Attaque réseau

Salut,

durant cette semaine, quand je suis connectée à internet, mon antivirus m'a annoncé 6 fois qu'il a décelé une attaque (de réseau), et il m'a aussi donné l'adresse IP de l'attaquant mais quand j'ai cherché son emplacement, j'ai remarqué que ce dernier ainsi que l'adresse ip sont changés d'une attaque à l'autre (je pense que cela est du au proxy que l'attaquant utilise). Je pense que cela est peut être causé par un spam??!!

Si vous pensez que c'est le cas, veuillez s'il vous plait m'aider à m'en débarrasser; sinon j'espère recevoir votre aide dans tous les cas car j'en ai vraiment besoin.

Merci d'avance

note : Hier j'ai téléchargé Ad-Aware et il a détecté 6 éléments dont il a supprimé 5 (Cookies) et mis 1 (fichier que j'ai supprimé apès) en quarantaine.



--
"La haine est la voix de celui qui a laissé la souffrance planter son drapeau aisément sur son encéphale"

46 réponses

Résumé de la discussion

Des alertes répétées d'attaque réseau ont été signalées par l'antivirus durant la semaine, l'adresse IP de l'attaquant semblant changer à chaque incident, vraisemblablement via un proxy. Plusieurs réponses recommandent des outils de diagnostic comme ZHPDiag et GMER pour repérer des rootkits et générer des rapports exploitables. D'autres conseils suggèrent d'utiliser List-Kill'em et des procédures de nettoyage associées, puis de partager les résultats via des liens de rapports afin d'obtenir une aide coordonnée. En dépit des outils évoqués, certains échanges montrent une prudence sur l'efficacité des antivirus gratuits et soulignent la nécessité de vérifier les modifications système et les éléments malveillants détectés.

Bobot (l’IA à votre service)
  1. J'ai fais un scan avec malwarebytes, et il a détecté 2 rootkit et 1 trojan, voici le rapport:

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4093

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 7.0.5730.13

    12/05/2010 00:33:58
    mbam-log-2010-05-12 (00-33-58).txt

    Type d'examen: Examen complet (C:\|D:\|E:\|)
    Elément(s) analysé(s): 299605
    Temps écoulé: 2 heure(s), 11 minute(s), 54 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 3

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    C:\System Volume Information\_restore{AAFCD855-4609-440C-BB03-F56D03119C50}\RP354\A0179994.exe (Trojan.Agent) -> No action taken.
    C:\System Volume Information\_restore{AAFCD855-4609-440C-BB03-F56D03119C50}\RP356\A0183245.sys (Rootkit.Agent) -> No action taken.
    C:\System Volume Information\_restore{AAFCD855-4609-440C-BB03-F56D03119C50}\RP356\A0183258.sys (Rootkit.Agent) -> No action taken.
    0
    1. En fait, j'ai déjà utilisé Ad-Aware puis je l'ai désinstallé; mais même après sa désinstallation il laisse un fichier LOG nommé "aaw7boot" sur C:\ dont le contenu est le suivant:

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-19 11:21
      [~] Preparing to execute queued commands
      [~] Deleting file: C:\Program Files\PHPNukeFR\PHPNukeFRToolbarHelper.exe
      [~] Finished processing queued commands

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-19 19:54

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-20 07:43

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-20 12:45

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-20 21:07

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2006-01-09 22:01

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-21 12:48

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-21 13:39

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-21 17:41

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-21 18:57

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2006-01-09 22:01

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-22 07:08

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-22 13:05

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-22 18:40

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2006-01-09 22:00

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2006-01-09 22:04

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2006-01-09 22:03

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2006-01-09 22:01

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-25 16:05

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-26 08:55

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-26 09:44

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-26 20:43

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-27 09:12

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-27 14:14

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-27 19:51

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-27 20:13

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-27 20:31

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-27 20:58

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-27 22:47

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-28 12:29

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-28 19:55

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-28 22:22

      ================================================================================
      Boot Cleaner
      ================================================================================
      [~] Cleaning started at 2010-04-28 23:22

      C'est comme si (avant sa désinstallation) Ad-Aware tentait à chaque démarrage de supprimer quelque chose...mais il n'arrivait pas à le faire.

