 aic78u2 - ok
      12:35:17.0984 0796 aic78xx - ok
      12:35:18.0031 0796 AliIde - ok
      12:35:18.0078 0796 amsint - ok
      12:35:18.0140 0796 asc - ok
      12:35:18.0171 0796 asc3350p - ok
      12:35:18.0187 0796 asc3550 - ok
      12:35:18.0265 0796 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys
      12:35:18.0421 0796 ASCTRM - ok
      12:35:18.0578 0796 Aspi32 (5b01af89d16d562825c4db4530f20cbb) C:\WINDOWS\system32\drivers\Aspi32.sys
      12:35:18.0718 0796 Aspi32 - ok
      12:35:18.0875 0796 aswFsBlk (b4079a98f294a3e262872cb76f4849f0) C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys
      12:35:18.0875 0796 aswFsBlk - ok
      12:35:18.0937 0796 aswMon2 (1aca2b7efe91ca68ceed9c904ed3310d) C:\WINDOWS\system32\drivers\aswMon2.sys
      12:35:18.0953 0796 aswMon2 - ok
      12:35:19.0015 0796 aswRdr (8080d683489c99cbace813f6fa4069cc) C:\WINDOWS\system32\drivers\aswRdr.sys
      12:35:19.0046 0796 aswRdr - ok
      12:35:19.0203 0796 aswSP (2e5a2ad5004b55df39b7606130a88142) C:\WINDOWS\system32\drivers\aswSP.sys
      12:35:19.0218 0796 aswSP - ok
      12:35:19.0390 0796 aswTdi (ec8ef1ce2d6ca1071be8b7888ffa48c0) C:\WINDOWS\system32\drivers\aswTdi.sys
      12:35:19.0390 0796 aswTdi - ok
      12:35:19.0531 0796 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
      12:35:19.0546 0796 AsyncMac - ok
      12:35:19.0625 0796 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
      12:35:19.0625 0796 atapi - ok
      12:35:19.0781 0796 Atdisk - ok
      12:35:19.0875 0796 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
      12:35:19.0875 0796 Atmarpc - ok
      12:35:20.0000 0796 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
      12:35:20.0015 0796 audstub - ok
      12:35:20.0281 0796 AVGIDSDriverxpx (97670687f6c8f35e7b611f2ce1f94472) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys
      12:35:20.0296 0796 AVGIDSDriverxpx - ok
      12:35:20.0453 0796 AVGIDSErHrxpx (277fc6b0f0be23bae7e63f184034b2fe) C:\WINDOWS\system32\Drivers\AVGIDSxx.sys
      12:35:20.0453 0796 AVGIDSErHrxpx - ok
      12:35:20.0640 0796 AVGIDSFilterxpx (dba65f23b686bdf043bbb54e55c72887) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys
      12:35:20.0640 0796 AVGIDSFilterxpx - ok
      12:35:20.0671 0796 AVGIDSShimxpx (a552461aab7a36c2465ff19e59af08bf) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys
      12:35:20.0687 0796 AVGIDSShimxpx - ok
      12:35:20.0828 0796 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\WINDOWS\System32\Drivers\avgldx86.sys
      12:35:20.0843 0796 AvgLdx86 - ok
      12:35:20.0968 0796 AvgMfx86 (80ff2b1b7eeda966394f0baa895bbf4b) C:\WINDOWS\System32\Drivers\avgmfx86.sys
      12:35:20.0968 0796 AvgMfx86 - ok
      12:35:21.0140 0796 AvgRkx86 (5bbcd8646074a3af4ee9b321d12c2b64) C:\WINDOWS\system32\Drivers\avgrkx86.sys
      12:35:21.0140 0796 AvgRkx86 - ok
      12:35:21.0281 0796 AvgTdiX (9a7a93388f503a34e7339ae7f9997449) C:\WINDOWS\System32\Drivers\avgtdix.sys
      12:35:21.0281 0796 AvgTdiX - ok
      12:35:21.0515 0796 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
      12:35:21.0515 0796 Beep - ok
      12:35:21.0750 0796 Camdrv30 (b626ec900ed64fea808c1763add40c87) C:\WINDOWS\system32\Drivers\camdrv30.sys
      12:35:21.0750 0796 Camdrv30 - ok
      12:35:21.0859 0796 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
      12:35:21.0859 0796 cbidf2k - ok
      12:35:22.0000 0796 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
      12:35:22.0000 0796 CCDECODE - ok
      12:35:22.0046 0796 cd20xrnt - ok
      12:35:22.0156 0796 CdaC15BA (08f60f40d1a2a95a1f12eddbd9f25c1c) C:\WINDOWS\system32\drivers\CdaC15BA.SYS
      12:35:22.0296 0796 CdaC15BA - ok
      12:35:22.0453 0796 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
      12:35:22.0468 0796 Cdaudio - ok
      12:35:22.0531 0796 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
      12:35:22.0531 0796 Cdfs - ok
      12:35:22.0609 0796 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
      12:35:22.0609 0796 Cdrom - ok
      12:35:22.0625 0796 Changer - ok
      12:35:22.0671 0796 CmdIde - ok
      12:35:22.0718 0796 Cpqarray - ok
      12:35:22.0750 0796 dac2w2k - ok
      12:35:22.0781 0796 dac960nt - ok
