Probleme de rootkit ou autre?
Fermé
bsp91
Messages postés
173
Date d'inscription
dimanche 12 avril 2009
Statut
Membre
Dernière intervention
23 janvier 2017
-
18 déc. 2012 à 13:57
bsp91 Messages postés 173 Date d'inscription dimanche 12 avril 2009 Statut Membre Dernière intervention 23 janvier 2017 - 18 déc. 2012 à 18:20
bsp91 Messages postés 173 Date d'inscription dimanche 12 avril 2009 Statut Membre Dernière intervention 23 janvier 2017 - 18 déc. 2012 à 18:20
A voir également:
- Probleme de rootkit ou autre?
- Anti rootkit - Télécharger - Antivirus & Antimalwares
- Rootkit hunter - Télécharger - Antivirus & Antimalwares
- Anti rootkit gratuit - Télécharger - Antivirus & Antimalwares
- Malwarebyte anti rootkit - Télécharger - Antivirus & Antimalwares
- Panda Anti-Rootkit - Télécharger - Antivirus & Antimalwares
5 réponses
Utilisateur anonyme
Modifié par lordenoy le 18/12/2012 à 14:19
Modifié par lordenoy le 18/12/2012 à 14:19
Bonjour,
Il semble que vous avez choppé un "Rogue"
Voyez cet outil
Il semble que vous avez choppé un "Rogue"
Voyez cet outil
bsp91
Messages postés
173
Date d'inscription
dimanche 12 avril 2009
Statut
Membre
Dernière intervention
23 janvier 2017
19
18 déc. 2012 à 15:15
18 déc. 2012 à 15:15
ok merci je vous tiens au courant ;)
bsp91
Messages postés
173
Date d'inscription
dimanche 12 avril 2009
Statut
Membre
Dernière intervention
23 janvier 2017
19
18 déc. 2012 à 16:12
18 déc. 2012 à 16:12
voilà ce que ça donne :
RogueKiller V8.4.0 [Dec 15 2012] par Tigzy
mail : tigzyRK<at>gmail<dot>com
Remontees : https://www.luanagames.com/index.fr.html
Site Web : https://www.luanagames.com/index.fr.html
Blog : http://tigzyrk.blogspot.com/
Systeme d'exploitation : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Demarrage : Mode normal
Utilisateur : mouths91 [Droits d'admin]
Mode : Recherche -- Date : 18/12/2012 15:36:52
¤¤¤ Processus malicieux : 0 ¤¤¤
¤¤¤ Entrees de registre : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ
¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
¤¤¤ Driver : [CHARGE] ¤¤¤
IRP[IRP_MJ_CREATE] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_CLOSE] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_DEVICE_CONTROL] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_POWER] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_SYSTEM_CONTROL] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_PNP] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
¤¤¤ Fichier HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Verif: ¤¤¤
+++++ PhysicalDrive0: SAMSUNG SP2504C +++++
--- User ---
[MBR] 66edd87ac8bcbf80d433b97a54e29838
[BSP] d9ffb2b1eafa1bca486e894476c70d64 : HP tatooed MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 233065 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 477319168 | Size: 5407 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: Seagate FreeAgentDesktop USB Device +++++
--- User ---
[MBR] efaae474bf56cd39e5d0462ccb81c6e6
[BSP] 5cab7fac78b6fe5301595cea6da44b25 : MBR Code unknown
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
Termine : << RKreport[1]_S_18122012_153652.txt >>
RKreport[1]_S_18122012_153652.txt
RogueKiller V8.4.0 [Dec 15 2012] par Tigzy
mail : tigzyRK<at>gmail<dot>com
Remontees : https://www.luanagames.com/index.fr.html
Site Web : https://www.luanagames.com/index.fr.html
Blog : http://tigzyrk.blogspot.com/
Systeme d'exploitation : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Demarrage : Mode normal
Utilisateur : mouths91 [Droits d'admin]
Mode : Recherche -- Date : 18/12/2012 15:36:52
¤¤¤ Processus malicieux : 0 ¤¤¤
¤¤¤ Entrees de registre : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ
¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
¤¤¤ Driver : [CHARGE] ¤¤¤
IRP[IRP_MJ_CREATE] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_CLOSE] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_DEVICE_CONTROL] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_POWER] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_SYSTEM_CONTROL] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
IRP[IRP_MJ_PNP] : \SystemRoot\system32\drivers\iastor.sys -> HOOKED ([MAJOR] Unknown @ 0x862231F8)
¤¤¤ Fichier HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Verif: ¤¤¤
+++++ PhysicalDrive0: SAMSUNG SP2504C +++++
--- User ---
[MBR] 66edd87ac8bcbf80d433b97a54e29838
[BSP] d9ffb2b1eafa1bca486e894476c70d64 : HP tatooed MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 233065 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 477319168 | Size: 5407 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: Seagate FreeAgentDesktop USB Device +++++
