BackDoor.Tdss - Demande assistance

Bonjour,

Le système utilisé est Windows 2003 (Windows Trust 4.5).
ESET NOD32 a détecté VIRUT.NBP sur un fichier temporaire et l'a mis en quarantaine.

J'ai suivi la procédure d'héradication préconisée sur ce site.
A priori plus de trace de Virut mais Dr. Web Cureit détecte à chaque redémarrage du PC la présence de BackDoor.Tdss.565

Il prétend l'héradiquer mais à chaque fois le redetecte sur 2 executables (une fois c'est C:\WINDOWS\Explorer.EXE une autre fois C:\WINDOWS\System32\svchost.exe).
L'utilisation de Combofix (préconisé ici ou ailleurs sur des variante de BackDoor.Tdss n'est pas envisageable car non compatible avec windows 2003.
Vous trouverez ci-dessous le rapport Dr. Web Cureit et Gmer. Ce dernier a relevé des anomalies sur les 2 exe mentionnés plus haut.

Dr. Web Cureit
Processus en mémoire: C:\WINDOWS\Explorer.EXE:192;;BackDoor.Tdss.565;Eradiqué.;

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-04 17:02:08
Windows 5.2.3790 Service Pack 2, v.4566
Running: 81t50z8f.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kwaiiaod.sys

---- System - GMER 1.0.15 ----

SSDT 8A15F580 ZwAssignProcessToJobObject
SSDT 8A160100 ZwDebugActiveProcess
SSDT 8A15FB30 ZwDuplicateObject
SSDT 8A15ECC0 ZwOpenProcess
SSDT 8A15EFC0 ZwOpenThread
SSDT 8A15F9C0 ZwProtectVirtualMemory
SSDT 8A15F860 ZwSetContextThread
SSDT 8A15F6E0 ZwSetInformationThread
SSDT 8A15C700 ZwSetSecurityObject
SSDT 8A15F420 ZwSuspendProcess
SSDT 8A15F2C0 ZwSuspendThread
SSDT 8A15EE50 ZwTerminateProcess
SSDT 8A15F150 ZwTerminateThread
SSDT 8A15FF50 ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB94EA000, 0x1BDE76, 0xE8000020]
init C:\WINDOWS\system32\drivers\monfilt.sys entry point in "init" section [0xAC132280]

---- User code sections - GMER 1.0.15 ----

.text C:\WINDOWS\System32\svchost.exe[768] ntdll.dll!NtProtectVirtualMemory 7C94747D 5 Bytes JMP 0083000A
.text C:\WINDOWS\System32\svchost.exe[768] ntdll.dll!NtWriteVirtualMemory 7C947D7D 5 Bytes JMP 0084000A
.text C:\WINDOWS\System32\svchost.exe[768] ntdll.dll!KiUserExceptionDispatcher 7C948570 5 Bytes JMP 0082000C
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1152] kernel32.dll!SetUnhandledExceptionFilter 7C842118 4 Bytes [C2, 04, 00, 00]
.text C:\WINDOWS\Explorer.EXE[1868] ntdll.dll!NtProtectVirtualMemory 7C94747D 5 Bytes JMP 00B1000A
.text C:\WINDOWS\Explorer.EXE[1868] ntdll.dll!NtWriteVirtualMemory 7C947D7D 5 Bytes JMP 00B2000A
.text C:\WINDOWS\Explorer.EXE[1868] ntdll.dll!KiUserExceptionDispatcher 7C948570 5 Bytes JMP 00B0000C

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)

Device \Driver\usbuhci \Device\USBPDO-0 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBPDO-1 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBPDO-2 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBPDO-3 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbehci \Device\USBPDO-4 hcmon.sys (VMware USB monitor/VMware, Inc.)

AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)

Device \Driver\usbhub \Device\00000075 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\00000076 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\00000077 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\00000078 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\00000079 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBFDO-0 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBFDO-1 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBFDO-2 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBFDO-3 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbehci \Device\USBFDO-4 hcmon.sys (VMware USB monitor/VMware, Inc.)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DesktopHeapLogging 1

---- EOF - GMER 1.0.15 ----

28 réponses

Résumé de la discussion

Un système Windows 2003 est infecté après qu'ESET NOD32 a détecté VIRUT.NBP sur un fichier temporaire et qu'une réinfection par BackDoor.Tdss.565 est signalée à chaque redémarrage. Plusieurs outils, CureIt et GMER, indiquent des anomalies persistantes et des preuves de rootkit, avec des modifications suspectes dans svchost.exe et Explorer.exe. Des résultats détaillés listent des pilotes et composants, eamon.sys et monfilt.sys, ainsi que des sections mémoire et des entrées AppInit_DLLs modifiés. Pour les cas graves, une remise à zéro ou réinstallation peut devenir nécessaire compte tenu de la persistance des traces et de l'incompatibilité des outils modernes avec Windows 2003.

Bobot (l’IA à votre service)
  1. meme si plus rien n'ennuie , ca n'est pas terminé....apres le massacre , le nettoyage ^^
    1. Salut,

      Je crois tenir la fin de mon problème. Ci-dessous le détail de mes opérations de ce soir qui ont significativement changé la donne sur les résultats d'analyse tdsskiller et drweb cureit qui détectaient depuis une semaine l'infection sans arrier à l'héradiquer.

      J'ai relancé pour commencer et être certain de partir d'un état de mon système toujours le même, càd infecté par tdss, l'opération de scan avec tdsskiller et drweb cureit.

      Résultat:

      1. Tdsskiller: le fichier atapi.sys est toujours détecté infecté et il le restore ... comme à chaque fois, ce soir à 20h29

      C:\Documents and Settings\Administrateur>dir "c:\WINDOWS\system32\drivers\atapi.sys"
      Le volume dans le lecteur C n'a pas de nom.
      Le numéro de série du volume est B844-79E7

      Répertoire de c:\WINDOWS\system32\drivers

      12/04/2010 20:29 96 768 atapi.sys
      1 fichier(s) 96 768 octets
      0 Rép(s) 25 475 903 488 octets libres

      2. DrWeb Cureit: j'ai téléchargé la version mise à jour aujourd'hui 12/04/2010 (ftp://ftp.drweb.com/pub/drweb/cureit/20100412214557/cureit.exe) j'avais auparavant celle du 03/04/2010.

      Résultat du scan analyse rapide: svchost.exe est détecté comme infecté en mémoire (comme à chaque fois...) mais là ô surprise une nouveauté est trouvée sur un fichier temp rswaecmxon.tmp

      Processus en mémoire: C:\WINDOWS\System32\svchost.exe:780;;BackDoor.Tdss.565;Eradiqué.;
      rswaecmxon.tmp;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp;Trojan.Click.25308;Supprimé.;

      3. J'ai relancé une analyse sélective avec DrWeb du C:\ en bootant sur ReatogoPE pour être sur d'analyser un disque sans fichier système chargé en mémoire. Bonne pioche encore une autre variante de Tdss détectée sur un fichier .sys:

      dmio.sys;C:\WINDOWS\system32\drivers;BackDoor.Tdss.2459;Cured.;

      4. Je reboote sur mon système Windows 2003:
      Je relance Tdsskiller: il ne trouve plus rien. C'est la première que cela arrive!!!
      Je relance scan DrWeb: il ne trouve plus rien non plus et là pareil c'est une première.

      Je vais relancer encore un scan complet malwarebyte pour m'assurer qu'il n'y a plus rien du tout, mais hier soir c'est ce que j'ai fait, sans rien trouver d'autre.
      Je vais bien voir si les symptômes de pop-up disparaissent également.