      12:35:22.0859 0796 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
      12:35:22.0875 0796 Disk - ok
      12:35:22.0968 0796 dmboot (e2d3b7620310fe56685f9b15a6b404b3) C:\WINDOWS\system32\drivers\dmboot.sys
      12:35:23.0000 0796 dmboot - ok
      12:35:23.0156 0796 dmio (c77f5c20aa70197a69aa84baa9de43c8) C:\WINDOWS\system32\drivers\dmio.sys
      12:35:23.0187 0796 dmio - ok
      12:35:23.0328 0796 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
      12:35:23.0328 0796 dmload - ok
      12:35:23.0437 0796 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
      12:35:23.0453 0796 DMusic - ok
      12:35:23.0484 0796 dpti2o - ok
      12:35:23.0640 0796 driverhardwarev2 (a694d8db6d360a3bbb0bd1517f1c1aee) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
      12:35:23.0656 0796 driverhardwarev2 - ok
      12:35:23.0843 0796 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
      12:35:23.0843 0796 drmkaud - ok
      12:35:24.0000 0796 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
      12:35:24.0000 0796 Fastfat - ok
      12:35:24.0140 0796 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys
      12:35:24.0156 0796 Fdc - ok
      12:35:24.0234 0796 Fips (8b121ff880683607ab2aef0340721718) C:\WINDOWS\system32\drivers\Fips.sys
      12:35:24.0234 0796 Fips - ok
      12:35:24.0296 0796 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys
      12:35:24.0296 0796 Flpydisk - ok
      12:35:24.0421 0796 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
      12:35:24.0421 0796 FltMgr - ok
      12:35:24.0500 0796 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
      12:35:24.0515 0796 Fs_Rec - ok
      12:35:24.0531 0796 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
      12:35:24.0546 0796 Ftdisk - ok
      12:35:24.0593 0796 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
      12:35:24.0640 0796 Gpc - ok
      12:35:24.0828 0796 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
      12:35:24.0875 0796 HDAudBus - ok
      12:35:25.0015 0796 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
      12:35:25.0015 0796 hidusb - ok
      12:35:25.0062 0796 hpn - ok
      12:35:25.0140 0796 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
      12:35:25.0250 0796 HTTP - ok
      12:35:25.0421 0796 hxctlflt (f02ea43ae8f936124debf5b87f12c795) C:\WINDOWS\system32\Drivers\hxctlflt.sys
      12:35:25.0468 0796 hxctlflt - ok
      12:35:25.0546 0796 i2omgmt - ok
      12:35:25.0578 0796 i2omp - ok
      12:35:25.0640 0796 i8042prt (d1efcbd693b5ba21314d06368c471070) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
      12:35:25.0656 0796 i8042prt - ok
      12:35:26.0046 0796 ialm (48846b31be5a4fa662ccfde7a1ba86b9) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
      12:35:26.0296 0796 ialm - ok
      12:35:26.0453 0796 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
      12:35:26.0453 0796 Imapi - ok
      12:35:26.0484 0796 ini910u - ok
      12:35:26.0750 0796 IntcAzAudAddService (12a9dafe2266b6fa6ddbce1847347751) C:\WINDOWS\system32\drivers\RtkHDAud.sys
      12:35:26.0953 0796 IntcAzAudAddService - ok
      12:35:27.0062 0796 IntelIde - ok
      12:35:27.0171 0796 intelppm (dd5ad1e79ac26d3f8d8828ad4627f160) C:\WINDOWS\system32\DRIVERS\intelppm.sys
      12:35:27.0171 0796 intelppm - ok
      12:35:27.0250 0796 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
      12:35:27.0250 0796 Ip6Fw - ok
      12:35:27.0328 0796 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
      12:35:27.0343 0796 IpFilterDriver - ok
      12:35:27.0421 0796 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
      12:35:27.0421 0796 IpInIp - ok
      12:35:27.0515 0796 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
      12:35:27.0515 0796 IpNat - ok
      12:35:27.0656 0796 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
      12:35:27.0656 0796 IPSec - ok
      12:35:27.0750 0796 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
      12:35:27.0750 0796 IRENUM - ok
      12:35:27.0843 0796 isapnp (54632f1a7de61dc3615d756f2a90fa72) C:\WINDOWS\system32\DRIVERS\isapnp.sys
      12:35:27.0843 0796 isapnp - ok
      12:35:27.0921 0796 JL2005C (aa964af499dfb4382f7723146ffa6a1b) C:\WINDOWS\system32\Drivers\jl2005c.sys
