Pc infecté, aide HITJAKIS

Fermé
majda - 28 déc. 2011 à 12:05
 majda - 28 déc. 2011 à 13:23
Bonjour,

je suis infecté par 1 virus et 3 chevaux de troie, mon avg n'arrive pas à tout supprimer, et je ne sais plus comment poster et utiliser hitjakis et ou le trouver merci de me venir en aide (urgent)


A voir également:

4 réponses

bonjour on peut avoir plus de precisions sur ces virus ? leur chemin ? les fichiers infectés ? le nom des virus ?
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
0
merci pour la rapidité:)

j'ai copié collé le rapport avg

"C:\WINDOWS\temp\vmdwue\setup.exe";"Cheval de Troie : Generic26.APIZ";"Placé en quarantaine"
"C:\WINDOWS\temp\vdqchp\setup.exe";"Virus identifié Win32/Cryptor";"Placé en quarantaine"
"C:\WINDOWS\system32\svchost.exe (1576):\memory_13140000";"Cheval de Troie : Generic22.CGZA";"L'objet n'est pas accessible."
"C:\WINDOWS\system32\svchost.exe (1576)";"Cheval de Troie : Generic22.CGZA";""
0
Utilisateur anonyme
28 déc. 2011 à 12:25
ok :)

▶ Télécharge Reload_TDSSKiller

▶ Lance le

choisis : lancer le nettoyage

l'outil va automatiquement télécharger la derniere version puis

TDSSKiller va s'ouvrir , clique sur "Start Scan"

Si TDSS.tdl2 est détecté l''option delete sera cochée par défaut.
Si TDSS.tdl3 est détecté assure toi que Cure est bien cochée.
Si TDSS.tdl4(\HardDisk0\MBR) est détecté assure toi que Cure est bien cochée.
Si Suspicious file est indiqué, laisse l''option cochée sur Skip
Si Rootkit.Win32.ZAccess.* est détecté règle sur "cure" en haut , et "delete" en bas

une fois qu'il a terminé , redemarre s'il te le demande pour finir de nettoyer

sinon , ferme tdssKiller et le rapport s'affichera sur le bureau

▶ Copie/Colle son contenu dans ta prochaine réponse.
0
voilà le rapport, c ok?