      Je patiente encore qq jours et on pourra passer en résolu si rien ne change.
      1. hello refais un complet sur tous les disques avec Malwarebytes et supprime tout ce qu'il trouve en fin de scan
        ?G3?-?@¢??@?(TM)©®?
        1. La fin de ntkrnlpa.exe est la suivante (j'ai laissé tomber la section PEinfo)

          ssdeep: 49152:iaE4A3KEw4xmC+s5PmXl6FFfTndyhLE5:iabA3PwCnP6l6FFfTnclE
          sigcheck: publisher....: Microsoft Corporation<br>copyright....: (c) Microsoft Corporation. Tous droits r_serv_s.<br>product......: Syst_me d_exploitation Microsoft_ Windows_<br>description..: Noyau et syst_me NT<br>original name: ntkrpamp.exe<br>internal name: ntkrpamp.exe<br>file version.: 5.2.3790.4566 (srv03_sp2_gdr.090805-1438)<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
          PEiD  : -
          RDS   : NSRL Reference Data Set<br>-
          1. Fichier ntkrnlpa.exe reçu le 2010.04.08 19:19:34 (UTC)
            Antivirus Version Dernière mise à jour Résultat
            a-squared 4.5.0.50 2010.04.08 -
            AhnLab-V3 5.0.0.2 2010.04.08 -
            AntiVir 7.10.6.49 2010.04.08 -
            Antiy-AVL 2.0.3.7 2010.04.08 -
            Authentium 5.2.0.5 2010.04.08 -
            Avast 4.8.1351.0 2010.04.08 -
            Avast5 5.0.332.0 2010.04.08 -
            AVG 9.0.0.787 2010.04.08 -
            BitDefender 7.2 2010.04.08 -
            CAT-QuickHeal 10.00 2010.04.08 -
            ClamAV 0.96.0.3-git 2010.04.08 -
            Comodo 4540 2010.04.08 -
            DrWeb 5.0.2.03300 2010.04.08 -
            eSafe 7.0.17.0 2010.04.08 -
            eTrust-Vet 35.2.7414 2010.04.08 -
            F-Prot 4.5.1.85 2010.04.08 -
            F-Secure 9.0.15370.0 2010.04.08 -
            Fortinet 4.0.14.0 2010.04.08 -
            GData 19 2010.04.08 -
            Ikarus T3.1.1.80.0 2010.04.08 -
            Jiangmin 13.0.900 2010.04.08 -
            Kaspersky 7.0.0.125 2010.04.08 -
            McAfee-GW-Edition 6.8.5 2010.04.08 -
            Microsoft 1.5605 2010.04.08 -
            NOD32 5011 2010.04.08 -
            Norman 6.04.11 2010.04.08 -
            nProtect 2009.1.8.0 2010.04.06 -
            Panda 10.0.2.2 2010.04.08 -
            PCTools 7.0.3.5 2010.04.08 -
            Prevx 3.0 2010.04.08 -
            Rising 22.42.03.03 2010.04.08 -
            Sophos 4.52.0 2010.04.08 -
            Sunbelt 6152 2010.04.08 -
            Symantec 20091.2.0.41 2010.04.08 -
            TheHacker 6.5.2.0.258 2010.04.08 -
            TrendMicro 9.120.0.1004 2010.04.08 -
            VBA32 3.12.12.4 2010.04.05 -
            ViRobot 2010.4.8.2267 2010.04.08 -
            VirusBuster 5.0.27.0 2010.04.08 -
            Information additionnelle
            File size: 2344448 bytes
            MD5   : f2dc96935fe0f1745c78fc0f26a86157
            SHA1  : 4cfe3d04f158a2c92f2d26dbf99d2bd1145c15ad
            SHA256: 64282b97017c1335ef85a5be6eabf2f858b7a964bee6bb75948fd0810db0111e

