Forums Zebulon.fr: Trojan FakeAlert menace dangereuse [ Resolu] - Forums Zebulon.fr

Aller au contenu

  • (2 Pages)
  • +
  • 1
  • 2
  • Vous ne pouvez pas commencer un sujet
  • Vous ne pouvez pas répondre à ce sujet

Trojan FakeAlert menace dangereuse [ Resolu] Noter : -----

#1 L'utilisateur est hors-ligne   Aioros 

  • Member
  • Groupe : Membres
  • Messages : 34
  • Inscrit(e) : 13-janvier 09

Posté 24 décembre 2009 - 12:28

Bonjour à tous, je viens vous solliciter pour un problème à mon avis non négligeable. Depuis ce matin, un logiciel appelé " Malware Defense" ne cesse d'ouvrir des fenêtres et me disant que j'ai tel ou tel virus sur mon pc et que je dois désinstaller toute une série de programme, entre autre mon antivirus. Je n'ai rien accepté de tout ça. Mon pc est également ralentit depuis.

Un anti-spyware vient de faire un scan et m'a détecté 8 infections dont 2 dangereuses : "Trojan.FakeAlert" et "Rootkit.TDSS"

Mon pc met plus de 5-10 minutes pour démarrer et je ne peux rien faire dessus, après 5 minutes il plante :P

Pourriez vous m'aider svp ?

Ce message a été modifié par Aioros - 27 décembre 2009 - 11:32 .

0

PUBLICITÉ

  • Annonces Google

#2 L'utilisateur est hors-ligne   Aioros 

  • Member
  • Groupe : Membres
  • Messages : 34
  • Inscrit(e) : 13-janvier 09

Posté 24 décembre 2009 - 06:25

Personne qui a une aide à me proposer?

Désolé double poste, plantage PC :P

Ce message a été modifié par Aioros - 24 décembre 2009 - 06:33 .

0

#3 L'utilisateur est hors-ligne   Aioros 

  • Member
  • Groupe : Membres
  • Messages : 34
  • Inscrit(e) : 13-janvier 09

Posté 24 décembre 2009 - 06:32

Personne qui a une aide à me proposer ?
0

#4 L'utilisateur est hors-ligne   pear 

  • Devil Member !
  • Groupe : Equipe Sécurité
  • Messages : 16496
  • Inscrit(e) : 22-mars 05

Posté 24 décembre 2009 - 06:49

Bonsoir,

Télécharger load_tdsskiller de Loup Blanc sur le Bureau
Cet outil est conçu pour automatiser différentes tâches proposées par TDSSKiller, un fix de Kaspersky.
  • Lancer load_tdsskiller en double-cliquant dessus :
    l'outil va se connecter au Net pour télécharger une copie à jour de TDSSKiller et lancer le scan
  • Un message dans la fenêtre noire d'invite de commande vous demandera d'appuyer sur une touche pour continuer
  • Le rapport s'affichera automatiquement : copier-coller son contenu dans la prochaine réponse
    (le fichier est également présent ici : C:\tdsskiller\report.txt)
  • Redémarrer le PC



Vous allez télécharger Combofix.
Ce logiciel est très puissant et ne doit pas être utilisé sans une aide compétente sous peine de risquer des dommages irréversibles.
Veuillez noter que ce logiciel est régulièrement mis à jour et que la version que vous allez charger sera obsolète dans quelques jours.

Télécharger combofix.exe de sUBs

Vous devriez avoir une fenêtre vous avertissant que vous téléchargez Combofix depuis un site non-autorisé.
N'en tenez pas compte


Lancez Combofix en double cliquant

Tout d'abord, Combofix vérifie si la Console de récupération est installée et vous propose de le faire dans le cas contraire.
Certaines infections comme braviax empêcheront son installation.
Les utilisateurs de Windows Vista peuvent utiliser leur CD Windows pour démarrer en mode Vista Recovery Environment (Environnement de réparation Vista)
La Console de récupération Windows vous permettra de démarrer dans un mode spécial de récupération (réparation).
Elle peut être nécessaire si votre ordinateur rencontre un problème après une tentative de nettoyage.
C'est une procédure simple, qui ne vous prendra que peu de temps et pourra peut-être un jour vous sauver la mis

Certaines infections (Rootkit en Mbr)ne peuvent être traitées qu'en utilisant la Console de Récupération,
D'importantes procédures que Combofix est susceptible de lancer ne fonctionneront qu'à la condition que la console de récupération(Sous Xp) soit installée
C'est pourquoi il vous est vivement conseillé d' installer d'abord la Console de Récupération sur le pc .