      12:35:28.0484 0796 JL2005C - ok
      12:35:28.0625 0796 Kbdclass (e798705e8dc7fab596ef6bfdf167e007) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
      12:35:28.0640 0796 Kbdclass - ok
      12:35:28.0734 0796 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
      12:35:28.0734 0796 kmixer - ok
      12:35:28.0828 0796 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
      12:35:28.0875 0796 KSecDD - ok
      12:35:29.0078 0796 lbrtfdc - ok
      12:35:29.0187 0796 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
      12:35:29.0187 0796 mnmdd - ok
      12:35:29.0312 0796 Modem (5ac7e16f5b40a6da14b5f2b3ada4693e) C:\WINDOWS\system32\drivers\Modem.sys
      12:35:29.0312 0796 Modem - ok
      12:35:29.0359 0796 Mouclass (7d4f19411bd941e1d432a99e24230386) C:\WINDOWS\system32\DRIVERS\mouclass.sys
      12:35:29.0375 0796 Mouclass - ok
      12:35:29.0437 0796 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
      12:35:29.0453 0796 mouhid - ok
      12:35:29.0515 0796 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
      12:35:29.0531 0796 MountMgr - ok
      12:35:29.0546 0796 mraid35x - ok
      12:35:29.0609 0796 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
      12:35:29.0609 0796 MRxDAV - ok
      12:35:29.0796 0796 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
      12:35:29.0828 0796 MRxSmb - ok
      12:35:29.0953 0796 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
      12:35:29.0953 0796 Msfs - ok
      12:35:30.0031 0796 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
      12:35:30.0046 0796 MSKSSRV - ok
      12:35:30.0125 0796 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
      12:35:30.0125 0796 MSPCLOCK - ok
      12:35:30.0203 0796 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
      12:35:30.0218 0796 MSPQM - ok
      12:35:30.0312 0796 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
      12:35:30.0312 0796 mssmbios - ok
      12:35:30.0390 0796 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
      12:35:30.0390 0796 MSTEE - ok
      12:35:30.0578 0796 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
      12:35:30.0593 0796 Mup - ok
      12:35:30.0718 0796 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
      12:35:30.0734 0796 NABTSFEC - ok
      12:35:30.0875 0796 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
      12:35:30.0875 0796 NDIS - ok
      12:35:30.0953 0796 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
      12:35:30.0968 0796 NdisIP - ok
      12:35:31.0156 0796 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
      12:35:31.0171 0796 NdisTapi - ok
      12:35:31.0296 0796 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
      12:35:31.0296 0796 Ndisuio - ok
      12:35:31.0421 0796 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
      12:35:31.0421 0796 NdisWan - ok
      12:35:31.0546 0796 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
      12:35:31.0546 0796 NDProxy - ok
      12:35:31.0671 0796 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
      12:35:31.0671 0796 NetBIOS - ok
      12:35:31.0828 0796 NetBT (39d2683fd6cc4baaa73e1dcb80631587) C:\WINDOWS\system32\DRIVERS\netbt.sys
      12:35:32.0812 0796 NetBT ( Rootkit.Win32.ZAccess.h ) - infected
      12:35:32.0812 0796 NetBT - detected Rootkit.Win32.ZAccess.h (0)
      12:35:32.0984 0796 Npfi2p_gc (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\drivers\nic1394.sys
      12:35:33.0000 0796 Npfi2p_gc - ok
      12:35:33.0062 0796 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
      12:35:33.0062 0796 Npfs - ok
      12:35:33.0125 0796 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
      12:35:33.0156 0796 Ntfs - ok
      12:35:33.0328 0796 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
      12:35:33.0328 0796 Null - ok
      12:35:33.0406 0796 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
      12:35:33.0421 0796 NwlnkFlt - ok
      12:35:33.0500 0796 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
      12:35:33.0515 0796 NwlnkFwd - ok
      12:35:33.0593 0796 Parport (318696359ac7df48d1e51974ec527dd2) C:\WINDOWS\system32\DRIVERS\parport.sys
      12:35:33.0609 0796 Parport - ok