            La suite est trop grosse pour tenir dans un message
            1. Fichier pciide.sys reçu le 2010.04.08 19:27:08 (UTC)
              Antivirus Version Dernière mise à jour Résultat
              a-squared 4.5.0.50 2010.04.08 -
              AhnLab-V3 5.0.0.2 2010.04.08 -
              AntiVir 7.10.6.49 2010.04.08 -
              Antiy-AVL 2.0.3.7 2010.04.08 -
              Authentium 5.2.0.5 2010.04.08 -
              Avast 4.8.1351.0 2010.04.08 -
              Avast5 5.0.332.0 2010.04.08 -
              AVG 9.0.0.787 2010.04.08 -
              BitDefender 7.2 2010.04.08 -
              CAT-QuickHeal 10.00 2010.04.08 -
              ClamAV 0.96.0.3-git 2010.04.08 -
              Comodo 4540 2010.04.08 -
              DrWeb 5.0.2.03300 2010.04.08 -
              eSafe 7.0.17.0 2010.04.08 -
              eTrust-Vet 35.2.7414 2010.04.08 -
              F-Prot 4.5.1.85 2010.04.08 -
              F-Secure 9.0.15370.0 2010.04.08 -
              Fortinet 4.0.14.0 2010.04.08 -
              GData 19 2010.04.08 -
              Ikarus T3.1.1.80.0 2010.04.08 -
              Jiangmin 13.0.900 2010.04.08 -
              Kaspersky 7.0.0.125 2010.04.08 -
              McAfee-GW-Edition 6.8.5 2010.04.08 -
              Microsoft 1.5605 2010.04.08 -
              NOD32 5011 2010.04.08 -
              Norman 6.04.11 2010.04.08 -
              nProtect 2009.1.8.0 2010.04.06 -
              Panda 10.0.2.2 2010.04.08 -
              PCTools 7.0.3.5 2010.04.08 -
              Prevx 3.0 2010.04.08 -
              Rising 22.42.03.03 2010.04.08 -
              Sophos 4.52.0 2010.04.08 -
              Sunbelt 6152 2010.04.08 -
              Symantec 20091.2.0.41 2010.04.08 -
              TheHacker 6.5.2.0.258 2010.04.08 -
              TrendMicro 9.120.0.1004 2010.04.08 -
              VBA32 3.12.12.4 2010.04.05 -
              ViRobot 2010.4.8.2267 2010.04.08 -
              VirusBuster 5.0.27.0 2010.04.08 -
              Information additionnelle
              File size: 5632 bytes
              MD5   : 8233f4066db48dd66303f838e5aabfde
              SHA1  : 842ebfc180117de95ad7d3eef80e9b495719c5af
              SHA256: 816db26837e6a38046646d7a4c24dc87912344b759ac12db079f353ebf0f9646
              PEInfo: PE Structure information<br> <br> ( base data )<br> entrypointaddress.: 0x4000<br> timedatestamp.....: 0x3E7FFF8E (Tue Mar 25 08:04:46 2003)<br> machinetype.......: 0x14C (Intel I386)<br> <br> ( 6 sections )<br> name viradd virsiz rawdsiz ntrpy md5<br> .text 0x1000 0x398 0x400 5.89 68788c1d0be54fbb07e2c2b1e1d6a3ad<br>.rdata 0x2000 0x5F 0x200 0.98 e2c8c09bd8cb8fcaa5297d7897a542df<br>.data 0x3000 0xC 0x200 0.23 b33c2d8f10effa7a514b87b1005c5ec9<br>INIT 0x4000 0xFC 0x200 2.76 8c06621f66902090ccccefa13a835529<br>.rsrc 0x5000 0x47C 0x600 3.96 ff313895a24387c45d95d308474c4e1e<br>.reloc 0x6000 0x58 0x200 0.71 7b78489871d8b46403e67edb61582264<br> <br> ( 2 imports )<br> <br>> ntoskrnl.exe: KeBugCheckEx, KeTickCount<br>> pciidex.sys: PciIdeXInitialize, PciIdeXSetBusData, PciIdeXGetBusData<br> <br> ( 0 exports )<br>
              TrID  : File type identification<br>Generic Win/DOS Executable (49.9%)<br>DOS Executable Generic (49.8%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
              ssdeep: 48:i2z6dib7xDX744y9a6Gp2Q4jmdnq2ZWyX2Hs7qo8chSUVMWG:TzyibVDX744Ua6wm+q+WEqoJdVM
              sigcheck: publisher....: Microsoft Corporation<br>copyright....: (c) Microsoft Corporation. Tous droits r_serv_s.<br>product......: Syst_me d_exploitation Microsoft_ Windows_<br>description..: Pilote de bus g_n_rique PCI IDE<br>original name: pciide.sys<br>internal name: pciide.sys<br>file version.: 5.2.3790.0 (srv03_rtm.030324-2048)<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
              PEiD  : -
              packers (Kaspersky): PE_Patch
              RDS   : NSRL Reference Data Set<br><br>( Microsoft )<br><br>MSDN Disc 2439: pciide.sysMSDN Disc 2439.1: pciide.sysMSDN Disc 2439.2: pciide.sysMSDN Disc 2439.3: pciide.sysMSDN Disc 2439.6: pciide.sysMSDN Disc 2439.7: pciide.sysMSDN Disc 2439.8: pciide.sysMSDN Windows Server 2003 Standard & Enterprise: pciide.sys
              1. Fichier hal.dll reçu le 2010.04.08 19:21:24 (UTC)
                Antivirus Version Dernière mise à jour Résultat
                a-squared 4.5.0.50 2010.04.08 -
                AhnLab-V3 5.0.0.2 2010.04.08 -
                AntiVir 7.10.6.49 2010.04.08 -
                Antiy-AVL 2.0.3.7 2010.04.08 -
                Authentium 5.2.0.5 2010.04.08 -
                Avast 4.8.1351.0 2010.04.08 -
                Avast5 5.0.332.0 2010.04.08 -
                AVG 9.0.0.787 2010.04.08 -
                BitDefender 7.2 2010.04.08 -
                CAT-QuickHeal 10.00 2010.04.08 -
                ClamAV 0.96.0.3-git 2010.04.08 -
                Comodo 4540 2010.04.08 -
                DrWeb 5.0.2.03300 2010.04.08 -
                eSafe 7.0.17.0 2010.04.08 -
                eTrust-Vet 35.2.7414 2010.04.08 -
                F-Prot 4.5.1.85 2010.04.08 -
                F-Secure 9.0.15370.0 2010.04.08 -
                Fortinet 4.0.14.0 2010.04.08 -
                GData 19 2010.04.08 -
                Ikarus T3.1.1.80.0 2010.04.08 -
                Jiangmin 13.0.900 2010.04.08 -
                Kaspersky 7.0.0.125 2010.04.08 -
                McAfee-GW-Edition 6.8.5 2010.04.08 -
                Microsoft 1.5605 2010.04.08 -
                NOD32 5011 2010.04.08 -
                Norman 6.04.11 2010.04.08 -
                nProtect 2009.1.8.0 2010.04.06 -
                Panda 10.0.2.2 2010.04.08 -
                PCTools 7.0.3.5 2010.04.08 -
                Prevx 3.0 2010.04.08 -
                Rising 22.42.03.03 2010.04.08 -
                Sophos 4.52.0 2010.04.08 -
                Sunbelt 6152 2010.04.08 -
                Symantec 20091.2.0.41 2010.04.08 -
                TheHacker 6.5.2.0.258 2010.04.08 -
                TrendMicro 9.120.0.1004 2010.04.08 -
                VBA32 3.12.12.4 2010.04.05 -
                ViRobot 2010.4.8.2267 2010.04.08 -
                VirusBuster 5.0.27.0 2010.04.08 -
                Information additionnelle
                File size: 119808 bytes
                MD5   : e209a057ab4d30eabf19ca71fe36a6b6
                SHA1  : b4e41ee51498927ca48ff7066bb07bde74b964a0
                SHA256: 2a7f3503b1a50e00fa3872864abf19c3f94918192a2d5dc740b724097664baac
                PEInfo: PE Structure information<br> <br> ( base data )<br> entrypointaddress.: 0x26E90<br> timedatestamp.....: 0x45D6972A (Sat Feb 17 06:48:26 2007)<br> machinetype.......: 0x14C (Intel I386)<br> <br> ( 12 sections )<br> name viradd virsiz rawdsiz ntrpy md5<br> .text 0x1000 0x98FD 0x9A00 6.44 55082324b7c5e639374619f293e12b03<br>.data 0xB000 0xCF80 0x4A00 0.93 96c532f3c2ee2f30520da1db6b81f6a8<br>INITCONS 0x18000 0x200 0x200 0.00 bf619eac0cdf3f68d496ea9344137e8b<br>INITDAT 0x19000 0x78 0x200 0.67 2b815f5fe11944160394a4140693a9af<br>PAGELK 0x1A000 0x3936 0x3A00 6.40 f586e11815045d8b0c74bb5e2bde8cf6<br>PAGELK16 0x1E000 0x82 0x200 1.61 5fe7505eff85308dbc158fb8dc2cc406<br>PAGE 0x1F000 0x2F2C 0x3000 6.52 60b2f3417631cff1911841a9d9c1da33<br>PAGEKD 0x22000 0x137C 0x1400 6.45 721f6cba82fc471e4a487632d4fb7977<br>.edata 0x24000 0xC05 0xE00 5.07 e66082e5cfc7a2c4fa38f5026c96dc86<br>INIT 0x25000 0x3FFA 0x4000 6.63 6a6bbbb021c177e4f02cf00b1b144b95<br>.rsrc 0x29000 0x410 0x600 2.54 ec6977365c40289afaccecc4a16dd44f<br>.reloc 0x2A000 0x1270 0x1400 5.96 4dac7ea71c7356c5375e99af7ea3d4be<br> <br> ( 0 imports )<br> <br> <br> ( 0 exports )<br>