Cela permettra de réparer le système au cas ou le pc ne redémarrerait plus suite à la désinfection.
* Après avoir cliqué sur le lien correspondant à votre version de Windows, vous serez dirigé sur une page:
cliquez sur le bouton Télécharger afin de récupérer le package d'installation sur leBureau:
Ne modifiez pas le nom du fichier
Windows XP Service Pack 2 (SP2) > Microsoft Windows XP Professionnel SP2
* Faites un glisser/déposer de ce fichier sur le fichier ComboFix.exe

Image IPB

* Suivre les indications à l'écran pour lancer ComboFix et lorsqu'on le demande, accepter le Contrat de Licence d'Utilisateur Final pour installer la Console de Récupération Microsoft.
Après installation,vous devriez voir ce message:
The Recovery Console was successfully installed.

Fermez ou désactivez tous les programmes Antivirus, Antispyware, Pare-feu actifs ,Teatimer de Spybot car ils pourraient perturber le fonctionnement de cet outil
Vous devez désactiver vos protections et ne savez pas comment faire

Sur Bleeping Computers en Anglais:

Sur PCA,En Français
Cela est absolument nécessaire au succès de la procédure.
Bien évidemment, vous les rétablirez ensuite.
Connecter tous les disques amovibles (disque dur externe, clé USB…).
*Double cliquer sur combofix.exe pour le lancer.

Ne pas fermer la fenêtre qui vient de s'ouvrir , le bureau serait vide et cela pourrait entraîner un plantage du programme!
Pour lancer le scan

* Taper sur la touche 1 pour démarrer le scan.
Si pour une raison quelconque combofix ne se lançait pas,
Démarrez en mode sans échec, choisissez le compte Administrateur,(sous Vista désactivez UAC) lancez Combofix
Lorsque ComboFix tourne, ne touchez plus du tout à votre ordinateur, vous risqueriez de planter le programme.

* Le scan pourrait prendre un certain temps:
Patientez au moins 30 minutes pendant l'analyse. Si le programme gèle (+ de 30 minutes), fermez le en cliquant le "X" au haut à droite de la fenêtre.
A la fin,,un rapport sera généré : postez en le contenu dans un prochain message.
* Si le rapport est trop long, postez le en deux fois.
Il se trouve à c:\combofix.txt

Si ce que tu as à dire ne vaut pas mieux que le silence, tais-toi (Confucius)
0

#5 L'utilisateur est hors-ligne   Aioros 

  • Member
  • Groupe : Membres
  • Messages : 34
  • Inscrit(e) : 13-janvier 09

Posté 25 décembre 2009 - 03:40

Voici les 2 rapports générés par les applications que vous m'avez link :

03:08:49:000 4036 TDSSKiller 2.1.1 Dec 20 2009 02:40:02
03:08:49:000 4036 ================================================================================
03:08:49:000 4036 SystemInfo:

03:08:49:000 4036 OS Version: 5.1.2600 ServicePack: 3.0
03:08:49:000 4036 Product type: Workstation
03:08:49:000 4036 ComputerName: QUENTIN
03:08:49:000 4036 UserName: HP_Propriétaire
03:08:49:000 4036 Windows directory: C:\WINDOWS
03:08:49:000 4036 Processor architecture: Intel x86
03:08:49:000 4036 Number of processors: 2
03:08:49:000 4036 Page size: 0x1000
03:08:49:000 4036 Boot type: Normal boot
03:08:49:000 4036 ================================================================================
03:08:49:156 4036 ForceUnloadDriver: NtUnloadDriver error 2
03:08:49:187 4036 main: Driver KLMD_Boot successfully unloaded
03:08:49:687 4036 ForceUnloadDriver: NtUnloadDriver error 2
03:08:49:718 4036 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\Drivers\KLMD.sys) returned status 0
03:08:49:718 4036 main: Driver KLMD successfully dropped
03:08:50:062 4036 main: Driver KLMD successfully loaded
03:08:50:062 4036
Scanning Registry ...
03:08:50:062 4036 ScanServices: Searching service UACd.sys
03:08:50:062 4036 ScanServices: Open/Create key error 2
03:08:50:062 4036 ScanServices: Searching service TDSSserv.sys
03:08:50:062 4036 ScanServices: Open/Create key error 2
03:08:50:062 4036 ScanServices: Searching service gaopdxserv.sys
03:08:50:062 4036 ScanServices: Open/Create key error 2
03:08:50:062 4036 ScanServices: Searching service gxvxcserv.sys
03:08:50:062 4036 ScanServices: Open/Create key error 2
03:08:50:062 4036 ScanServices: Searching service MSIVXserv.sys
03:08:50:062 4036 ScanServices: Open/Create key error 2
03:08:50:062 4036 UnhookRegistry: Kernel module file name: C:\windows\system32\ntkrnlpa.exe, base addr: 804D7000
03:08:50:531 4036 UnhookRegistry: Kernel local addr: D10000
03:08:50:531 4036 UnhookRegistry: KeServiceDescriptorTable addr: D95700
03:08:50:531 4036 UnhookRegistry: KiServiceTable addr: D3D460
03:08:50:531 4036 UnhookRegistry: NtEnumerateKey service number (local): 47
03:08:50:531 4036 UnhookRegistry: NtEnumerateKey local addr: E5CFF2
03:08:50:531 4036 KLMD_OpenDevice: Trying to open KLMD device
03:08:50:531 4036 KLMD_GetSystemRoutineAddressA: Trying to get system routine address ZwEnumerateKey
03:08:50:531 4036 KLMD_GetSystemRoutineAddressW: Trying to get system routine address ZwEnumerateKey
03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x805002C9[0x4]
03:08:50:531 4036 UnhookRegistry: NtEnumerateKey service number (kernel): 47
03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x8050457C[0x4]
03:08:50:531 4036 UnhookRegistry: NtEnumerateKey real addr: 80623FF2
03:08:50:531 4036 UnhookRegistry: NtEnumerateKey calc addr: 80623FF2
03:08:50:531 4036 UnhookRegistry: No SDT hooks found on NtEnumerateKey
03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x80623FF2[0xA]
03:08:50:531 4036 UnhookRegistry: No splicing found on NtEnumerateKey
03:08:50:531 4036
Scanning Kernel memory ...
03:08:50:531 4036 KLMD_OpenDevice: Trying to open KLMD device
03:08:50:531 4036 KLMD_GetSystemObjectAddressByNameA: Trying to get system object address by name \Driver\Disk
03:08:50:531 4036 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
03:08:50:531 4036 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 87167900
03:08:50:531 4036 DetectCureTDL3: KLMD_GetDeviceObjectList returned 11 DevObjects
03:08:50:531 4036 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 86B55030
03:08:50:531 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86B55030
03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x86B55030[0x38]
03:08:50:531 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900
03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]
03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]
03:08:50:531 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
03:08:50:531 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0
03:08:50:531 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:531 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0
03:08:50:546 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F
03:08:50:546 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F
03:08:50:546 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (:P addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2
03:08:50:546 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB
03:08:50:546 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28
03:08:50:546 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2
03:08:50:546 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82
03:08:50:546 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E
03:08:50:546 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:546 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:546 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
03:08:50:546 4036 KLMD_ReadMem: DeviceIoControl error 1
03:08:50:546 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code
03:08:50:546 4036 TDL3_FileDetect: Processing driver: Disk
03:08:50:546 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk
03:08:50:546 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
03:08:50:546 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
03:08:50:562 4036 DetectCureTDL3: 1 Curr stack PDEVICE_OBJECT: 86E88610
03:08:50:562 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86E88610
03:08:50:562 4036 KLMD_ReadMem: Trying to ReadMemory 0x86E88610[0x38]
03:08:50:562 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900
03:08:50:562 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]
03:08:50:562 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]
03:08:50:562 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
03:08:50:562 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0
03:08:50:562 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0
03:08:50:562 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F
03:08:50:562 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F
03:08:50:562 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (:P addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2