      "La haine est la voix de celui qui a laissé la souffrance planter son drapeau aisément sur son encéphale"
      0
      1. Modérateur
        note : Hier j'ai téléchargé Ad-Aware et il a détecté 6 éléments dont il a supprimé 5 (Cookies) et mis 1 (fichier que j'ai supprimé apès) en quarantaine.

        Ad-Aware gratuit est mauvais en désinfection et protection.
        A oublier d'urgence.

        0
        1. Bonjour,
          Je sais que cela vient trop en retard mais c'est seulement par ce que ce Gmer m'a vraiment eu :p je l'ai lancé plusieurs fois avec le mode sans echec mais voilà qu'il redémarre le pc sans aucun avertissement.. alors j'ai pas pu scanner avec

          Mais jusqu'à maintenant, mon antivirus ne me donne plus d'avertissements sur une attaque, j'espère que le problème est résolu.

          Merci infiniment pour ton aide et intérêt moment de grace :)
          0
          1. Je démarre le pc en mode sans echec puis lance Gmer, c'est ça? (avec le compte d'administrateur)
            0
            1. Contributeur sécurité
              oui
              0
          2. rapport Avenger:

            Logfile of The Avenger Version 2.0, (c) by Swandog46
            http://swandog46.geekstogo.com

            Platform: Windows XP

            *******************

            Script file opened successfully.
            Script file read successfully.

            Backups directory opened successfully at C:\Avenger

            *******************

            Beginning to process script file:

            Rootkit scan active.
            No rootkits found!

            Completed script processing.

            *******************

            Finished! Terminate.
            0
            1. Contributeur sécurité
              trouve pas...

              Télécharge The Avenger sur ton Bureau.
              http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/

              --> Dézippe le fichier avenger.zip (Clique droit > Extraire).
              --> Ferme toutes les fenêtres et toutes les applications en cours et double-clique sur l'icône avenger (Icône avec l'épée).
              --> Clique sur OK pour accepter les termes d'utilisation.
              --> Une fois le programme lancé, verifie bien que :
              - La case "Scan For RootKit" soit cochée.
              - La case "Automatically disable any rootkits found" ne soit pas cochée.
              --> Clique sur Execute pour lancer le scan.
              --> Répondre Oui à ce message de confirmation.
              --> Répondre Oui pour exécuter un scan antirootkit.
              --> La première étape étant finie, The Avenger a désormais besoin de redémarrer votre PC pour finir, clique sur Oui.
              Ton PC redémarrera alors automatiquement.
              --> Au redémarrage, le rapport de The Avenger s'ouvrira automatiquement, poste-le (C:\avenger.txt).

              0
              1. C'est fait :) et voici les liens des rapports:

                Pour c:\windows\system32\drivers\lgwusbser02.sys ==> http://www.cijoint.fr/cjlink.php?file=cj201005/cijUpXorQj.txt

                Pour c:\program files\PHPNukeFR\tbPHP1.dll ==> http://www.cijoint.fr/cjlink.php?file=cj201005/cijk0gn9Ez.txt
                0
                1. Contributeur sécurité
                  Rends toi sur ce site :

                  https://www.virustotal.com/gui/

                  Clique sur parcourir et cherche ce fichier :

                  c:\windows\system32\drivers\lgwusbser02.sys
                  c:\program files\PHPNukeFR\tbPHP1.dll

                  Clique sur Send File.

                  Un rapport va s'élaborer ligne à ligne.

                  Attends la fin. Il doit comprendre la taille du fichier envoyé.

                  Sauvegarde le rapport avec le bloc-note.

                  Copie le dans ta réponse.