                TrID  : File type identification<br>Win32 Executable Generic (68.0%)<br>Generic Win/DOS Executable (15.9%)<br>DOS Executable Generic (15.9%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
                ssdeep: 1536:NmLhG6ADQ4UFjdaYStSqQPK2Lsw/xj/IDEojhT/FrN1HOmH:sL86AK4BkqQPKaB9/4EojhLn1HOm
                sigcheck: publisher....: Microsoft Corporation<br>copyright....: (c) Microsoft Corporation. All rights reserved.<br>product......: Microsoft_ Windows_ Operating System<br>description..: Hardware Abstraction Layer DLL<br>original name: halmacpi.dll<br>internal name: halmacpi.dll<br>file version.: 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
                PEiD  : -
                RDS   : NSRL Reference Data Set<br><br>( Microsoft )<br><br>MSDN Disc 2939.3: halmacpi.dllMSDN Disc 2939.4: halmacpi.dll
                1. Fichier ACPI.sys reçu le 2010.04.08 19:25:57 (UTC)
                  Antivirus Version Dernière mise à jour Résultat
                  a-squared 4.5.0.50 2010.04.08 -
                  AhnLab-V3 5.0.0.2 2010.04.08 -
                  AntiVir 7.10.6.49 2010.04.08 -
                  Antiy-AVL 2.0.3.7 2010.04.08 -
                  Authentium 5.2.0.5 2010.04.08 -
                  Avast 4.8.1351.0 2010.04.08 -
                  Avast5 5.0.332.0 2010.04.08 -
                  AVG 9.0.0.787 2010.04.08 -
                  BitDefender 7.2 2010.04.08 -
                  CAT-QuickHeal 10.00 2010.04.08 -
                  ClamAV 0.96.0.3-git 2010.04.08 -
                  Comodo 4540 2010.04.08 -
                  DrWeb 5.0.2.03300 2010.04.08 -
                  eSafe 7.0.17.0 2010.04.08 -
                  eTrust-Vet 35.2.7414 2010.04.08 -
                  F-Prot 4.5.1.85 2010.04.08 -
                  F-Secure 9.0.15370.0 2010.04.08 -
                  Fortinet 4.0.14.0 2010.04.08 -
                  GData 19 2010.04.08 -
                  Ikarus T3.1.1.80.0 2010.04.08 -
                  Jiangmin 13.0.900 2010.04.08 -
                  Kaspersky 7.0.0.125 2010.04.08 -
                  McAfee-GW-Edition 6.8.5 2010.04.08 -
                  Microsoft 1.5605 2010.04.08 -
                  NOD32 5011 2010.04.08 -
                  Norman 6.04.11 2010.04.08 -
                  nProtect 2009.1.8.0 2010.04.06 -
                  Panda 10.0.2.2 2010.04.08 -
                  PCTools 7.0.3.5 2010.04.08 -
                  Prevx 3.0 2010.04.08 -
                  Rising 22.42.03.03 2010.04.08 -
                  Sophos 4.52.0 2010.04.08 -
                  Sunbelt 6152 2010.04.08 -
                  Symantec 20091.2.0.41 2010.04.08 -
                  TheHacker 6.5.2.0.258 2010.04.08 -
                  TrendMicro 9.120.0.1004 2010.04.08 -
                  VBA32 3.12.12.4 2010.04.05 -
                  ViRobot 2010.4.8.2267 2010.04.08 -
                  VirusBuster 5.0.27.0 2010.04.08 -
                  Information additionnelle
                  File size: 195072 bytes
                  MD5   : 97b8cf6b9df2d2e69c22cfb7c3a69c5c
                  SHA1  : da52cdef658d6ce055c2e2fdfd069e99a7627bff
                  SHA256: 61d40a28aefc427ca8b14691e52e03a457f3a315c4bc8eb167674f9a28ff5cbc
                  PEInfo: PE Structure information<br> <br> ( base data )<br> entrypointaddress.: 0x2D459<br> timedatestamp.....: 0x45D69997 (Sat Feb 17 06:58:47 2007)<br> machinetype.......: 0x14C (Intel I386)<br> <br> ( 8 sections )<br> name viradd virsiz rawdsiz ntrpy md5<br> .text 0x1000 0x1BCDE 0x1BE00 6.53 3dd4c3eee6e178494d657f2948c9ac52<br>.rdata 0x1D000 0xB0D 0xC00 5.22 0c9c72126dccc7bab3d2cf7c50e12e31<br>.data 0x1E000 0x2AD0 0x1C00 3.70 f4bb666926efe548750b27d1496b6a13<br>PAGE 0x21000 0xAFDE 0xB000 6.61 2cddbc09de6f605ebcba411e7e16a70b<br>PAGE 0x2C000 0x40C 0x600 3.13 282dcb14e54725518269e80233c72f29<br>INIT 0x2D000 0x13BC 0x1400 5.97 94c3b0a3ca5e87eda77076d91d19e3c8<br>.rsrc 0x2F000 0x1C4C 0x1E00 4.74 7fdc2023256c026b3d1aa009fd768c2f<br>.reloc 0x31000 0x266E 0x2800 6.48 33a23a65c6e57dc412d2bb9823dbc599<br> <br> ( 3 imports )<br> <br>> hal.dll: KeStallExecutionProcessor, WRITE_PORT_USHORT, WRITE_PORT_UCHAR, READ_PORT_ULONG, READ_PORT_USHORT, READ_PORT_UCHAR, KeGetCurrentIrql, KfRaiseIrql, KfLowerIrql, HalSetBusDataByOffset, HalGetBusDataByOffset, KdComPortInUse, KfAcquireSpinLock, KfReleaseSpinLock, WRITE_PORT_ULONG<br>> ntoskrnl.exe: memmove, _snwprintf, RtlInvertRangeList, RtlAddRange, RtlInitializeRangeList, RtlFreeRangeList, KeInsertQueueDpc, InterlockedCompareExchange, IoDeleteDevice, IoAttachDeviceToDeviceStack, IoCreateDevice, IoInvalidateDeviceRelations, strstr, IoGetAttachedDeviceReference, KefReleaseSpinLockFromDpcLevel, KefAcquireSpinLockAtDpcLevel, InterlockedPopEntrySList, InterlockedPushEntrySList, KeWaitForSingleObject, KeInitializeEvent, ExfInterlockedInsertTailList, IofCompleteRequest, ObReferenceObjectByPointer, RtlCompareMemory, PoRequestPowerIrp, ExQueueWorkItem, IoReleaseCancelSpinLock, InterlockedExchange, PoSetSystemState, PoStartNextPowerIrp, PoCallDriver, IoAcquireCancelSpinLock, PoSetPowerState, KdEnableDebugger, KdDisableDebugger, IofCallDriver, ExDeleteNPagedLookasideList, ObfDereferenceObject, IoBuildSynchronousFsdRequest, IoDetachDevice, IoWriteErrorLogEntry, IoAllocateErrorLogEntry, RtlInitUnicodeString, strncpy, RtlIntegerToUnicodeString, ZwClose, RtlAnsiStringToUnicodeString, RtlInitAnsiString, ZwSetValueKey, RtlIsRangeAvailable, RtlxAnsiStringToUnicodeSize, NlsMbCodePageTag, IoSetDeviceInterfaceState, IoRegisterDeviceInterface, ExfInterlockedCompareExchange64, _alldiv, ExCreateCallback, KeSetTimer, RtlGetNextRange, RtlGetFirstRange, RtlFreeUnicodeString, RtlEqualUnicodeString, MmGetPhysicalAddress, HeadlessDispatch, IoRequestDeviceEject, PoShutdownBugCheck, RtlDeleteRange, RtlFindRange, ZwCreateKey, ZwQueryValueKey, ZwOpenKey, RtlUnicodeStringToInteger, ZwEnumerateKey, RtlFreeAnsiString, RtlUnicodeStringToAnsiString, RtlFindLeastSignificantBit, IoWMIRegistrationControl, IoWMIWriteEvent, vsprintf, ObReferenceObjectByHandle, KeClearEvent, PsTerminateSystemThread, KeWaitForMultipleObjects, PsCreateSystemThread, wcslen, ObfReferenceObject, IoFreeWorkItem, IoQueueWorkItem, IoAllocateWorkItem, KeTickCount, KeSetEvent, swprintf, sprintf, RtlCopyUnicodeString, KeQueryActiveProcessors, KeInitializeTimer, KeInitializeSpinLock, ExInitializeNPagedLookasideList, HalDispatchTable, InterlockedDecrement, IoOpenDeviceRegistryKey, InterlockedIncrement, DbgBreakPoint, ExNotifyCallback, MmMapIoSpace, MmUnmapIoSpace, DbgPrint, _vsnprintf, KeQueryInterruptTime, KeCancelTimer, ExfInterlockedRemoveHeadList, ZwSetSystemInformation, KeRevertToUserAffinityThread, KeSetSystemAffinityThread, READ_REGISTER_UCHAR, READ_REGISTER_USHORT, WRITE_REGISTER_UCHAR, WRITE_REGISTER_USHORT, RtlDeleteOwnersRanges, RtlCopyRangeList, _aullrem, IoGetDeviceProperty, _wcsicmp, ExAllocatePoolWithTag, ExFreePoolWithTag, ZwPowerInformation, KeBugCheckEx, KeInitializeDpc, ExRegisterCallback, IoConnectInterrupt<br>> wmilib.sys: WmiCompleteRequest, WmiSystemControl<br> <br> ( 0 exports )<br>
                  TrID  : File type identification<br>Win32 Executable Generic (68.0%)<br>Generic Win/DOS Executable (15.9%)<br>DOS Executable Generic (15.9%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