03:08:50:562 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB
03:08:50:562 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28
03:08:50:562 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2
03:08:50:562 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82
03:08:50:562 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E
03:08:50:562 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:562 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:562 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
03:08:50:562 4036 KLMD_ReadMem: DeviceIoControl error 1
03:08:50:562 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code
03:08:50:562 4036 TDL3_FileDetect: Processing driver: Disk
03:08:50:562 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk
03:08:50:562 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
03:08:50:562 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
03:08:50:578 4036 DetectCureTDL3: 2 Curr stack PDEVICE_OBJECT: 86C718F0
03:08:50:578 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86C718F0
03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C718F0[0x38]
03:08:50:578 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900
03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]
03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]
03:08:50:578 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
03:08:50:578 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0
03:08:50:578 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0
03:08:50:578 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F
03:08:50:578 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F
03:08:50:578 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (:P addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2
03:08:50:578 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB
03:08:50:578 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28
03:08:50:578 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2
03:08:50:578 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82
03:08:50:578 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E
03:08:50:578 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:578 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
03:08:50:578 4036 KLMD_ReadMem: DeviceIoControl error 1
03:08:50:578 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code
03:08:50:578 4036 TDL3_FileDetect: Processing driver: Disk
03:08:50:578 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk
03:08:50:578 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
03:08:50:578 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
03:08:50:578 4036 DetectCureTDL3: 3 Curr stack PDEVICE_OBJECT: 86A9D298
03:08:50:578 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A9D298
03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x86A9D298[0x38]
03:08:50:578 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900
03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]
03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]
03:08:50:578 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
03:08:50:578 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0
03:08:50:578 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0
03:08:50:593 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F
03:08:50:593 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F
03:08:50:593 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (:P addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2
03:08:50:593 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB
03:08:50:593 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28
03:08:50:593 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2
03:08:50:593 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82
03:08:50:593 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E
03:08:50:593 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:593 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
03:08:50:593 4036 KLMD_ReadMem: DeviceIoControl error 1
03:08:50:593 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code
03:08:50:593 4036 TDL3_FileDetect: Processing driver: Disk
03:08:50:593 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk
03:08:50:593 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
03:08:50:593 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
03:08:50:593 4036 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 86B5CAB8
03:08:50:593 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86B5CAB8
03:08:50:593 4036 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 86F9DC80
03:08:50:593 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86F9DC80
03:08:50:593 4036 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 86C8CDE8
03:08:50:593 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86C8CDE8
03:08:50:593 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C8CDE8[0x38]
03:08:50:593 4036 DetectCureTDL3: DRIVER_OBJECT addr: 86C97AE8
03:08:50:593 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C97AE8[0xA8]
03:08:50:593 4036 KLMD_ReadMem: Trying to ReadMemory 0xE227FBA8[0x208]
03:08:50:593 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
03:08:50:593 4036 DetectCureTDL3: IrpHandler (0) addr: F7A69218
03:08:50:593 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:593 4036 DetectCureTDL3: IrpHandler (2) addr: F7A69218
03:08:50:609 4036 DetectCureTDL3: IrpHandler (3) addr: F7A6923C
03:08:50:609 4036 DetectCureTDL3: IrpHandler (4) addr: F7A6923C
03:08:50:609 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (:) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (14) addr: F7A69180
03:08:50:609 4036 DetectCureTDL3: IrpHandler (15) addr: F7A649E6
03:08:50:609 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (22) addr: F7A685F0
03:08:50:609 4036 DetectCureTDL3: IrpHandler (23) addr: F7A66A6E
03:08:50:609 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:609 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:609 4036 KLMD_ReadMem: Trying to ReadMemory 0xF7A65F26[0x400]