                  Si tu ne trouves pas le fichier alors

                  Affiche tous les fichiers et dossiers :

                  Pour cela :
                  Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                  Cocher afficher les dossiers cachés

                  Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                  Décocher masquer les extensions dont le type est connu

                  Puis fais «appliquer» pour valider les changements.

                  Et OK
                  0
                  1. J'ai retenté GMER, mais ...

                    sans rien toucher (ni clavier ni souris) il bloque et fait planter le PC à chaque fois :s
                    0
                    1. Contributeur sécurité
                      peut tu retenter GMER ?

                      /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

                      ? Télécharge : Gmer (by Przemyslaw Gmerek)

                      http://www.gmer.net/

                      ? Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

                      ? Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)
                      0
                      1. Salut ^^, rapport de Combofix:

                        ComboFix 10-04-29.05 - user 30/04/2010 21:48:09.2.2 - x86
                        Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2038.1451 [GMT 0:00]
                        Lancé depuis: c:\documents and settings\user\Bureau\ComboFix.exe
                        AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
                        FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
                        .

                        ((((((((((((((((((((((((((((( Fichiers créés du 2010-03-28 au 2010-04-30 ))))))))))))))))))))))))))))))))))))
                        .

                        2010-04-26 11:15 . 2010-04-30 19:58 -------- d-----w- c:\program files\ZHPDiag
                        2010-04-26 09:06 . 2010-04-26 09:46 -------- d-----w- C:\Kill'em
                        2010-04-25 22:52 . 2010-04-30 19:54 -------- d-----w- c:\program files\List_Kill'em
                        2010-04-21 19:07 . 2010-04-21 19:07 1894702 ----a-w- C:\UsbFix_Upload_Me_HANAA.zip
                        2010-04-19 19:51 . 2010-04-30 20:00 -------- d-----w- C:\UsbFix
                        2010-04-18 21:10 . 2010-04-18 21:10 -------- d-----w- c:\documents and settings\LocalService\Bureau
                        2010-04-18 21:00 . 2010-04-18 21:00 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
                        2010-04-18 20:47 . 2010-04-30 19:57 -------- d-----w- c:\program files\Lavasoft
                        2010-04-18 20:47 . 2010-04-29 01:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
                        2010-04-18 20:10 . 2010-04-18 20:10 5918776 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
                        2010-04-18 12:04 . 2010-04-18 12:04 -------- d-----w- c:\documents and settings\user\Application Data\Fighters
                        2010-04-18 12:01 . 2010-04-18 12:01 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{E434619C-846F-4697-8739-15F436DE9B2F}
                        2010-04-18 12:01 . 2010-04-18 12:01 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\PackageAware
                        2010-04-15 07:14 . 2009-09-23 00:31 21248 ----a-w- c:\windows\system32\drivers\lgwusbser02.sys
                        2010-04-15 07:14 . 2009-09-23 00:31 21248 ----a-w- c:\windows\system32\drivers\lgwusbser01.sys
                        2010-04-15 07:14 . 2009-09-23 00:31 25216 ----a-w- c:\windows\system32\drivers\lgwusbmodem.sys
                        2010-04-15 07:14 . 2009-09-23 00:31 13696 ----a-w- c:\windows\system32\drivers\lgwusbbus.sys
                        2010-04-15 07:13 . 2010-04-15 08:08 -------- d-----w- c:\documents and settings\user\Application Data\LG Connection Manager
                        2010-04-15 07:13 . 2010-04-26 11:43 -------- d-----w- c:\program files\LG Connection Manager
                        2010-04-14 21:21 . 2010-04-14 21:21 -------- d-----w- c:\documents and settings\user\.thumbnails
                        2010-04-14 21:19 . 2010-04-19 13:35 -------- d-----w- c:\documents and settings\user\.gimp-2.6
                        2010-04-14 21:18 . 2010-04-14 21:18 -------- d-----w- c:\program files\GIMP-2.0
                        2010-04-13 18:38 . 2010-04-13 18:38 443912 ----a-w- c:\documents and settings\user\Application Data\Real\Update\setup3.10\setup.exe