                  ssdeep: 3072:35X3uFKoT621bqjkoeEjf5G/teXNmJSUhVdHByde5Dm0wCrTtcRsoqxnqNEGZXl:p+bBnO5G/t8wdI/GTtcRsrnGJ
                  sigcheck: publisher....: Microsoft Corporation<br>copyright....: (c) Microsoft Corporation. Tous droits r_serv_s.<br>product......: Syst_me d_exploitation Microsoft_ Windows_<br>description..: Pilote ACPI pour NT<br>original name: ACPI.sys<br>internal name: ACPI.sys<br>file version.: 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
                  PEiD  : -
                  packers (Kaspersky): PE_Patch
                  RDS   : NSRL Reference Data Set<br>-
                  1. Fichier disk.sys reçu le 2010.04.09 06:06:20 (UTC)
                    Antivirus Version Dernière mise à jour Résultat
                    a-squared 4.5.0.50 2010.04.09 -
                    AhnLab-V3 5.0.0.2 2010.04.08 -
                    AntiVir 7.10.6.49 2010.04.08 -
                    Antiy-AVL 2.0.3.7 2010.04.08 -
                    Authentium 5.2.0.5 2010.04.09 -
                    Avast 4.8.1351.0 2010.04.08 -
                    Avast5 5.0.332.0 2010.04.08 -
                    AVG 9.0.0.787 2010.04.08 -
                    BitDefender 7.2 2010.04.09 -
                    CAT-QuickHeal 10.00 2010.04.09 -
                    ClamAV 0.96.0.3-git 2010.04.09 -
                    Comodo 4545 2010.04.09 -
                    DrWeb 5.0.2.03300 2010.04.09 -
                    eSafe 7.0.17.0 2010.04.08 -
                    eTrust-Vet 35.2.7416 2010.04.08 -
                    F-Prot 4.5.1.85 2010.04.08 -
                    F-Secure 9.0.15370.0 2010.04.09 -
                    Fortinet 4.0.14.0 2010.04.08 -
                    GData 19 2010.04.09 -
                    Ikarus T3.1.1.80.0 2010.04.09 -
                    Jiangmin 13.0.900 2010.04.09 -
                    Kaspersky 7.0.0.125 2010.04.09 -
                    McAfee-GW-Edition 6.8.5 2010.04.09 -
                    Microsoft 1.5605 2010.04.09 -
                    NOD32 5011 2010.04.08 -
                    Norman 6.04.11 2010.04.08 -
                    nProtect 2009.1.8.0 2010.04.06 -
                    Panda 10.0.2.2 2010.04.08 -
                    PCTools 7.0.3.5 2010.04.09 -
                    Prevx 3.0 2010.04.09 -
                    Rising 22.42.04.03 2010.04.09 -
                    Sophos 4.52.0 2010.04.09 -
                    Sunbelt 6154 2010.04.09 -
                    Symantec 20091.2.0.41 2010.04.09 -
                    TheHacker 6.5.2.0.258 2010.04.08 -
                    TrendMicro 9.120.0.1004 2010.04.09 -
                    VBA32 3.12.12.4 2010.04.05 -
                    ViRobot 2010.4.9.2268 2010.04.09 -
                    VirusBuster 5.0.27.0 2010.04.08 -
                    Information additionnelle
                    File size: 39936 bytes
                    MD5   : 98433302c02f1168efb7364f8111a179
                    SHA1  : dd537c3831f1267683cdb392c72b66d53fd48ca1
                    SHA256: e764f52e99f0c6352e7d25dfccdd333a899fef38693bcf9e1cfc143cde427ca5
                    PEInfo: PE Structure information<br> <br> ( base data )<br> entrypointaddress.: 0xC8BB<br> timedatestamp.....: 0x45D69BB7 (Sat Feb 17 07:07:51 2007)<br> machinetype.......: 0x14C (Intel I386)<br> <br> ( 8 sections )<br> name viradd virsiz rawdsiz ntrpy md5<br> .text 0x1000 0x23A6 0x2400 6.37 6636b7ccdb1979fd469b46d20987d36d<br>.rdata 0x4000 0x57D 0x600 4.01 ddb9be90302fd2e7fc6b7312e1ea8ded<br>.data 0x5000 0xF8 0x200 2.28 7f0143fd1b314a7451cbba31ef0d2b3a<br>PAGE 0x6000 0x48BF 0x4A00 6.48 3abe386e312944370a37b1d57b132544<br>PAGE 0xB000 0x150 0x200 1.91 8e20fe94eec58b411cc201a9e1ced327<br>INIT 0xC000 0x152E 0x1600 5.98 388354170f7d7360a6d937a45b0c2a62<br>.rsrc 0xE000 0x3D8 0x400 3.33 79ebd7d5d27ad6495adde71f451f5135<br>.reloc 0xF000 0x580 0x600 5.74 1bcfcf006467073e08b2a3b545117ee5<br> <br> ( 2 imports )<br> <br>> classpnp.sys: ClassQueryTimeOutRegistryValue, ClassUpdateInformationInRegistry, ClassInitializeMediaChangeDetection, ClassGetDeviceParameter, ClassDeleteSrbLookasideList, ClassReadDriveCapacity, ClassSignalCompletion, ClassMarkChildMissing, ClassInitializeSrbLookasideList, ClassNotifyFailurePredicted, ClassSetFailurePredictionPoll, ClassWmiCompleteRequest, ClassReleaseQueue, ClassInterpretSenseInfo, ClassSpinDownPowerHandler, ClassInitialize, ClassInitializeEx, ClassGetVpb, ClassSendDeviceIoControlSynchronous, ClassAcquireChildLock, ClassReleaseChildLock, ClassDeviceControl, ClassInvalidateBusRelations, ClassSetDeviceParameter, ClassModeSense, ClassFindModePage, ClassAcquireRemoveLockEx, ClassAsynchronousCompletion, ClassSendSrbSynchronous, ClassIoComplete, ClassReleaseRemoveLock, ClassCompleteRequest, ClassClaimDevice, ClassCreateDeviceObject, ClassScanForSpecial<br>> ntoskrnl.exe: IoWMIRegistrationControl, ExfInterlockedPopEntryList, KeInitializeSpinLock, ExQueueWorkItem, ExfInterlockedPushEntryList, MmBuildMdlForNonPagedPool, IoAllocateMdl, KeEnterCriticalRegion, KeLeaveCriticalRegion, ZwQueryValueKey, RtlUnicodeStringToInteger, IoReadDiskSignature, ZwOpenKey, IoReadPartitionTable, DbgPrint, IoReadPartitionTableEx, IoWritePartitionTableEx, IoSetPartitionInformationEx, IoSetPartitionInformation, IoVerifyPartitionTable, IoFreeMdl, RtlQueryRegistryValues, IoOpenDeviceRegistryKey, RtlxAnsiStringToUnicodeSize, NlsMbCodePageTag, sprintf, _snprintf, RtlAnsiStringToUnicodeString, RtlInitAnsiString, strncpy, IoCreateSymbolicLink, IoDeleteSymbolicLink, RtlFreeUnicodeString, IoSetDeviceInterfaceState, KeInitializeMutex, InitSafeBootMode, IoRegisterDeviceInterface, HalExamineMBR, KeTickCount, KeBugCheckEx, IoFreeIrp, IoRegisterBootDriverReinitialization, _allmul, _allrem, IoAllocateWorkItem, IoQueueWorkItem, IoReportTargetDeviceChangeAsynchronous, IoBuildDeviceIoControlRequest, IoBuildSynchronousFsdRequest, IoInvalidateDeviceRelations, memmove, IoCreateDisk, IoAllocateErrorLogEntry, IoWriteErrorLogEntry, IoAllocateIrp, IofCallDriver, _allshr, IoFreeWorkItem, KeWaitForSingleObject, KeReleaseMutex, ExAllocatePoolWithTag, KeSetEvent, strncmp, IoSetHardErrorOrVerifyDevice, _snwprintf, RtlInitUnicodeString, ZwCreateDirectoryObject, IoGetAttachedDeviceReference, ZwMakeTemporaryObject, ZwClose, ExFreePoolWithTag, IoAttachDeviceToDeviceStack, IoDeleteDevice, ObfDereferenceObject, IoGetConfigurationInformation, KeInitializeEvent<br> <br> ( 0 exports )<br>
                    TrID  : File type identification<br>Generic Win/DOS Executable (49.9%)<br>DOS Executable Generic (49.8%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
                    ssdeep: 768:K9bf9981wRgnImbcpps/Zn99meoNvHjZ31+FJsHfDXgmgld7+Xyb:K9bF981BnxiSZ9seo9j0WHfDXgmgld7l
                    sigcheck: publisher....: Microsoft Corporation<br>copyright....: (c) Microsoft Corporation. All rights reserved.<br>product......: Microsoft_ Windows_ Operating System<br>description..: PnP Disk Driver<br>original name: disk.sys<br>internal name: disk<br>file version.: 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
                    PEiD  : -
                    packers (Kaspersky): PE_Patch
                    RDS   : NSRL Reference Data Set<br><br>( Microsoft )<br><br>MSDN Disc 2939.3: disk.sysMSDN Disc 2939.4: disk.sys
                    1. Désolé pour mon absence, des priorités personnelles m'ont tenues à l'écart de mon PC ce we.