      12:35:33.0750 0796 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
      12:35:33.0750 0796 PartMgr - ok
      12:35:33.0828 0796 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
      12:35:33.0828 0796 ParVdm - ok
      12:35:33.0921 0796 PCI (7c5da5c1ed801ad8b0309d5514f0b75e) C:\WINDOWS\system32\DRIVERS\pci.sys
      12:35:33.0921 0796 PCI - ok
      12:35:34.0000 0796 PCIDump - ok
      12:35:34.0046 0796 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys
      12:35:34.0062 0796 PCIIde - ok
      12:35:34.0156 0796 Pcmcia (641da274e163617ea7a33506bc6da8e3) C:\WINDOWS\system32\drivers\Pcmcia.sys
      12:35:34.0171 0796 Pcmcia - ok
      12:35:34.0343 0796 PDCOMP - ok
      12:35:34.0390 0796 PDFRAME - ok
      12:35:34.0421 0796 PDRELI - ok
      12:35:34.0437 0796 PDRFRAME - ok
      12:35:34.0468 0796 perc2 - ok
      12:35:34.0500 0796 perc2hib - ok
      12:35:34.0609 0796 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
      12:35:34.0625 0796 PptpMiniport - ok
      12:35:34.0734 0796 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
      12:35:34.0734 0796 PSched - ok
      12:35:34.0843 0796 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
      12:35:34.0859 0796 Ptilink - ok
      12:35:34.0937 0796 PxHelp20 (b572ed0c3e6165643fa116af20425a54) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
      12:35:34.0953 0796 PxHelp20 - ok
      12:35:34.0968 0796 ql1080 - ok
      12:35:35.0000 0796 Ql10wnt - ok
      12:35:35.0015 0796 ql12160 - ok
      12:35:35.0046 0796 ql1240 - ok
      12:35:35.0109 0796 ql1280 - ok
      12:35:35.0187 0796 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
      12:35:35.0187 0796 RasAcd - ok
      12:35:35.0296 0796 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
      12:35:35.0312 0796 Rasl2tp - ok
      12:35:35.0390 0796 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
      12:35:35.0390 0796 RasPppoe - ok
      12:35:35.0468 0796 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
      12:35:35.0468 0796 Raspti - ok
      12:35:35.0546 0796 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
      12:35:35.0562 0796 Rdbss - ok
      12:35:35.0625 0796 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
      12:35:35.0640 0796 RDPCDD - ok
      12:35:35.0750 0796 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
      12:35:35.0765 0796 rdpdr - ok
      12:35:35.0921 0796 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
      12:35:35.0921 0796 RDPWD - ok
      12:35:36.0015 0796 redbook (2cc30b68dd62b73d444a41322cd7fc4c) C:\WINDOWS\system32\DRIVERS\redbook.sys
      12:35:36.0015 0796 redbook - ok
      12:35:36.0125 0796 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
      12:35:36.0125 0796 ROOTMODEM - ok
      12:35:36.0281 0796 RTLE8023xp (b52b25f41bf3511071a0e7d10d659c56) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
      12:35:36.0296 0796 RTLE8023xp - ok
      12:35:36.0406 0796 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
      12:35:36.0437 0796 Secdrv - ok
      12:35:36.0671 0796 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
      12:35:36.0671 0796 serenum - ok
      12:35:36.0812 0796 Serial (653201755ca96ab4aaa4131daf6da356) C:\WINDOWS\system32\DRIVERS\serial.sys
      12:35:36.0828 0796 Serial - ok
      12:35:36.0859 0796 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
      12:35:36.0859 0796 Sfloppy - ok
      12:35:36.0906 0796 Simbad - ok
      12:35:36.0984 0796 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
      12:35:36.0984 0796 SLIP - ok
      12:35:37.0187 0796 SNP2UVC (a70f178299812dce4cc0e802d403be9b) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
      12:35:37.0343 0796 SNP2UVC - ok
      12:35:37.0453 0796 Sparrow - ok
      12:35:37.0515 0796 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
      12:35:37.0546 0796 splitter - ok
      12:35:37.0625 0796 sr (b52181023b827acda36c1b76751ebffd) C:\WINDOWS\system32\DRIVERS\sr.sys
      12:35:37.0625 0796 sr - ok
      12:35:37.0765 0796 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
      12:35:37.0781 0796 Srv - ok
      12:35:37.0906 0796 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
      12:35:37.0921 0796 streamip - ok