                        .
                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2010-04-30 21:54 . 2010-03-11 16:25 439328 --sha-w- c:\windows\system32\drivers\fidbox2.dat
                        2010-04-30 21:54 . 2010-03-11 16:25 10261024 --sha-w- c:\windows\system32\drivers\fidbox.dat
                        2010-04-30 21:53 . 2010-02-07 19:15 -------- d-----w- c:\documents and settings\user\Application Data\Free Download Manager
                        2010-04-30 21:43 . 2010-03-11 16:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
                        2010-04-30 21:34 . 2010-03-11 16:25 43040 --sha-w- c:\windows\system32\drivers\fidbox2.idx
                        2010-04-30 21:34 . 2010-03-11 16:25 139556 --sha-w- c:\windows\system32\drivers\fidbox.idx
                        2010-04-30 17:26 . 2010-03-11 16:26 97549 ----a-w- c:\windows\system32\drivers\klick.dat
                        2010-04-30 17:26 . 2010-03-11 16:26 113933 ----a-w- c:\windows\system32\drivers\klin.dat
                        2010-04-26 20:48 . 2001-08-24 12:00 81824 ----a-w- c:\windows\system32\perfc00C.dat
                        2010-04-26 20:48 . 2001-08-24 12:00 503894 ----a-w- c:\windows\system32\perfh00C.dat
                        2010-04-22 18:46 . 2010-01-10 01:16 -------- d-----w- c:\documents and settings\user\Application Data\DMCache
                        2010-04-22 09:43 . 2010-02-24 16:49 -------- d-----w- c:\program files\Apache Software Foundation
                        2010-04-22 09:36 . 2009-03-15 16:48 -------- d-----w- c:\program files\Apple Software Update
                        2010-04-21 18:03 . 2008-11-20 19:10 -------- d-----w- c:\documents and settings\user\Application Data\dvdcss
                        2010-04-19 13:33 . 2009-06-16 20:22 -------- d-----w- c:\documents and settings\user\Application Data\gtk-2.0
                        2010-04-18 22:17 . 2010-01-08 12:17 -------- d-----w- c:\program files\PHPNukeFR
                        2010-04-18 21:03 . 2010-02-17 14:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                        2010-04-18 12:47 . 2009-03-16 19:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
                        2010-04-15 08:19 . 2008-11-24 13:03 107768 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                        2010-04-15 07:14 . 2008-11-22 16:24 -------- d-----w- c:\program files\LG Electronics
                        2010-04-15 07:14 . 2008-11-20 17:54 -------- d--h--w- c:\program files\InstallShield Installation Information
                        2010-04-12 08:16 . 2008-11-25 22:32 357 ----a-w- c:\documents and settings\user\.cb_layout.bin
                        2010-04-10 13:50 . 2009-01-27 19:56 0 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                        2010-03-29 22:46 . 2010-02-17 14:37 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                        2010-03-29 22:45 . 2010-02-17 14:37 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
                        2010-03-24 23:10 . 2010-03-24 23:09 -------- d-----w- c:\documents and settings\user\Application Data\TeamViewer
                        2010-03-23 09:39 . 2010-03-23 09:39 -------- d-----w- c:\program files\Modem Samsung SCH-U209
                        2010-03-22 13:47 . 2010-03-22 13:47 -------- d-----w- c:\documents and settings\Administrateur\Application Data\PC Suite
                        2010-03-21 15:01 . 2010-03-21 15:01 -------- d-----w- c:\program files\Sun
                        2010-03-20 21:10 . 2010-03-20 21:07 -------- d-----w- c:\program files\Lexmark 2600 Series
                        2010-03-17 14:36 . 2009-12-23 21:46 -------- d-----w- c:\program files\Java
                        2010-03-17 14:33 . 2010-03-17 14:33 -------- d-----w- c:\program files\Fichiers communs\Java
                        2010-03-11 21:52 . 2007-07-18 13:39 112144 ----a-w- c:\windows\system32\drivers\kl1.sys
                        2010-03-11 21:51 . 2010-03-11 21:51 112144 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\X86\kl1.sys
                        2010-03-11 21:51 . 2010-03-11 21:48 715280 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\updater.dll
                        2010-03-11 21:48 . 2010-03-11 21:48 158224 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\scrchpg.dll
                        2010-03-11 21:47 . 2010-03-11 21:47 201504 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\klif.sys
                        2010-03-11 21:47 . 2010-03-11 21:47 41488 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\fssync.dll
                        2010-03-11 21:47 . 2010-03-11 21:47 342544 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\ckahum.dll
                        2010-03-11 21:46 . 2010-03-11 21:46 231952 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\avp.exe
                        2010-03-11 16:25 . 2010-03-11 16:25 -------- d-----w- c:\program files\Kaspersky Lab
                        2010-03-10 14:08 . 2009-03-16 19:06 -------- d-----w- c:\program files\MSBuild
                        2010-03-10 14:02 . 2010-03-10 14:02 -------- d-----w- c:\program files\Microsoft Visual Studio 8
                        2010-03-10 13:57 . 2010-03-10 13:57 -------- d-----w- c:\program files\MSECache
                        2010-03-05 21:19 . 2010-01-11 01:33 -------- d-----w- c:\documents and settings\All Users\Application Data\VMware
                        2010-03-05 21:13 . 2010-01-11 11:48 -------- d-----w- c:\documents and settings\user\Application Data\VMware
                        2010-03-05 18:36 . 2010-01-11 01:36 -------- d-----w- c:\documents and settings\LocalService\Application Data\VMware
                        .