12:35:04.0093 2944 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
12:35:04.0281 2944 ============================================================
12:35:04.0281 2944 Current date / time: 2011/12/28 12:35:04.0281
12:35:04.0281 2944 SystemInfo:
12:35:04.0281 2944
12:35:04.0281 2944 OS Version: 5.1.2600 ServicePack: 2.0
12:35:04.0281 2944 Product type: Workstation
12:35:04.0281 2944 ComputerName: TITANIUM
12:35:04.0281 2944 UserName: Administrateur
12:35:04.0281 2944 Windows directory: C:\WINDOWS
12:35:04.0281 2944 System windows directory: C:\WINDOWS
12:35:04.0281 2944 Processor architecture: Intel x86
12:35:04.0281 2944 Number of processors: 2
12:35:04.0281 2944 Page size: 0x1000
12:35:04.0281 2944 Boot type: Normal boot
12:35:04.0281 2944 ============================================================
12:35:07.0328 2944 Initialize success
12:35:12.0484 0796 ============================================================
12:35:12.0484 0796 Scan started
12:35:12.0484 0796 Mode: Manual;
12:35:12.0484 0796 ============================================================
12:35:16.0187 0796 Aavmker4 (31a8ab3deb93e3d90717ad8fb0974c3f) C:\WINDOWS\system32\drivers\Aavmker4.sys
12:35:16.0187 0796 Aavmker4 - ok
12:35:16.0296 0796 Abiosdsk - ok
12:35:16.0359 0796 abp480n5 - ok
12:35:16.0453 0796 ACPI (0bd94fbfc14ea3606cd6ca4c0255baa3) C:\WINDOWS\system32\DRIVERS\ACPI.sys
12:35:16.0546 0796 ACPI - ok
12:35:16.0875 0796 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
12:35:16.0890 0796 ACPIEC - ok
12:35:17.0187 0796 adpu160m - ok
12:35:17.0578 0796 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
12:35:17.0625 0796 aec - ok
12:35:17.0828 0796 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
12:35:17.0843 0796 AFD - ok
12:35:17.0937 0796 Aha154x - ok
12:35:17.0953 0796 aic78u2 - ok
12:35:17.0984 0796 aic78xx - ok
12:35:18.0031 0796 AliIde - ok
12:35:18.0078 0796 amsint - ok
12:35:18.0140 0796 asc - ok
12:35:18.0171 0796 asc3350p - ok
12:35:18.0187 0796 asc3550 - ok
12:35:18.0265 0796 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys
12:35:18.0421 0796 ASCTRM - ok
12:35:18.0578 0796 Aspi32 (5b01af89d16d562825c4db4530f20cbb) C:\WINDOWS\system32\drivers\Aspi32.sys
12:35:18.0718 0796 Aspi32 - ok
12:35:18.0875 0796 aswFsBlk (b4079a98f294a3e262872cb76f4849f0) C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys
12:35:18.0875 0796 aswFsBlk - ok
12:35:18.0937 0796 aswMon2 (1aca2b7efe91ca68ceed9c904ed3310d) C:\WINDOWS\system32\drivers\aswMon2.sys
12:35:18.0953 0796 aswMon2 - ok
12:35:19.0015 0796 aswRdr (8080d683489c99cbace813f6fa4069cc) C:\WINDOWS\system32\drivers\aswRdr.sys
12:35:19.0046 0796 aswRdr - ok
12:35:19.0203 0796 aswSP (2e5a2ad5004b55df39b7606130a88142) C:\WINDOWS\system32\drivers\aswSP.sys
12:35:19.0218 0796 aswSP - ok
12:35:19.0390 0796 aswTdi (ec8ef1ce2d6ca1071be8b7888ffa48c0) C:\WINDOWS\system32\drivers\aswTdi.sys
12:35:19.0390 0796 aswTdi - ok
12:35:19.0531 0796 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
12:35:19.0546 0796 AsyncMac - ok
12:35:19.0625 0796 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
12:35:19.0625 0796 atapi - ok
12:35:19.0781 0796 Atdisk - ok
12:35:19.0875 0796 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
12:35:19.0875 0796 Atmarpc - ok
12:35:20.0000 0796 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
12:35:20.0015 0796 audstub - ok
12:35:20.0281 0796 AVGIDSDriverxpx (97670687f6c8f35e7b611f2ce1f94472) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys
12:35:20.0296 0796 AVGIDSDriverxpx - ok
12:35:20.0453 0796 AVGIDSErHrxpx (277fc6b0f0be23bae7e63f184034b2fe) C:\WINDOWS\system32\Drivers\AVGIDSxx.sys
12:35:20.0453 0796 AVGIDSErHrxpx - ok