      12:35:38.0000 0796 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
      12:35:38.0000 0796 swenum - ok
      12:35:38.0093 0796 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
      12:35:38.0093 0796 swmidi - ok
      12:35:38.0250 0796 symc810 - ok
      12:35:38.0453 0796 symc8xx - ok
      12:35:38.0734 0796 sym_hi - ok
      12:35:39.0015 0796 sym_u3 - ok
      12:35:39.0265 0796 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
      12:35:39.0296 0796 sysaudio - ok
      12:35:39.0718 0796 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
      12:35:39.0796 0796 Tcpip - ok
      12:35:40.0187 0796 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
      12:35:40.0203 0796 TDPIPE - ok
      12:35:40.0562 0796 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
      12:35:40.0671 0796 TDTCP - ok
      12:35:41.0093 0796 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
      12:35:41.0125 0796 TermDD - ok
      12:35:41.0250 0796 TosIde - ok
      12:35:41.0343 0796 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
      12:35:41.0343 0796 Udfs - ok
      12:35:41.0390 0796 ultra - ok
      12:35:41.0484 0796 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
      12:35:41.0500 0796 Update - ok
      12:35:41.0625 0796 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys
      12:35:41.0640 0796 usbaudio - ok
      12:35:41.0750 0796 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
      12:35:41.0750 0796 usbccgp - ok
      12:35:41.0875 0796 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
      12:35:41.0875 0796 usbehci - ok
      12:35:41.0937 0796 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
      12:35:41.0937 0796 usbhub - ok
      12:35:42.0015 0796 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
      12:35:42.0015 0796 usbprint - ok
      12:35:42.0093 0796 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
      12:35:42.0109 0796 usbscan - ok
      12:35:42.0156 0796 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
      12:35:42.0156 0796 usbstor - ok
      12:35:42.0234 0796 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
      12:35:42.0234 0796 usbuhci - ok
      12:35:42.0312 0796 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\WINDOWS\system32\Drivers\usbvideo.sys
      12:35:42.0312 0796 usbvideo - ok
      12:35:42.0406 0796 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
      12:35:42.0406 0796 VgaSave - ok
      12:35:42.0437 0796 ViaIde - ok
      12:35:42.0531 0796 VolSnap (313b1a0d5db26dfe1c34a6c13b2ce0a7) C:\WINDOWS\system32\drivers\VolSnap.sys
      12:35:42.0531 0796 VolSnap - ok
      12:35:42.0718 0796 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
      12:35:42.0734 0796 Wanarp - ok
      12:35:42.0843 0796 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
      12:35:42.0859 0796 wanatw - ok
      12:35:42.0890 0796 WDICA - ok
      12:35:42.0953 0796 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
      12:35:42.0953 0796 wdmaud - ok
      12:35:43.0109 0796 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
      12:35:43.0109 0796 WSTCODEC - ok
      12:35:43.0187 0796 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0
      12:35:43.0390 0796 \Device\Harddisk0\DR0 - ok
      12:35:43.0390 0796 Boot (0x1200) (2d1d1bd348c0d4fc6af6f8752b3f9073) \Device\Harddisk0\DR0\Partition0
      12:35:43.0390 0796 \Device\Harddisk0\DR0\Partition0 - ok
      12:35:43.0390 0796 ============================================================
      12:35:43.0390 0796 Scan finished
      12:35:43.0390 0796 ============================================================
      12:35:43.0421 3252 Detected object count: 1
      12:35:43.0421 3252 Actual detected object count: 1
      12:36:27.0828 3252 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\netbt.sys) error 1813
      12:36:28.0593 3252 Backup copy not found, trying to cure infected file..
      12:36:28.0734 3252 Cure success, using it..
      12:36:28.0921 3252 C:\WINDOWS\system32\DRIVERS\netbt.sys - will be cured on reboot
      12:36:35.0828 3252 NetBT ( Rootkit.Win32.ZAccess.h ) - User select action: Cure
      12:36:47.0437 0432 Deinitialize success
      0
  3. g3n-h@ckm@n
     