                        ((((((((((((((((((((((((((((( SnapShot@2010-04-30_21.10.22 )))))))))))))))))))))))))))))))))))))))))
                        .
                        + 2010-04-30 21:43 . 2010-04-30 21:43 16384 c:\windows\Temp\Perflib_Perfdata_56c.dat
                        .
                        ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                        REGEDIT4

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                        "{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}"= "c:\program files\PHPNukeFR\tbPHP1.dll" [2010-03-29 2349080]
                        "{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}"= "c:\program files\Eazel-FR\tbEaz0.dll" [2010-03-29 2349080]

                        [HKEY_CLASSES_ROOT\clsid\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]

                        [HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]

                        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
                        2010-03-29 15:52 2349080 ----a-w- c:\program files\PHPNukeFR\tbPHP1.dll

                        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
                        2010-03-29 15:54 2349080 ----a-w- c:\program files\Eazel-FR\tbEaz0.dll

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                        "{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}"= "c:\program files\PHPNukeFR\tbPHP1.dll" [2010-03-29 2349080]
                        "{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}"= "c:\program files\Eazel-FR\tbEaz0.dll" [2010-03-29 2349080]

                        [HKEY_CLASSES_ROOT\clsid\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]

                        [HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                        "{258FE8B8-A13C-4B91-9A0C-C2D3CAB8B990}"= "c:\program files\PHPNukeFR\tbPHP1.dll" [2010-03-29 2349080]
                        "{A8F9752D-E2B8-4E7A-86B5-499F4330E2FE}"= "c:\program files\Eazel-FR\tbEaz0.dll" [2010-03-29 2349080]

                        [HKEY_CLASSES_ROOT\clsid\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]

                        [HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
                        "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-15 39408]
                        "REVAService"="c:\program files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe" [2008-12-02 23040]
                        "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
                        "Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2009-01-31 3399727]
                        "Z810SysStart"="c:\program files\Modem Samsung SCH-U209\sysctrlU.exe" [2009-02-11 311296]
                        "Z810PNP"="c:\program files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe" [2009-02-13 176128]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "NokiaMServer"="c:\program files\Fichiers communs\Nokia\MPlatform\NokiaMServer" [X]
                        "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
                        "RTHDCPL"="RTHDCPL.EXE" [2007-05-29 16132608]
                        "AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-12 53248]
                        "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-21 142104]
                        "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-21 162584]
                        "Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-21 138008]
                        "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-03-15 198160]
                        "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-23 149280]
                        "lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2007-12-17 660136]
                        "EzPrint"="c:\program files\Lexmark 2600 Series\ezprint.exe" [2007-12-17 107176]