03:08:50:609 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 0, 0
03:08:50:609 4036 TDL3_FileDetect: Processing driver: USBSTOR
03:08:50:609 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\usbstor.sys, C:\WINDOWS\system32\Drivers\usbstor.tsk, SYSTEM\CurrentControlSet\Services\USBSTOR, system32\Drivers\usbstor.tsk
03:08:50:609 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\usbstor.sys
03:08:50:609 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\usbstor.sys
03:08:50:625 4036 DetectCureTDL3: 5 Curr stack PDEVICE_OBJECT: 86AD9338
03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86AD9338
03:08:50:625 4036 DetectCureTDL3: 5 Curr stack PDEVICE_OBJECT: 86A2C108
03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A2C108
03:08:50:625 4036 DetectCureTDL3: 5 Curr stack PDEVICE_OBJECT: 869D8AE0
03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 869D8AE0
03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0x869D8AE0[0x38]
03:08:50:625 4036 DetectCureTDL3: DRIVER_OBJECT addr: 86C97AE8
03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C97AE8[0xA8]
03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0xE227FBA8[0x208]
03:08:50:625 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
03:08:50:625 4036 DetectCureTDL3: IrpHandler (0) addr: F7A69218
03:08:50:625 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (2) addr: F7A69218
03:08:50:625 4036 DetectCureTDL3: IrpHandler (3) addr: F7A6923C
03:08:50:625 4036 DetectCureTDL3: IrpHandler (4) addr: F7A6923C
03:08:50:625 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (;) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (14) addr: F7A69180
03:08:50:625 4036 DetectCureTDL3: IrpHandler (15) addr: F7A649E6
03:08:50:625 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (22) addr: F7A685F0
03:08:50:625 4036 DetectCureTDL3: IrpHandler (23) addr: F7A66A6E
03:08:50:625 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0xF7A65F26[0x400]
03:08:50:625 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 0, 0
03:08:50:625 4036 TDL3_FileDetect: Processing driver: USBSTOR
03:08:50:625 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\usbstor.sys, C:\WINDOWS\system32\Drivers\usbstor.tsk, SYSTEM\CurrentControlSet\Services\USBSTOR, system32\Drivers\usbstor.tsk
03:08:50:625 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\usbstor.sys
03:08:50:625 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\usbstor.sys
03:08:50:625 4036 DetectCureTDL3: 6 Curr stack PDEVICE_OBJECT: 86A7C518
03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A7C518
03:08:50:625 4036 DetectCureTDL3: 6 Curr stack PDEVICE_OBJECT: 86C96CE0
03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86C96CE0
03:08:50:625 4036 DetectCureTDL3: 6 Curr stack PDEVICE_OBJECT: 869DDCC0
03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 869DDCC0
03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0x869DDCC0[0x38]
03:08:50:625 4036 DetectCureTDL3: DRIVER_OBJECT addr: 86C97AE8
03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C97AE8[0xA8]
03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0xE227FBA8[0x208]
03:08:50:625 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
03:08:50:625 4036 DetectCureTDL3: IrpHandler (0) addr: F7A69218
03:08:50:625 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (2) addr: F7A69218
03:08:50:625 4036 DetectCureTDL3: IrpHandler (3) addr: F7A6923C
03:08:50:625 4036 DetectCureTDL3: IrpHandler (4) addr: F7A6923C
03:08:50:625 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:625 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (;) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (14) addr: F7A69180
03:08:50:640 4036 DetectCureTDL3: IrpHandler (15) addr: F7A649E6
03:08:50:640 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (22) addr: F7A685F0
03:08:50:640 4036 DetectCureTDL3: IrpHandler (23) addr: F7A66A6E
03:08:50:640 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0xF7A65F26[0x400]
03:08:50:640 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 0, 0
03:08:50:640 4036 TDL3_FileDetect: Processing driver: USBSTOR
03:08:50:640 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\usbstor.sys, C:\WINDOWS\system32\Drivers\usbstor.tsk, SYSTEM\CurrentControlSet\Services\USBSTOR, system32\Drivers\usbstor.tsk
03:08:50:640 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\usbstor.sys
03:08:50:640 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\usbstor.sys
03:08:50:640 4036 DetectCureTDL3: 7 Curr stack PDEVICE_OBJECT: 86FA3AB8
03:08:50:640 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86FA3AB8
03:08:50:640 4036 DetectCureTDL3: 7 Curr stack PDEVICE_OBJECT: 86A36288
03:08:50:640 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A36288
03:08:50:640 4036 DetectCureTDL3: 7 Curr stack PDEVICE_OBJECT: 86A75D50
03:08:50:640 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A75D50
03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0x86A75D50[0x38]
03:08:50:640 4036 DetectCureTDL3: DRIVER_OBJECT addr: 86C97AE8
03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C97AE8[0xA8]
03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0xE227FBA8[0x208]
03:08:50:640 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
03:08:50:640 4036 DetectCureTDL3: IrpHandler (0) addr: F7A69218
03:08:50:640 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (2) addr: F7A69218
03:08:50:640 4036 DetectCureTDL3: IrpHandler (3) addr: F7A6923C
03:08:50:640 4036 DetectCureTDL3: IrpHandler (4) addr: F7A6923C
03:08:50:640 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (:) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (14) addr: F7A69180
03:08:50:640 4036 DetectCureTDL3: IrpHandler (15) addr: F7A649E6
03:08:50:640 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (22) addr: F7A685F0
03:08:50:640 4036 DetectCureTDL3: IrpHandler (23) addr: F7A66A6E
03:08:50:640 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:640 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0xF7A65F26[0x400]