    nickel l'ordi a du redemarrer (confirme)

    ===================

    telecharge et enregistre ceci sur ton bureau :

    Pre_Scan

    Avertissement: tous les processus non-vitaux de windows seront coupés --> pas de panique.

    une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition du rapport sur le bureau.

    si 'outil est bloqué par l'infection utilise cette version : Version .pif

    ou encore cette version renommée : Winlogon.exe

    si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

    si l'outil semble ne pas avoir fonctionné affiche les extensions des fichiers et renomme-le winlogon.exe , ou change son extension en .com ou .scr

    Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

    Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan après redemarrage

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    heberge le rapport sur http://pjjoint.malekal.com et donne le lien obtenu

    0
    1. majda
       
      voici le lien obtenu (et je confirme le redemarage du pc)
      0
    2. majda
       
      dsl voici le lien
      http://pjjoint.malekal.com/files.php?id=20111228_j10g6m14k8m13
      0
  4. g3n-h@ckm@n
     
    re

    ton windows XP titanium n'est pas une version de windows legitime , je t'invite donc à te procurer une licence légale

    pour info :

    https://www.commentcamarche.net/faq/2981-j-utilise-une-version-piratee-de-windows
    0
    1. majda
       
      ok, pour la version piraté :(

      mais est ce que c'est nettoyé ou y a t'il encore des manip a faire,
      en tous les cas merci
      0