                        c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
                        BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176]
                        DSLMON.lnk - c:\program files\Menara\dslmon.exe [2009-6-14 966756]
                        Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                        "HonorAutoRunSetting"= 0 (0x0)

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                        "HonorAutoRunSetting"= 0 (0x0)

                        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                        "AntiVirusOverride"=dword:00000001
                        "FirewallOverride"=dword:00000001

                        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
                        "DisableMonitoring"=dword:00000001

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                        "EnableFirewall"= 0 (0x0)

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                        "%windir%\\system32\\sessmgr.exe"=
                        "c:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe"=
                        "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
                        "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                        "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                        "c:\\Program Files\\Packet Tracer 5.0\\bin\\PacketTracer5.exe"=
                        "c:\\Program Files\\Recosoft PDF2Office\\PDF2Office v5.0\\PDF2Office.exe"=
                        "c:\\Program Files\\Recosoft PDF2Office\\PDF2Office v5.0\\PDF2OfficeDesktopServer.exe"=
                        "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                        "c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
                        "c:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE"=
                        "c:\\WINDOWS\\system32\\lxdncoms.exe"=
                        "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnpswx.exe"=
                        "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdntime.exe"=
                        "c:\\Program Files\\Lexmark 2600 Series\\lxdnmon.exe"=
                        "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
                        "c:\\Documents and Settings\\user\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=
                        "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnjswx.exe"=
                        "c:\\Documents and Settings\\user\\Mes documents\\cours\\FSTS\\JAVA\\eclipse\\eclipse.exe"=

                        R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [06/03/2010 10:51 100944]
                        R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [06/03/2010 10:49 41424]
                        R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service --> c:\windows\system32\lxdncoms.exe -service [?]
                        R2 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE --> c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE [?]
                        R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/05/2007 16:49 24344]
                        R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [21/03/2010 15:03 79888]
                        R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [29/05/2009 19:12 87760]
                        S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [08/01/2010 16:17 715248]
                        S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [20/03/2010 21:09 98984]
                        S2 OracleXETNSListener;OracleXETNSListener;c:\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE [01/02/2006 23:49 204800]
                        S3 Tomcat6;Apache Tomcat 6;c:\program files\Apache Software Foundation\Tomcat 6.0\bin\tomcat6.exe [09/03/2010 17:06 61440]
                        S3 UsbEvdoAtc;LGE EVDO USB Serial Port;c:\windows\system32\DRIVERS\lgevdoatc.sys --> c:\windows\system32\DRIVERS\lgevdoatc.sys [?]
                        S3 usbevdobus;LGE EVDO Composite USB Device;c:\windows\system32\DRIVERS\lgevdobus.sys --> c:\windows\system32\DRIVERS\lgevdobus.sys [?]
                        S3 UsbEvdoDiag;LGE EVDO USB Serial DM Port;c:\windows\system32\DRIVERS\lgevdodiag.sys --> c:\windows\system32\DRIVERS\lgevdodiag.sys [?]
                        S3 UsbEvdomAtc;LGE EVDOM USB Serial Port;c:\windows\system32\drivers\lgevdomatc.sys [08/04/2009 22:03 19840]
                        S3 usbevdombus;LGE EVDOM Composite USB Device;c:\windows\system32\drivers\lgevdombus.sys [08/04/2009 22:03 13696]
                        S3 UsbEvdomDiag;LGE EVDOM USB Serial DM Port;c:\windows\system32\drivers\lgevdomdiag.sys [08/04/2009 22:03 19840]
                        S3 USBEVDOmModem;LGE EVDOM USB Modem;c:\windows\system32\drivers\lgevdommodem.sys [08/04/2009 22:03 21632]
                        S3 USBEVDOModem;LGE EVDO USB Modem;c:\windows\system32\DRIVERS\lgevdomodem.sys --> c:\windows\system32\DRIVERS\lgevdomodem.sys [?]
                        S3 UsblgwmAtc;LGE Wireless USB Serial02 Device;c:\windows\system32\drivers\lgwusbser02.sys [15/04/2010 07:14 21248]
                        S3 usblgwmbus;LGE Wireless Composite USB Device;c:\windows\system32\drivers\lgwusbbus.sys [15/04/2010 07:14 13696]
                        S3 UsblgwmDiag;LGE Wireless USB Serial01 Device;c:\windows\system32\drivers\lgwusbser01.sys [15/04/2010 07:14 21248]
                        S3 USBlgwmModem;LGE Wireless USB Modem;c:\windows\system32\drivers\lgwusbmodem.sys [15/04/2010 07:14 25216]
                        S4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE --> c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE [?]
                        .
                        Contenu du dossier 'Tâches planifiées'