                      Je poste 1 à 1 les résultats si cela tient.

                      Fichier CLASSPNP.SYS reçu le 2010.04.08 19:23:32 (UTC)
                      Antivirus Version Dernière mise à jour Résultat
                      a-squared 4.5.0.50 2010.04.08 -
                      AhnLab-V3 5.0.0.2 2010.04.08 -
                      AntiVir 7.10.6.49 2010.04.08 -
                      Antiy-AVL 2.0.3.7 2010.04.08 -
                      Authentium 5.2.0.5 2010.04.08 -
                      Avast 4.8.1351.0 2010.04.08 -
                      Avast5 5.0.332.0 2010.04.08 -
                      AVG 9.0.0.787 2010.04.08 -
                      BitDefender 7.2 2010.04.08 -
                      CAT-QuickHeal 10.00 2010.04.08 -
                      ClamAV 0.96.0.3-git 2010.04.08 -
                      Comodo 4540 2010.04.08 -
                      DrWeb 5.0.2.03300 2010.04.08 -
                      eSafe 7.0.17.0 2010.04.08 -
                      eTrust-Vet 35.2.7414 2010.04.08 -
                      F-Prot 4.5.1.85 2010.04.08 -
                      F-Secure 9.0.15370.0 2010.04.08 -
                      Fortinet 4.0.14.0 2010.04.08 -
                      GData 19 2010.04.08 -
                      Ikarus T3.1.1.80.0 2010.04.08 -
                      Jiangmin 13.0.900 2010.04.08 -
                      Kaspersky 7.0.0.125 2010.04.08 -
                      McAfee-GW-Edition 6.8.5 2010.04.08 -
                      Microsoft 1.5605 2010.04.08 -
                      NOD32 5011 2010.04.08 -
                      Norman 6.04.11 2010.04.08 -
                      nProtect 2009.1.8.0 2010.04.06 -
                      Panda 10.0.2.2 2010.04.08 -
                      PCTools 7.0.3.5 2010.04.08 -
                      Prevx 3.0 2010.04.08 -
                      Rising 22.42.03.03 2010.04.08 -
                      Sophos 4.52.0 2010.04.08 -
                      Sunbelt 6152 2010.04.08 -
                      Symantec 20091.2.0.41 2010.04.08 -
                      TheHacker 6.5.2.0.258 2010.04.08 -
                      TrendMicro 9.120.0.1004 2010.04.08 -
                      VBA32 3.12.12.4 2010.04.05 -
                      ViRobot 2010.4.8.2267 2010.04.08 -
                      VirusBuster 5.0.27.0 2010.04.08 -
                      Information additionnelle
                      File size: 54784 bytes
                      MD5   : 85cd8241cfef25f27212acb5bb16be23
                      SHA1  : 879c90a5b5a7ccc3ea9e0167c3abec2f865867f5
                      SHA256: 04f9451ae01e5db26cf4d5107edc368db5e8367d4771958f270314444edc19df
                      PEInfo: PE Structure information<br> <br> ( base data )<br> entrypointaddress.: 0x1000F<br> timedatestamp.....: 0x45D6A080 (Sat Feb 17 07:28:16 2007)<br> machinetype.......: 0x14C (Intel I386)<br> <br> ( 9 sections )<br> name viradd virsiz rawdsiz ntrpy md5<br> .text 0x1000 0x6CA9 0x6E00 6.45 3b06f4f92bc8f3a425a33c9a7e84bf9a<br>.rdata 0x8000 0x32C 0x400 4.29 0e7657253d02c824b6d4084b084557b3<br>.data 0x9000 0x30 0x200 0.60 5e66600595f50988f0175c13d9816ff8<br>PAGE 0xA000 0x3D79 0x3E00 6.35 c9d5f4e34e9e15552441af78e3a8649c<br>.edata 0xE000 0x7BC 0x800 5.11 672c3890be21685c48c695d9b6a05a50<br>PAGE 0xF000 0x90 0x200 1.09 67de607debd776b54ee92960e47a7d89<br>INIT 0x10000 0xA50 0xC00 5.12 32e5beba8a42d2d740277c173d61b3ed<br>.rsrc 0x11000 0x400 0x400 3.42 52960a24b388fb29c1471d83af478e2f<br>.reloc 0x12000 0x5E4 0x600 6.52 3b17aaed39237d3796f58861c7951a60<br> <br> ( 2 imports )<br> <br>> hal.dll: KfLowerIrql, KfAcquireSpinLock, KfReleaseSpinLock, KfRaiseIrql<br>> ntoskrnl.exe: IoFreeWorkItem, ZwClose, RtlQueryRegistryValues, ZwCreateKey, RtlInitUnicodeString, IoOpenDeviceRegistryKey, ZwOpenKey, IoFreeIrp, IoFreeMdl, RtlCompareMemory, IoStopTimer, IoWriteErrorLogEntry, IoAllocateErrorLogEntry, KeQueryTimeIncrement, KeQuerySystemTime, _allmul, IoQueueWorkItem, IoAllocateWorkItem, IoReuseIrp, IofCallDriver, KeInitializeEvent, MmBuildMdlForNonPagedPool, IoAllocateMdl, RtlFreeUnicodeString, RtlAnsiStringToUnicodeString, ObfDereferenceObject, IoBuildDeviceIoControlRequest, IoGetAttachedDeviceReference, KeInitializeMutex, IoAllocateIrp, IoStartTimer, IoInitializeTimer, KeLeaveCriticalRegion, KeSetEvent, KeEnterCriticalRegion, IoGetDriverObjectExtension, _allshl, _alldiv, IoGetPagingIoPriority, IoStartNextPacket, MmUnlockPages, IoSetDeviceInterfaceState, IoRegisterDeviceInterface, KeInitializeSpinLock, IoInitializeIrp, KeWaitForSingleObject, KeBugCheckEx, KefAcquireSpinLockAtDpcLevel, KeGetCurrentThread, KeSetTimerEx, KeTickCount, IoGetDeviceProperty, IoStartPacket, IoSetHardErrorOrVerifyDevice, memmove, ObReferenceObjectByPointer, MmProbeAndLockPages, _except_handler3, _alldvrm, IoDeleteDevice, IoDetachDevice, IoInvalidateDeviceRelations, IoWMIRegistrationControl, ZwSetValueKey, RtlInitString, _snprintf, KeInitializeDpc, KeInitializeTimer, KeBugCheck, ObfReferenceObject, KeDelayExecutionThread, IofCompleteRequest, RtlDeleteRegistryValue, RtlCopyUnicodeString, IoAllocateDriverObjectExtension, IoCreateDevice, IoWMIWriteEvent, InterlockedPopEntrySList, PoStartNextPowerIrp, PoCallDriver, PoSetPowerState, InterlockedPushEntrySList, MmUnmapLockedPages, ExVerifySuite, IoBuildPartialMdl, KeSetTimer, strncmp, RtlWriteRegistryValue, ExDeleteNPagedLookasideList, ExInitializeNPagedLookasideList, KeReleaseMutex, ExAllocatePoolWithTag, IoReportTargetDeviceChangeAsynchronous, KefReleaseSpinLockFromDpcLevel, ExFreePoolWithTag<br> <br> ( 1 exports )<br> <br>> ClassAcquireChildLock, ClassAcquireRemoveLockEx, ClassAsynchronousCompletion, ClassBuildRequest, ClassCheckMediaState, ClassClaimDevice, ClassCleanupMediaChangeDetection, ClassCompleteRequest, ClassCreateDeviceObject, ClassDebugPrint, ClassDeleteSrbLookasideList, ClassDeviceControl, ClassDisableMediaChangeDetection, ClassEnableMediaChangeDetection, ClassFindModePage, ClassForwardIrpSynchronous, ClassGetDescriptor, ClassGetDeviceParameter, ClassGetDriverExtension, ClassGetVpb, ClassInitialize, ClassInitializeEx, ClassInitializeMediaChangeDetection, ClassInitializeSrbLookasideList, ClassInitializeTestUnitPolling, ClassInternalIoControl, ClassInterpretSenseInfo, ClassInvalidateBusRelations, ClassIoComplete, ClassIoCompleteAssociated, ClassMarkChildMissing, ClassMarkChildrenMissing, ClassModeSense, ClassNotifyFailurePredicted, ClassQueryTimeOutRegistryValue, ClassReadDriveCapacity, ClassReleaseChildLock, ClassReleaseQueue, ClassReleaseRemoveLock, ClassRemoveDevice, ClassResetMediaChangeTimer, ClassScanForSpecial, ClassSendDeviceIoControlSynchronous, ClassSendIrpSynchronous, ClassSendSrbAsynchronous, ClassSendSrbSynchronous, ClassSendStartUnit, ClassSetDeviceParameter, ClassSetFailurePredictionPoll, ClassSetMediaChangeState, ClassSignalCompletion, ClassSpinDownPowerHandler, ClassSplitRequest, ClassStopUnitPowerHandler, ClassUpdateInformationInRegistry, ClassWmiCompleteRequest, ClassWmiFireEvent
                      TrID  : File type identification<br>Generic Win/DOS Executable (49.9%)<br>DOS Executable Generic (49.8%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
                      ssdeep: 768:v1rZEKnDvcFbyPg0BAtVBChAYgY4DMR4sRBYR7qGd2FBh9oC:v71LcFKDAxChAG0I/BYBrd2FBh9o
                      sigcheck: publisher....: Microsoft Corporation<br>copyright....: (c) Microsoft Corporation. All rights reserved.<br>product......: Microsoft_ Windows_ Operating System<br>description..: SCSI Class System Dll<br>original name: Classpnp.sys<br>internal name: Classpnp.sys<br>file version.: 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
                      PEiD  : -
                      RDS   : NSRL Reference Data Set<br><br>( Microsoft )<br><br>MSDN Disc 2939.3: classpnp.sysMSDN Disc 2939.4: classpnp.sys
                      1. j'aurais bien aimé voir les rapports de chacun pour lire les signatures de fichiers.....
                        1. Résultat des courses:
                          aucun des fichiers n'est noté comme infecté par les 39 anti-virus.
                          Bonne nouvelle, non?
                          1. ? Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
                            * - Coche Afficher les fichiers et dossiers cachés
                            * - Décoche Masquer les extensions des fichiers dont le type est connu
                            * - Décoche Masquer les fichiers protégés du système d'exploitation (recommandé)