12:35:20.0640 0796 AVGIDSFilterxpx (dba65f23b686bdf043bbb54e55c72887) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys
12:35:20.0640 0796 AVGIDSFilterxpx - ok
12:35:20.0671 0796 AVGIDSShimxpx (a552461aab7a36c2465ff19e59af08bf) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys
12:35:20.0687 0796 AVGIDSShimxpx - ok
12:35:20.0828 0796 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\WINDOWS\System32\Drivers\avgldx86.sys
12:35:20.0843 0796 AvgLdx86 - ok
12:35:20.0968 0796 AvgMfx86 (80ff2b1b7eeda966394f0baa895bbf4b) C:\WINDOWS\System32\Drivers\avgmfx86.sys
12:35:20.0968 0796 AvgMfx86 - ok
12:35:21.0140 0796 AvgRkx86 (5bbcd8646074a3af4ee9b321d12c2b64) C:\WINDOWS\system32\Drivers\avgrkx86.sys
12:35:21.0140 0796 AvgRkx86 - ok
12:35:21.0281 0796 AvgTdiX (9a7a93388f503a34e7339ae7f9997449) C:\WINDOWS\System32\Drivers\avgtdix.sys
12:35:21.0281 0796 AvgTdiX - ok
12:35:21.0515 0796 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
12:35:21.0515 0796 Beep - ok
12:35:21.0750 0796 Camdrv30 (b626ec900ed64fea808c1763add40c87) C:\WINDOWS\system32\Drivers\camdrv30.sys
12:35:21.0750 0796 Camdrv30 - ok
12:35:21.0859 0796 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
12:35:21.0859 0796 cbidf2k - ok
12:35:22.0000 0796 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
12:35:22.0000 0796 CCDECODE - ok
12:35:22.0046 0796 cd20xrnt - ok
12:35:22.0156 0796 CdaC15BA (08f60f40d1a2a95a1f12eddbd9f25c1c) C:\WINDOWS\system32\drivers\CdaC15BA.SYS
12:35:22.0296 0796 CdaC15BA - ok
12:35:22.0453 0796 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
12:35:22.0468 0796 Cdaudio - ok
12:35:22.0531 0796 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
12:35:22.0531 0796 Cdfs - ok
12:35:22.0609 0796 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
12:35:22.0609 0796 Cdrom - ok
12:35:22.0625 0796 Changer - ok
12:35:22.0671 0796 CmdIde - ok
12:35:22.0718 0796 Cpqarray - ok
12:35:22.0750 0796 dac2w2k - ok
12:35:22.0781 0796 dac960nt - ok
12:35:22.0859 0796 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
12:35:22.0875 0796 Disk - ok
12:35:22.0968 0796 dmboot (e2d3b7620310fe56685f9b15a6b404b3) C:\WINDOWS\system32\drivers\dmboot.sys
12:35:23.0000 0796 dmboot - ok
12:35:23.0156 0796 dmio (c77f5c20aa70197a69aa84baa9de43c8) C:\WINDOWS\system32\drivers\dmio.sys
12:35:23.0187 0796 dmio - ok
12:35:23.0328 0796 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
12:35:23.0328 0796 dmload - ok
12:35:23.0437 0796 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
12:35:23.0453 0796 DMusic - ok
12:35:23.0484 0796 dpti2o - ok
12:35:23.0640 0796 driverhardwarev2 (a694d8db6d360a3bbb0bd1517f1c1aee) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
12:35:23.0656 0796 driverhardwarev2 - ok
12:35:23.0843 0796 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
12:35:23.0843 0796 drmkaud - ok
12:35:24.0000 0796 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
12:35:24.0000 0796 Fastfat - ok
12:35:24.0140 0796 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys
12:35:24.0156 0796 Fdc - ok
12:35:24.0234 0796 Fips (8b121ff880683607ab2aef0340721718) C:\WINDOWS\system32\drivers\Fips.sys
12:35:24.0234 0796 Fips - ok
12:35:24.0296 0796 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys
12:35:24.0296 0796 Flpydisk - ok
12:35:24.0421 0796 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
12:35:24.0421 0796 FltMgr - ok
12:35:24.0500 0796 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
12:35:24.0515 0796 Fs_Rec - ok
12:35:24.0531 0796 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
12:35:24.0546 0796 Ftdisk - ok
12:35:24.0593 0796 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
12:35:24.0640 0796 Gpc - ok
12:35:24.0828 0796 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
12:35:24.0875 0796 HDAudBus - ok