                        2010-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
                        - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
                        .
                        .
                        ------- Examen supplémentaire -------
                        .
                        uStart Page = hxxp://www.google.com/
                        uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCxdm345YYMA&fl=0&ptb=_yFo.BNAqqvM_H6PHlj1_w&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
                        IE: Ajouter à Kaspersky Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\ie_banner_deny.htm
                        IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
                        IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                        IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                        IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                        IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                        IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                        IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
                        IE: Tout télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
                        IE: Télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
                        IE: Télécharger la sélection avec Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
                        IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
                        TCP: {EA1660F8-3782-493E-B3DF-6967A2A233AC} = 192.168.1.200,212.217.0.1
                        FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\of0vzbp9.default\
                        FF - prefs.js: browser.search.selectedEngine - Yahoo
                        FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&p=
                        FF - component: c:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
                        FF - plugin: c:\program files\Microsoft Silverlight\3.0.50106.0\npctrl.1.0.20926.0.dll
                        FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

                        ---- PARAMETRES FIREFOX ----
                        c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
                        c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
                        c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
                        c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
                        .

                        **************************************************************************

                        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2010-04-30 21:54
                        Windows 5.1.2600 Service Pack 2 NTFS

                        Recherche de processus cachés ...

                        Recherche d'éléments en démarrage automatique cachés ...

                        HKCU\Software\Microsoft\Windows\CurrentVersion\Run
                        Z810SysStart = c:\program files\Modem Samsung SCH-U209\sysctrlU.exe???w????s??wR??w??Y?}???????b??w????????????????4???s??|??????????Y?}???????????????D?A????w???w???w'??????????????????w?;??????L??????w'???????????????'?????A?'???????????????r?A?'?????????????????????A
                        Z810PNP = c:\program files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe???? ??|'??|????]??|pi?w???????? ???D??????w ??? ??????????w???w|???|??????w???w ???????????????T??????w???????w???w???????w??@? ???P???P??????w??@?????????????????x?"|x?"|????l?6M%??????

                        Recherche de fichiers cachés ...

                        Scan terminé avec succès
                        Fichiers cachés: 0

                        **************************************************************************
                        .
                        --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0e7e038b-91b3-4b70-a21f-8f9520d6cc44}]
                        @Denied: (Full) (Everyone)
                        "Model"=dword:0000006f
                        "Therad"=dword:00000001
                        "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
                        1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

                        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
                        @Denied: (Full) (Everyone)
                        "scansk"=hex(0):d9,8f,5d,91,27,c7,f6,72,fb,0e,77,b7,a8,d9,5a,f9,ad,8a,8f,7b,b2,
                        72,52,28,85,8b,e3,8a,4c,72,b3,78,d1,e3,bb,4c,a0,f5,a0,b0,00,00,00,00,00,00,\