                            ? clique sur Appliquer, puis OK.

                            N'oublie pas de recacher à nouveau les fichiers cachés et protégés du système d'exploitation en fin de désinfection, c'est important

                            Fais analyser le(s) fichier(s) suivants sur Virustotal :

                            Virus Total

                            * Clique sur Parcourir en haut, choisis Poste de travail et cherche ces fichiers :

                            C:\WINDOWS\system32\ntkrnlpa.exe
                            C:\WINDOWS\system32\drivers\CLASSPNP.SYS
                            C:\WINDOWS\system32\drivers\disk.sys
                            C:\WINDOWS\system32\drivers\ACPI.sys
                            C:\WINDOWS\system32\hal.dll
                            C:\WINDOWS\system32\drivers\pciide.sys

                            * Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
                            * Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
                            * Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
                            * Une nouvelle fenêtre de ton navigateur va apparaître
                            * Clique alors sur les deux fleches
                            * Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
                            * Enfin colle le résultat dans ta prochaine réponse.

                            Note : Pour analyser un autre fichier, clique en bas sur Autre fichier.
                            ?G3?-?@¢??@?(TM)©®?
                            1. Voila le résultat: il y a eu un peu de ménage, notamment sur les fichiers temp qui je crois sont une "signature" d'une des variantes de tdss

                              Kill'em by g3n-h@ckm@n 1.7.0.2

                              User : Administrateur (Administrateurs)
                              Update on 02/04/2010 by g3n-h@ckm@n ::::: 18.00
                              Start at: 22:30:36 | 07/04/2010

                              Processeur Intel(R) Pentium(R) III Xeon
                              Microsoft(R) Windows(R) 2000 Professionnel (5.2.3790 32-bit) # Service Pack 2, v.4566
                              Internet Explorer 8.0.6001.18702
                              Windows Firewall Status : Disabled

                              C:\ -> Disque fixe local | 40 Go (23 Go free) | NTFS
                              D:\ -> Disque fixe local | 425,76 Go (2,06 Go free) [Data] | NTFS
                              F:\ -> Disque fixe local | 10 Go (3,59 Go free) [Application] | NTFS
                              G:\ -> Disque fixe local | 132,67 Go (4,25 Go free) [Données] | NTFS
                              H:\ -> Disque fixe local | 10 Go (392,45 Mo free) [System] | NTFS
                              Z:\ -> Disque CD-ROM

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\logonui.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\cmd.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe
                              C:\Program Files\List_Kill'em\ERUNT.EXE
                              C:\Program Files\List_Kill'em\pv.exe

                              Detections :
                              ==========

                              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                              Quarantined & Deleted !! : C:\WINDOWS\System32\KEYBOARD.exe
                              Quarantined & Deleted !! : C:\WINDOWS\System32\split.exe
                              Quarantined & Deleted !! : C:\WINDOWS\System32\unrar.exe
                              Quarantined & Deleted !! : C:\Documents and Settings\Administrateur\LOCAL Settings\Temp\Al0XS1Yf.dll
                              Quarantined & Deleted !! : C:\Documents and Settings\Administrateur\LOCAL Settings\Temp\swt-win32-3448.dll
                              Quarantined & Deleted !! : C:\Documents and Settings\Administrateur\LOCAL Settings\Temp\WTW2W6Gz.dll

                              ==============
                              host file OK !
                              ==============

                              ========
                              Registry
                              ========

                              Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop
                              Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
                              Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                              Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                              ========
                              Services
                              =========

                              Ndisuio : Start = 3
                              Ip6Fw : Start = 2
                              SharedAccess : Start = 2
                              wuauserv : Start = 2

                              ============
                              Disk Cleaned
                              ============

                              =================
                              anti-ver blaster : OK !!
                              =================

                              ================
                              Prefetch cleaned
                              ================

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                              1. non desolé lol ^^

                                l'option clean....;c'est une vieille fiche que j'avais , avant que le tool n'evolue , et comme je suis en train de refaire mon systeme , je n'ai pas tous les canned sous la main
                                1. Vraiment désolé, je n'ai pas compris ta dernière consigne.
                                  Je dois être à la masse.

                                  L'option 2, qu'est-ce que cela peut être?
                                  - revendre mon PC en l'état à mon pire ennemi?
                                  - prendre mon Pc et le balancer par la fenêtre... en faisant attention que personne ne se le prenne sur la tête?
                                  - renoncer à toucher mon clavier sans avoir passer au préalable un coup de gel antisseptique en insistant sur les touche H,1,N et 1?
                                  ou
                                  - croire que ce virus est un poisson d'avril envoyé par des plaisantins qui ont réussi à bousiller le we de Paques de leur victime?
                                  1. Contributeur sécurité
                                    very_ill bonjour, merci gen d'être passer à ma demande ..

                                    gen demande que tu fasses l'option 2 de list&kill"em sans plus !!

                                    . Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
                                    mais cette fois-ci :

                                    . choisis l'option 2 = Mode Suppression

                                    laisse travailler l'outil.

                                    en fin de scan un rapport s'ouvre

                                    . colle le contenu dans ta reponse
                                2. Merci gen-hackman

                                  Ci-dessous le résultat du san

                                  List'em by g3n-h@ckm@n 1.7.0.2

                                  User : Administrateur (Administrateurs)
                                  Update on 02/04/2010 by g3n-h@ckm@n ::::: 18.00
                                  Start at: 06:51:44 | 06/04/2010

                                  Processeur Intel(R) Pentium(R) III Xeon
                                  Microsoft(R) Windows(R) 2000 Professionnel (5.2.3790 32-bit) # Service Pack 2, v.4566
                                  Internet Explorer 8.0.6001.18702
                                  Windows Firewall Status : Disabled

                                  C:\ -> Disque fixe local | 40 Go (23,01 Go free) | NTFS
                                  D:\ -> Disque fixe local | 425,76 Go (2,88 Go free) [Data] | NTFS
                                  E:\ -> Disque amovible | 7,62 Go (261,12 Mo free) [SANSA FUZE] | FAT32
                                  F:\ -> Disque fixe local | 10 Go (3,59 Go free) [Application] | NTFS
                                  G:\ -> Disque fixe local | 132,67 Go (4,25 Go free) [Données] | NTFS
                                  H:\ -> Disque fixe local | 10 Go (392,45 Mo free) [System] | NTFS
                                  I:\ -> Disque amovible
                                  Z:\ -> Disque CD-ROM

                                  Boot: Normal

                                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\csrss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
                                  C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                                  C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                                  C:\portableapps\IronPortable\IronPortable.exe
                                  C:\portableapps\IronPortable\App\Iron\iron.exe
                                  C:\portableapps\IronPortable\App\Iron\iron.exe
                                  C:\portableapps\IronPortable\App\Iron\iron.exe
                                  C:\portableapps\IronPortable\App\Iron\iron.exe
                                  C:\Program Files\List_Kill'em\List_Kill'em.exe
                                  C:\WINDOWS\system32\cmd.exe
                                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                                  C:\Program Files\List_Kill'em\pv.exe

                                  ======================
                                  Keys "Run"
                                  ======================

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AutorunsDisabled

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  egui REG_SZ "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                                  TNod UP REG_SZ "C:\Program Files\Tukero[X]Team\TNod User & Password Finder\TNODUP.exe" /i
                                  GrooveMonitor REG_SZ "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                                  Malwarebytes Anti-Malware (reboot) REG_SZ "C:\portableapps\MalwarebytesPortable\App\Malwarebytes\mbam.exe" /runcleanupscript
                                  HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\AutorunsDisabled

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                                  =====================
                                  Other Keys
                                  =====================
                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                                  disablecad REG_DWORD 1 (0x1)
                                  dontdisplaylastusername REG_DWORD 0 (0x0)
                                  legalnoticecaption REG_SZ
                                  legalnoticetext REG_SZ
                                  scforceoption REG_DWORD 0 (0x0)
                                  shutdownwithoutlogon REG_DWORD 1 (0x1)
                                  undockwithoutlogon REG_DWORD 1 (0x1)
                                  NoInternetOpenWith REG_DWORD 1 (0x1)

                                  ===============
                                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                  NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                                  ForceClassicControlPanel REG_DWORD 1 (0x1)
                                  LinkResolveIgnoreLinkInfo REG_DWORD 1 (0x1)
                                  NoDesktopCleanupWizard REG_DWORD 1 (0x1)
                                  NoInstrumentation REG_DWORD 1 (0x1)
                                  NoLowDiskSpaceChecks REG_DWORD 1 (0x1)
                                  NoResolveSearch REG_DWORD 1 (0x1)
                                  NoResolveTrack REG_DWORD 1 (0x1)
                                  NoSMBalloonTip REG_DWORD 1 (0x1)
                                  NoSMConfigurePrograms REG_DWORD 1 (0x1)
                                  NoStartBanner REG_DWORD 1 (0x1)
                                  NoStartMenuMFUprogramsList REG_DWORD 1 (0x1)
                                  NoStrCmpLogical REG_DWORD 0 (0x0)
                                  NoWelcomeScreen REG_DWORD 1 (0x1)