12:35:25.0015 0796 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
12:35:25.0015 0796 hidusb - ok
12:35:25.0062 0796 hpn - ok
12:35:25.0140 0796 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
12:35:25.0250 0796 HTTP - ok
12:35:25.0421 0796 hxctlflt (f02ea43ae8f936124debf5b87f12c795) C:\WINDOWS\system32\Drivers\hxctlflt.sys
12:35:25.0468 0796 hxctlflt - ok
12:35:25.0546 0796 i2omgmt - ok
12:35:25.0578 0796 i2omp - ok
12:35:25.0640 0796 i8042prt (d1efcbd693b5ba21314d06368c471070) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
12:35:25.0656 0796 i8042prt - ok
12:35:26.0046 0796 ialm (48846b31be5a4fa662ccfde7a1ba86b9) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
12:35:26.0296 0796 ialm - ok
12:35:26.0453 0796 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
12:35:26.0453 0796 Imapi - ok
12:35:26.0484 0796 ini910u - ok
12:35:26.0750 0796 IntcAzAudAddService (12a9dafe2266b6fa6ddbce1847347751) C:\WINDOWS\system32\drivers\RtkHDAud.sys
12:35:26.0953 0796 IntcAzAudAddService - ok
12:35:27.0062 0796 IntelIde - ok
12:35:27.0171 0796 intelppm (dd5ad1e79ac26d3f8d8828ad4627f160) C:\WINDOWS\system32\DRIVERS\intelppm.sys
12:35:27.0171 0796 intelppm - ok
12:35:27.0250 0796 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
12:35:27.0250 0796 Ip6Fw - ok
12:35:27.0328 0796 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
12:35:27.0343 0796 IpFilterDriver - ok
12:35:27.0421 0796 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
12:35:27.0421 0796 IpInIp - ok
12:35:27.0515 0796 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
12:35:27.0515 0796 IpNat - ok
12:35:27.0656 0796 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
12:35:27.0656 0796 IPSec - ok
12:35:27.0750 0796 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
12:35:27.0750 0796 IRENUM - ok
12:35:27.0843 0796 isapnp (54632f1a7de61dc3615d756f2a90fa72) C:\WINDOWS\system32\DRIVERS\isapnp.sys
12:35:27.0843 0796 isapnp - ok
12:35:27.0921 0796 JL2005C (aa964af499dfb4382f7723146ffa6a1b) C:\WINDOWS\system32\Drivers\jl2005c.sys
12:35:28.0484 0796 JL2005C - ok
12:35:28.0625 0796 Kbdclass (e798705e8dc7fab596ef6bfdf167e007) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
12:35:28.0640 0796 Kbdclass - ok
12:35:28.0734 0796 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
12:35:28.0734 0796 kmixer - ok
12:35:28.0828 0796 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
12:35:28.0875 0796 KSecDD - ok
12:35:29.0078 0796 lbrtfdc - ok
12:35:29.0187 0796 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
12:35:29.0187 0796 mnmdd - ok
12:35:29.0312 0796 Modem (5ac7e16f5b40a6da14b5f2b3ada4693e) C:\WINDOWS\system32\drivers\Modem.sys
12:35:29.0312 0796 Modem - ok
12:35:29.0359 0796 Mouclass (7d4f19411bd941e1d432a99e24230386) C:\WINDOWS\system32\DRIVERS\mouclass.sys
12:35:29.0375 0796 Mouclass - ok
12:35:29.0437 0796 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
12:35:29.0453 0796 mouhid - ok
12:35:29.0515 0796 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
12:35:29.0531 0796 MountMgr - ok
12:35:29.0546 0796 mraid35x - ok
12:35:29.0609 0796 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
12:35:29.0609 0796 MRxDAV - ok
12:35:29.0796 0796 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
12:35:29.0828 0796 MRxSmb - ok
12:35:29.0953 0796 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
12:35:29.0953 0796 Msfs - ok
12:35:30.0031 0796 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
12:35:30.0046 0796 MSKSSRV - ok
12:35:30.0125 0796 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
12:35:30.0125 0796 MSPCLOCK - ok
12:35:30.0203 0796 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
12:35:30.0218 0796 MSPQM - ok