                        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
                        @Denied: (Full) (Everyone)
                        "scansk"=hex(0):38,92,8d,83,2c,2f,4c,0d,32,49,95,63,b4,8a,32,37,aa,3c,8a,51,a9,
                        44,f4,e4,40,c7,78,5c,03,50,7f,fa,ef,94,de,39,ad,b8,2d,dc,00,00,00,00,00,00,\

                        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c812e4ce-a1e6-483f-bcbf-cfbeb5b9637d}]
                        @Denied: (Full) (Everyone)
                        "Model"=dword:00000018
                        "Therad"=dword:0000001f
                        "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
                        38,95,44,51,c4,5c,06,a5,56,2b,b8,ce,4a,c2,09,3e,66,22,82,83,e0,8b,c5,07,bb,\

                        [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð*€|ÿÿÿÿ.*€|þ»Ñw*]
                        "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                        .
                        --------------------- DLLs chargées dans les processus actifs ---------------------

                        - - - - - - - > 'winlogon.exe'(1728)
                        c:\windows\system32\klogon.dll

                        - - - - - - - > 'explorer.exe'(2104)
                        c:\windows\system32\btmmhook.dll
                        c:\windows\system32\WPDShServiceObj.dll
                        c:\windows\system32\PortableDeviceTypes.dll
                        c:\windows\system32\PortableDeviceApi.dll
                        .
                        Heure de fin: 2010-04-30 21:56:18
                        ComboFix-quarantined-files.txt 2010-04-30 21:56
                        ComboFix2.txt 2010-04-30 21:16

                        Avant-CF: 2 644 439 040 octets libres
                        Après-CF: 2 606 354 432 octets libres

                        - - End Of File - - 53FAD6B7175F5E5ADBB037BB2D5C7137
                        0
                        1. Contributeur sécurité
                          Attention, avant de commencer, lit attentivement la procédure, et imprime la

                          Aide à l'utilisation
                          https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                          Télécharge ComboFix de sUBs sur ton Bureau :

                          http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                          /!\ Déconnecte-toi du net et DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\

                          ---> Double-clique sur ComboFix.exe
                          Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

                          SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
                          (si il te propose de l'installer remets internet)

                          ---> Mets-le en langue française F
                          Tape sur la touche 1 (Yes) pour démarrer le scan.

                          Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

                          En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                          Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                          /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                          Note : Le rapport se trouve également là : C:\ComboFix.txt

                          0
                          1. Mais le message d'attaque apparait encore de temps en temps
                            0
                            1. Salut,

                              J'ai fais un scan complet avec mon antivirus et il n'a rien détecté, mais avec Gmer ça ne va pas vraiment bien car avant hier il bloquait à chaque fois avant de finir le scan, et hier il a pris beaucoup de temps mais après le pc a soudain redémarré alors j'ai pas pu récupérer le rapport (mais lors du scan, il n'y avait aucune ligne rouge)
                              0
                              1. J''ai le même problème que list&kill'em avec le lien de gmer (snif)
                                "La haine est la voix de celui qui a laissé la souffrance planter son drapeau aisément sur son encéphale"
                                0
                                1. Contributeur sécurité
                                  salut Gen...déjà réveillé ..!
                                  (sourire)

                                  /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

                                  ? Télécharge : Gmer (by Przemyslaw Gmerek)

                                  http://www.gmer.net/

                                  ? Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

                                  ? Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)
                                  0
                                  1. salut le MBR est clean aussi dans le rapport de List_Kill'em mais il indique certainement un ficher patché...

                                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                                    device: opened successfully
                                    user: MBR read successfully
                                    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A5C11F8]<<
                                    kernel: MBR read successfully
                                    detected MBR rootkit hooks:
                                    \Driver\atapi -> 0x8a5c11f8
                                    Warning: possible MBR rootkit infection !
                                    user & kernel MBR OK
                                    Use "Recovery Console" command "fixmbr" to clear infection !
                                    0
                                    • 1
                                    • 2
                                    • 3