03:08:50:640 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 0, 0
03:08:50:640 4036 TDL3_FileDetect: Processing driver: USBSTOR
03:08:50:640 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\usbstor.sys, C:\WINDOWS\system32\Drivers\usbstor.tsk, SYSTEM\CurrentControlSet\Services\USBSTOR, system32\Drivers\usbstor.tsk
03:08:50:640 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\usbstor.sys
03:08:50:640 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\usbstor.sys
03:08:50:656 4036 DetectCureTDL3: 8 Curr stack PDEVICE_OBJECT: 8713EC68
03:08:50:656 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8713EC68
03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x8713EC68[0x38]
03:08:50:656 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900
03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]
03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]
03:08:50:656 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
03:08:50:656 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0
03:08:50:656 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0
03:08:50:656 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F
03:08:50:656 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F
03:08:50:656 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (:D addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2
03:08:50:656 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB
03:08:50:656 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28
03:08:50:656 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2
03:08:50:656 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82
03:08:50:656 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E
03:08:50:656 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
03:08:50:656 4036 KLMD_ReadMem: DeviceIoControl error 1
03:08:50:656 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code
03:08:50:656 4036 TDL3_FileDetect: Processing driver: Disk
03:08:50:656 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk
03:08:50:656 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
03:08:50:656 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
03:08:50:656 4036 DetectCureTDL3: 9 Curr stack PDEVICE_OBJECT: 8713F9F0
03:08:50:656 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8713F9F0
03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x8713F9F0[0x38]
03:08:50:656 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900
03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]
03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]
03:08:50:656 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
03:08:50:656 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0
03:08:50:656 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0
03:08:50:656 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F
03:08:50:656 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F
03:08:50:656 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (:lol: addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2
03:08:50:656 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:656 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB
03:08:50:671 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28
03:08:50:671 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2
03:08:50:671 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82
03:08:50:671 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E
03:08:50:671 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
03:08:50:671 4036 KLMD_ReadMem: DeviceIoControl error 1
03:08:50:671 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code
03:08:50:671 4036 TDL3_FileDetect: Processing driver: Disk
03:08:50:671 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk
03:08:50:671 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
03:08:50:671 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
03:08:50:671 4036 DetectCureTDL3: 10 Curr stack PDEVICE_OBJECT: 87160AB8
03:08:50:671 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87160AB8
03:08:50:671 4036 DetectCureTDL3: 10 Curr stack PDEVICE_OBJECT: 87142958
03:08:50:671 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87142958
03:08:50:671 4036 DetectCureTDL3: 10 Curr stack PDEVICE_OBJECT: 87165B00
03:08:50:671 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87165B00
03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0x87165B00[0x38]
03:08:50:671 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87188510
03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0x87188510[0xA8]
03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0xE1012910[0x208]
03:08:50:671 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
03:08:50:671 4036 DetectCureTDL3: IrpHandler (0) addr: F74CE6F2
03:08:50:671 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (2) addr: F74CE6F2
03:08:50:671 4036 DetectCureTDL3: IrpHandler (3) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (4) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (:mhh: addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (14) addr: F74CE712
03:08:50:671 4036 DetectCureTDL3: IrpHandler (15) addr: F74CA852
03:08:50:671 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (22) addr: F74CE73C
03:08:50:671 4036 DetectCureTDL3: IrpHandler (23) addr: F74D5336
03:08:50:671 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562
03:08:50:671 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562
03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0xF74CB864[0x400]
03:08:50:671 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 316, 0
03:08:50:671 4036 TDL3_FileDetect: Processing driver: atapi
03:08:50:671 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\atapi.sys, C:\WINDOWS\system32\Drivers\atapi.tsk, SYSTEM\CurrentControlSet\Services\atapi, system32\Drivers\atapi.tsk
03:08:50:671 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\atapi.sys
03:08:50:671 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\atapi.sys
03:08:50:703 4036
Completed