12:35:30.0312 0796 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
12:35:30.0312 0796 mssmbios - ok
12:35:30.0390 0796 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
12:35:30.0390 0796 MSTEE - ok
12:35:30.0578 0796 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
12:35:30.0593 0796 Mup - ok
12:35:30.0718 0796 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
12:35:30.0734 0796 NABTSFEC - ok
12:35:30.0875 0796 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
12:35:30.0875 0796 NDIS - ok
12:35:30.0953 0796 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
12:35:30.0968 0796 NdisIP - ok
12:35:31.0156 0796 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
12:35:31.0171 0796 NdisTapi - ok
12:35:31.0296 0796 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
12:35:31.0296 0796 Ndisuio - ok
12:35:31.0421 0796 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:35:31.0421 0796 NdisWan - ok
12:35:31.0546 0796 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
12:35:31.0546 0796 NDProxy - ok
12:35:31.0671 0796 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
12:35:31.0671 0796 NetBIOS - ok
12:35:31.0828 0796 NetBT (39d2683fd6cc4baaa73e1dcb80631587) C:\WINDOWS\system32\DRIVERS\netbt.sys
12:35:32.0812 0796 NetBT ( Rootkit.Win32.ZAccess.h ) - infected
12:35:32.0812 0796 NetBT - detected Rootkit.Win32.ZAccess.h (0)
12:35:32.0984 0796 Npfi2p_gc (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\drivers\nic1394.sys
12:35:33.0000 0796 Npfi2p_gc - ok
12:35:33.0062 0796 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
12:35:33.0062 0796 Npfs - ok
12:35:33.0125 0796 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
12:35:33.0156 0796 Ntfs - ok
12:35:33.0328 0796 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
12:35:33.0328 0796 Null - ok
12:35:33.0406 0796 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
12:35:33.0421 0796 NwlnkFlt - ok
12:35:33.0500 0796 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
12:35:33.0515 0796 NwlnkFwd - ok
12:35:33.0593 0796 Parport (318696359ac7df48d1e51974ec527dd2) C:\WINDOWS\system32\DRIVERS\parport.sys
12:35:33.0609 0796 Parport - ok
12:35:33.0750 0796 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
12:35:33.0750 0796 PartMgr - ok
12:35:33.0828 0796 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
12:35:33.0828 0796 ParVdm - ok
12:35:33.0921 0796 PCI (7c5da5c1ed801ad8b0309d5514f0b75e) C:\WINDOWS\system32\DRIVERS\pci.sys
12:35:33.0921 0796 PCI - ok
12:35:34.0000 0796 PCIDump - ok
12:35:34.0046 0796 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys
12:35:34.0062 0796 PCIIde - ok
12:35:34.0156 0796 Pcmcia (641da274e163617ea7a33506bc6da8e3) C:\WINDOWS\system32\drivers\Pcmcia.sys
12:35:34.0171 0796 Pcmcia - ok
12:35:34.0343 0796 PDCOMP - ok
12:35:34.0390 0796 PDFRAME - ok
12:35:34.0421 0796 PDRELI - ok
12:35:34.0437 0796 PDRFRAME - ok
12:35:34.0468 0796 perc2 - ok
12:35:34.0500 0796 perc2hib - ok
12:35:34.0609 0796 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
12:35:34.0625 0796 PptpMiniport - ok
12:35:34.0734 0796 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
12:35:34.0734 0796 PSched - ok
12:35:34.0843 0796 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
12:35:34.0859 0796 Ptilink - ok
12:35:34.0937 0796 PxHelp20 (b572ed0c3e6165643fa116af20425a54) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
12:35:34.0953 0796 PxHelp20 - ok
12:35:34.0968 0796 ql1080 - ok
12:35:35.0000 0796 Ql10wnt - ok
12:35:35.0015 0796 ql12160 - ok
12:35:35.0046 0796 ql1240 - ok
12:35:35.0109 0796 ql1280 - ok
12:35:35.0187 0796 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
12:35:35.0187 0796 RasAcd - ok
12:35:35.0296 0796 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