--- User ---
[MBR] efaae474bf56cd39e5d0462ccb81c6e6
[BSP] 5cab7fac78b6fe5301595cea6da44b25 : MBR Code unknown
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
Termine : << RKreport[1]_S_18122012_153652.txt >>
RKreport[1]_S_18122012_153652.txt
bsp91
Messages postés
173
Date d'inscription
dimanche 12 avril 2009
Statut
Membre
Dernière intervention
23 janvier 2017
19
18 déc. 2012 à 16:14
18 déc. 2012 à 16:14
et pour kill' em
¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.0.0.4 ¤¤¤¤¤¤¤¤¤¤
User : mouths91 (Administrateurs)
Update on 23/05/2010 by g3n-h@ckm@n ::::: 15.00
Start at: 14:20:19 | 18/12/2012
Intel(R) Core(TM)2 CPU 4300 @ 1.80GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 9.0.8112.16421
Windows Firewall Status : Enabled
C:\ -> Disque fixe local | 227,6 Go (52,37 Go free) [HP] | NTFS
D:\ -> Disque fixe local | 5,28 Go (897,08 Mo free) [RECOVERY] | NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque fixe local
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque amovible
K:\ -> Disque CD-ROM
L:\ -> Disque amovible
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\explorer.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WJATH\WpsSupplicant.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\ProgramData\hpzinstall.log
Quarantined & Deleted !! : C:\Windows\System32\avs.dll
Quarantined & Deleted !! : C:\Windows\System32\drivers\etc\hosts.msn
Quarantined & Deleted !! : C:\Windows\System32\mmfinfo.dll
Quarantined & Deleted !! : C:\Windows\system32\MSWINSCK.OCX
Quarantined & Deleted !! : C:\Users\mouths91\AppData\Local\d3d9caps.dat
Quarantined & Deleted !! : C:\Users\mouths91\AppData\Local\GDIPFONTCACHEV1.DAT
Quarantined & Deleted !! : C:\Users\mouths91\LOCAL Settings\Temp\54ca8b5f-d80f-4a85-b3e0-cb4e2cccdcf0.exe
Quarantined & Deleted !! : C:\Users\mouths91\LOCAL Settings\Temp\676342f2-0d1b-48b1-987a-e09000c63f6f.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$I2LRBEW.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$I3KDZ2Z.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$I96ANGI
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$I9C07VK.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IE509HU.pdf
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IGAH7LK.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IIOI45A.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IKIZXEV.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$ILSN9DJ.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IQWTL33.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$ISUZMZB.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$R2LRBEW.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$R3KDZ2Z.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$R9C07VK.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RE509HU.pdf
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RGAH7LK.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RIOI45A.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RKIZXEV.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RLSN9DJ.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RQWTL33.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RSUZMZB.exe
=======
Hosts :
=======
127.0.0.1 localhost
========
Registry
========
Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCU\Software\Conduit
Deleted : HKLM\Software\Classes\Interface\{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
Deleted : HKLM\Software\Conduit
=================
Internet Explorer
=================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.com/?gws_rd=ssl
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
===============
Security Center
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
cval REG_DWORD 1 (0x1)
FirstRunDisabled REG_DWORD 1 (0x1)
AntiVirusDisableNotify REG_DWORD 0 (0x0)
FirewallDisableNotify REG_DWORD 0 (0x0)
UpdatesDisableNotify REG_DWORD 0 (0x0)
AntiVirusOverride REG_DWORD 1 (0x1)
FirewallOverride REG_DWORD 1 (0x1)
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Wlansvc : Start = 2
SharedAccess : Start = 2
windefend : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
================
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys spnm.sys hal.dll >>UNKNOWN [0x861D8938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x862231f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.0.0.4 ¤¤¤¤¤¤¤¤¤¤
User : mouths91 (Administrateurs)