                                  ===============
                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                  CDRAutoRun REG_DWORD 1 (0x1)
                                  HideRunAsVerb REG_DWORD 1 (0x1)
                                  NoActiveDesktop REG_DWORD 1 (0x1)
                                  NoCDBurning REG_DWORD 1 (0x1)
                                  NoDesktopCleanupWizard REG_DWORD 1 (0x1)
                                  NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                                  NoInstrumentation REG_DWORD 1 (0x1)
                                  NoNetConnectDisconnect REG_DWORD 1 (0x1)
                                  NoRemoteRecursiveEvents REG_DWORD 1 (0x1)
                                  NoResolveTrack REG_DWORD 1 (0x1)
                                  NoSetActiveDesktop REG_DWORD 1 (0x1)
                                  NoStartMenuMFUprogramsList REG_DWORD 1 (0x1)
                                  HonorAutoRunSetting REG_DWORD 1 (0x1)

                                  ===============
                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                  AppInit_DLLS REG_SZ

                                  ===============

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                  AutoRestartShell REG_DWORD 1 (0x1)
                                  DefaultDomainName REG_SZ WINDOWS-FE82175
                                  DefaultUserName REG_SZ Administrateur
                                  LegalNoticeCaption REG_SZ
                                  LegalNoticeText REG_SZ
                                  PowerdownAfterShutdown REG_SZ 1
                                  ReportBootOk REG_SZ 1
                                  Shell REG_SZ Explorer.exe
                                  ShutdownWithoutLogon REG_SZ 0
                                  System REG_SZ
                                  Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                                  VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                                  SfcQuota REG_DWORD -1 (0xffffffff)
                                  SfcDisable REG_DWORD -99 (0xffffff9d)
                                  allocatecdroms REG_SZ 0
                                  allocatedasd REG_SZ 0
                                  allocatefloppies REG_SZ 0
                                  cachedlogonscount REG_SZ 10
                                  forceunlocklogon REG_DWORD 0 (0x0)
                                  passwordexpirywarning REG_DWORD 14 (0xe)
                                  scremoveoption REG_SZ 0
                                  AllowMultipleTSSessions REG_DWORD 1 (0x1)
                                  LogonType REG_DWORD 1 (0x1)
                                  EnableConcurrentSessions REG_DWORD 1 (0x1)
                                  KeepRasConnections REG_SZ 1
                                  SlowLinkDetectEnabled REG_DWORD 0 (0x0)
                                  DisableCAD REG_DWORD 1 (0x1)
                                  UIHost REG_EXPAND_SZ %SystemRoot%\system32\logonui.exe
                                  DebugServerCommand REG_SZ no
                                  HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                                  WinStationsDisabled REG_SZ 0
                                  ShowLogonOptions REG_DWORD 1 (0x1)
                                  AltDefaultUserName REG_SZ Administrateur
                                  AltDefaultDomainName REG_SZ WINDOWS-FE82175

                                  ===============

                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                                  ===============

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                                  {B5A7F190-DDA6-4420-B3BA-52453494E6CD} REG_SZ Groove GFS Stub Execution Hook

                                  ===============
                                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                  C:\Program Files\VMware\VMware Workstation\vmware-authd.exe REG_SZ C:\Program Files\VMware\VMware Workstation\vmware-authd.exe:*:Enabled:VMware Authd
                                  C:\Program Files\uTorrent\utorrent.exe REG_SZ C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent
                                  C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
                                  C:\Program Files\Microsoft Office\Office12\GROOVE.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove
                                  C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote
                                  C:\portableapps\DreamweaverPortable\App\DreamweaverCS4\Dreamweaver.exe REG_SZ C:\portableapps\DreamweaverPortable\App\DreamweaverCS4\Dreamweaver.exe:*:Enabled:DreamweaverCS4
                                  C:\portableapps\IronPortable\App\Iron\iron.exe REG_SZ C:\portableapps\IronPortable\App\Iron\iron.exe:*:Enabled:Iron

                                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                  C:\portableapps\DreamweaverPortable\App\DreamweaverCS4\Dreamweaver.exe REG_SZ C:\portableapps\DreamweaverPortable\App\DreamweaverCS4\Dreamweaver.exe:*:Enabled:DreamweaverCS4
                                  C:\portableapps\IronPortable\App\Iron\iron.exe REG_SZ C:\portableapps\IronPortable\App\Iron\iron.exe:*:Enabled:Iron

                                  ===============
                                  ActivX controls
                                  ===============
                                  [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6414512B-B978-451D-A0D8-FCFDF33E833C}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]

                                  ===============
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{99820200-ECBD-11cf-8B85-00AA005B4340}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73fa19d0-2d75-11d2-995d-00c04f98bbc9}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{abcdf74f-9a64-4e6e-b8eb-6e5a41de6550}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F196AC50-7C95-42E1-9947-BDAB18BF3C8C}]

                                  ==============
                                  BHO :
                                  ======
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

                                  ===
                                  DNS
                                  ===

                                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{F12CBA01-D8CE-459C-9472-3F285EB51199}: DhcpNameServer=212.27.40.240 212.27.40.241
                                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{F12CBA01-D8CE-459C-9472-3F285EB51199}: DhcpNameServer=212.27.40.240 212.27.40.241
                                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{F12CBA01-D8CE-459C-9472-3F285EB51199}: DhcpNameServer=212.27.40.240 212.27.40.241
                                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
                                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
                                  HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

                                  ================
                                  Internet Explorer :
                                  ================
                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                  Start Page REG_SZ https://www.msn.com/fr-fr

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                  Start Page REG_SZ https://www.msn.com/fr-fr

                                  ========
                                  Services
                                  ========
                                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                                  Ndisuio : 0x3 ( OK = 3 )
                                  SharedAccess : 0x2 ( OK = 2 )
                                  wuauserv : 0x4 ( OK = 2 )

                                  =========
                                  Atapi.sys
                                  =========

                                  %%%% HASHDEEP-1.0
                                  %%%% size,md5,sha256,filename
                                  ## Invoked from: C:\Program Files\List_Kill'em
                                  ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
                                  ##
                                  96768,ff953a8f08ca3f822127654375786bbe,4b9cb9b31b85365f3ba49ab96bd6fd7ec6b4fe6bdd4982b4af800127a8102297,C:\WINDOWS\system32\drivers\atapi.sys
                                  %%%% HASHDEEP-1.0
                                  %%%% size,md5,sha256,filename
                                  ## Invoked from: C:\Program Files\List_Kill'em
                                  ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
                                  ##
                                  96768,ff953a8f08ca3f822127654375786bbe,4b9cb9b31b85365f3ba49ab96bd6fd7ec6b4fe6bdd4982b4af800127a8102297,C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
                                  %%%% HASHDEEP-1.0
                                  %%%% size,md5,sha256,filename
                                  ## Invoked from: C:\Program Files\List_Kill'em
                                  ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
                                  ##
                                  96768,ff953a8f08ca3f822127654375786bbe,4b9cb9b31b85365f3ba49ab96bd6fd7ec6b4fe6bdd4982b4af800127a8102297,C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

                                  Référence :
                                  ==========

                                  Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                                  Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
                                  Win XP_32b : a64013e98426e1877cb653685c5c0009
                                  Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                                  Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                                  Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                                  Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                                  Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                                  Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                                  Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                                  Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
                                  Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

                                  =======
                                  Drive :
                                  =======

                                  ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                  Present !! : C:\WINDOWS\System32\KEYBOARD.exe
                                  Present !! : C:\WINDOWS\System32\split.exe
                                  Present !! : C:\WINDOWS\System32\unrar.exe
                                  Present !! : C:\Documents and Settings\Administrateur\LOCAL Settings\Temp\Al0XS1Yf.dll
                                  Present !! : C:\Documents and Settings\Administrateur\LOCAL Settings\Temp\WTW2W6Gz.dll

                                  ¤¤¤¤¤¤¤¤¤¤ Keys :

                                  Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop
                                  Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                                  Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"

                                  ============

                                  catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                  Rootkit scan 2010-04-06 07:11:32
                                  Windows 5.2.3790 Service Pack 2, v.4566 FAT NTAPI

                                  scanning hidden processes ...

                                  scanning hidden services ...

                                  scanning hidden autostart entries ...

                                  scanning hidden files ...

                                  scan completed successfully
                                  hidden processes: 0
                                  hidden services: 0
                                  hidden files: 0

                                  Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                                  device: opened successfully
                                  user: MBR read successfully
                                  called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys >>UNKNOWN [0x8ACA38B4]<<
                                  kernel: MBR read successfully
                                  user & kernel MBR OK

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

                                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                                  End of scan : 7:11:34,26
                                  • 1
                                  • 2