12:35:35.0312 0796 Rasl2tp - ok
12:35:35.0390 0796 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
12:35:35.0390 0796 RasPppoe - ok
12:35:35.0468 0796 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
12:35:35.0468 0796 Raspti - ok
12:35:35.0546 0796 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
12:35:35.0562 0796 Rdbss - ok
12:35:35.0625 0796 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
12:35:35.0640 0796 RDPCDD - ok
12:35:35.0750 0796 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
12:35:35.0765 0796 rdpdr - ok
12:35:35.0921 0796 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
12:35:35.0921 0796 RDPWD - ok
12:35:36.0015 0796 redbook (2cc30b68dd62b73d444a41322cd7fc4c) C:\WINDOWS\system32\DRIVERS\redbook.sys
12:35:36.0015 0796 redbook - ok
12:35:36.0125 0796 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
12:35:36.0125 0796 ROOTMODEM - ok
12:35:36.0281 0796 RTLE8023xp (b52b25f41bf3511071a0e7d10d659c56) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
12:35:36.0296 0796 RTLE8023xp - ok
12:35:36.0406 0796 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
12:35:36.0437 0796 Secdrv - ok
12:35:36.0671 0796 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
12:35:36.0671 0796 serenum - ok
12:35:36.0812 0796 Serial (653201755ca96ab4aaa4131daf6da356) C:\WINDOWS\system32\DRIVERS\serial.sys
12:35:36.0828 0796 Serial - ok
12:35:36.0859 0796 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
12:35:36.0859 0796 Sfloppy - ok
12:35:36.0906 0796 Simbad - ok
12:35:36.0984 0796 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
12:35:36.0984 0796 SLIP - ok
12:35:37.0187 0796 SNP2UVC (a70f178299812dce4cc0e802d403be9b) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
12:35:37.0343 0796 SNP2UVC - ok
12:35:37.0453 0796 Sparrow - ok
12:35:37.0515 0796 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
12:35:37.0546 0796 splitter - ok
12:35:37.0625 0796 sr (b52181023b827acda36c1b76751ebffd) C:\WINDOWS\system32\DRIVERS\sr.sys
12:35:37.0625 0796 sr - ok
12:35:37.0765 0796 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
12:35:37.0781 0796 Srv - ok
12:35:37.0906 0796 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
12:35:37.0921 0796 streamip - ok
12:35:38.0000 0796 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
12:35:38.0000 0796 swenum - ok
12:35:38.0093 0796 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
12:35:38.0093 0796 swmidi - ok
12:35:38.0250 0796 symc810 - ok
12:35:38.0453 0796 symc8xx - ok
12:35:38.0734 0796 sym_hi - ok
12:35:39.0015 0796 sym_u3 - ok
12:35:39.0265 0796 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
12:35:39.0296 0796 sysaudio - ok
12:35:39.0718 0796 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
12:35:39.0796 0796 Tcpip - ok
12:35:40.0187 0796 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
12:35:40.0203 0796 TDPIPE - ok
12:35:40.0562 0796 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
12:35:40.0671 0796 TDTCP - ok
12:35:41.0093 0796 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
12:35:41.0125 0796 TermDD - ok
12:35:41.0250 0796 TosIde - ok
12:35:41.0343 0796 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
12:35:41.0343 0796 Udfs - ok
12:35:41.0390 0796 ultra - ok
12:35:41.0484 0796 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
12:35:41.0500 0796 Update - ok
12:35:41.0625 0796 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys
12:35:41.0640 0796 usbaudio - ok
12:35:41.0750 0796 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
12:35:41.0750 0796 usbccgp - ok
12:35:41.0875 0796 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
12:35:41.0875 0796 usbehci - ok
12:35:41.0937 0796 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