Update on 23/05/2010 by g3n-h@ckm@n ::::: 15.00
Start at: 14:20:19 | 18/12/2012
Intel(R) Core(TM)2 CPU 4300 @ 1.80GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 9.0.8112.16421
Windows Firewall Status : Enabled
C:\ -> Disque fixe local | 227,6 Go (52,37 Go free) [HP] | NTFS
D:\ -> Disque fixe local | 5,28 Go (897,08 Mo free) [RECOVERY] | NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque fixe local
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque amovible
K:\ -> Disque CD-ROM
L:\ -> Disque amovible
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\explorer.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WJATH\WpsSupplicant.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\ProgramData\hpzinstall.log
Quarantined & Deleted !! : C:\Windows\System32\avs.dll
Quarantined & Deleted !! : C:\Windows\System32\drivers\etc\hosts.msn
Quarantined & Deleted !! : C:\Windows\System32\mmfinfo.dll
Quarantined & Deleted !! : C:\Windows\system32\MSWINSCK.OCX
Quarantined & Deleted !! : C:\Users\mouths91\AppData\Local\d3d9caps.dat
Quarantined & Deleted !! : C:\Users\mouths91\AppData\Local\GDIPFONTCACHEV1.DAT
Quarantined & Deleted !! : C:\Users\mouths91\LOCAL Settings\Temp\54ca8b5f-d80f-4a85-b3e0-cb4e2cccdcf0.exe
Quarantined & Deleted !! : C:\Users\mouths91\LOCAL Settings\Temp\676342f2-0d1b-48b1-987a-e09000c63f6f.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$I2LRBEW.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$I3KDZ2Z.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$I96ANGI
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$I9C07VK.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IE509HU.pdf
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IGAH7LK.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IIOI45A.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IKIZXEV.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$ILSN9DJ.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$IQWTL33.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$ISUZMZB.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$R2LRBEW.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$R3KDZ2Z.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$R9C07VK.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RE509HU.pdf
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RGAH7LK.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RIOI45A.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RKIZXEV.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RLSN9DJ.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RQWTL33.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-3088393738-1579665052-972719567-1001\$RSUZMZB.exe
=======
Hosts :
=======
127.0.0.1 localhost
========
Registry
========
Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCU\Software\Conduit
Deleted : HKLM\Software\Classes\Interface\{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
Deleted : HKLM\Software\Conduit
=================
Internet Explorer
=================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.com/?gws_rd=ssl
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
===============
Security Center
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
cval REG_DWORD 1 (0x1)
FirstRunDisabled REG_DWORD 1 (0x1)
AntiVirusDisableNotify REG_DWORD 0 (0x0)
FirewallDisableNotify REG_DWORD 0 (0x0)
UpdatesDisableNotify REG_DWORD 0 (0x0)
AntiVirusOverride REG_DWORD 1 (0x1)
FirewallOverride REG_DWORD 1 (0x1)
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Wlansvc : Start = 2
SharedAccess : Start = 2
windefend : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
================
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys spnm.sys hal.dll >>UNKNOWN [0x861D8938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x862231f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
bsp91
Messages postés
173
Date d'inscription
dimanche 12 avril 2009
Statut
Membre
Dernière intervention
23 janvier 2017
19
18 déc. 2012 à 17:04
18 déc. 2012 à 17:04
toujours rien malgré les scans et tout toujours ce problème que faire svp ? merci
bsp91
Messages postés
173
Date d'inscription
dimanche 12 avril 2009
Statut
Membre
Dernière intervention
23 janvier 2017
19
18 déc. 2012 à 18:20
18 déc. 2012 à 18:20
ok merci.
Pour info j'ai lancer tellement de petit programme anti rootkit ou autre malware que j'ai pas beaucoup d'espoir...
Pour info j'ai lancer tellement de petit programme anti rootkit ou autre malware que j'ai pas beaucoup d'espoir...