12:35:41.0937 0796 usbhub - ok
12:35:42.0015 0796 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
12:35:42.0015 0796 usbprint - ok
12:35:42.0093 0796 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
12:35:42.0109 0796 usbscan - ok
12:35:42.0156 0796 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
12:35:42.0156 0796 usbstor - ok
12:35:42.0234 0796 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
12:35:42.0234 0796 usbuhci - ok
12:35:42.0312 0796 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\WINDOWS\system32\Drivers\usbvideo.sys
12:35:42.0312 0796 usbvideo - ok
12:35:42.0406 0796 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
12:35:42.0406 0796 VgaSave - ok
12:35:42.0437 0796 ViaIde - ok
12:35:42.0531 0796 VolSnap (313b1a0d5db26dfe1c34a6c13b2ce0a7) C:\WINDOWS\system32\drivers\VolSnap.sys
12:35:42.0531 0796 VolSnap - ok
12:35:42.0718 0796 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:35:42.0734 0796 Wanarp - ok
12:35:42.0843 0796 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
12:35:42.0859 0796 wanatw - ok
12:35:42.0890 0796 WDICA - ok
12:35:42.0953 0796 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
12:35:42.0953 0796 wdmaud - ok
12:35:43.0109 0796 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
12:35:43.0109 0796 WSTCODEC - ok
12:35:43.0187 0796 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0
12:35:43.0390 0796 \Device\Harddisk0\DR0 - ok
12:35:43.0390 0796 Boot (0x1200) (2d1d1bd348c0d4fc6af6f8752b3f9073) \Device\Harddisk0\DR0\Partition0
12:35:43.0390 0796 \Device\Harddisk0\DR0\Partition0 - ok
12:35:43.0390 0796 ============================================================
12:35:43.0390 0796 Scan finished
12:35:43.0390 0796 ============================================================
12:35:43.0421 3252 Detected object count: 1
12:35:43.0421 3252 Actual detected object count: 1
12:36:27.0828 3252 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\netbt.sys) error 1813
12:36:28.0593 3252 Backup copy not found, trying to cure infected file..
12:36:28.0734 3252 Cure success, using it..
12:36:28.0921 3252 C:\WINDOWS\system32\DRIVERS\netbt.sys - will be cured on reboot
12:36:35.0828 3252 NetBT ( Rootkit.Win32.ZAccess.h ) - User select action: Cure
12:36:47.0437 0432 Deinitialize success
0
Utilisateur anonyme
28 déc. 2011 à 12:50
nickel l'ordi a du redemarrer (confirme)

===================

telecharge et enregistre ceci sur ton bureau :

Pre_Scan

Avertissement: tous les processus non-vitaux de windows seront coupés --> pas de panique.

une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition du rapport sur le bureau.

si 'outil est bloqué par l'infection utilise cette version : Version .pif

ou encore cette version renommée : Winlogon.exe

si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

si l'outil semble ne pas avoir fonctionné affiche les extensions des fichiers et renomme-le winlogon.exe , ou change son extension en .com ou .scr

Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan après redemarrage

▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

heberge le rapport sur http://pjjoint.malekal.com et donne le lien obtenu

0
voici le lien obtenu (et je confirme le redemarage du pc)
0
dsl voici le lien
http://pjjoint.malekal.com/files.php?id=20111228_j10g6m14k8m13
0
Utilisateur anonyme
28 déc. 2011 à 13:21
re

ton windows XP titanium n'est pas une version de windows legitime , je t'invite donc à te procurer une licence légale

pour info :

https://www.commentcamarche.net/faq/2981-j-utilise-une-version-piratee-de-windows
0
ok, pour la version piraté :(

mais est ce que c'est nettoyé ou y a t'il encore des manip a faire,
en tous les cas merci
0