Results:
03:08:50:703 4036 Infected objects in memory: 0
03:08:50:703 4036 Cured objects in memory: 0
03:08:50:703 4036 Infected objects on disk: 0
03:08:50:703 4036 Objects on disk cured on reboot: 0
03:08:50:703 4036 Objects on disk deleted on reboot: 0
03:08:50:703 4036 Registry nodes deleted on reboot: 0
03:08:50:703 4036











ComboFix 09-12-24.02 - HP_Propriétaire 25/12/2009 3:23.4.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.304 [GMT 1:00]
Lancé depuis: c:\documents and settings\HP_Propriétaire\Mes documents\Téléchargements\69356-CF.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\LHT1F.tmp
C:\LHT22.tmp
C:\LHT23.tmp
C:\LHT90.tmp
C:\LHTB6.tmp
c:\windows\system32\2492142984.dat
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\H8SRTiqqjcbqjhn.dll
c:\windows\system32\H8SRTmttappehem.dat
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\krl32mainweq.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\ps2.bat
c:\windows\system32\SrchSTS.exe
c:\windows\system32\srcr.dat
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-11-25 au 2009-12-25 ))))))))))))))))))))))))))))))))))))
.

2009-12-25 01:54 . 2009-12-25 02:08 -------- d-----w- C:\tdsskiller
2009-12-24 14:45 . 2009-12-24 14:45 -------- d-sh--w- c:\documents and settings\Administrateur\PrivacIE
2009-12-24 14:43 . 2009-12-24 14:43 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
2009-12-24 13:49 . 2009-12-24 13:49 -------- d-----w- C:\sh4ldr
2009-12-24 13:48 . 2009-12-24 13:48 -------- d-----w- c:\program files\Enigma Software Group
2009-12-24 11:12 . 2009-12-24 11:12 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-24 11:12 . 2009-12-25 02:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-09 16:53 . 2009-12-11 21:18 -------- d-----w- c:\program files\Microsoft Silverlight
2009-12-09 16:53 . 2009-12-09 16:53 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-12-09 16:53 . 2009-08-05 21:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-12-09 16:52 . 2009-12-09 16:52 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-12-09 16:51 . 2006-11-29 12:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-12-09 16:51 . 2009-12-09 16:51 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-09 16:49 . 2009-12-09 16:53 -------- d-----w- c:\program files\Microsoft
2009-12-09 16:49 . 2009-12-09 16:49 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-12-09 16:43 . 2009-12-09 16:43 -------- d-----w- c:\program files\Fichiers communs\Windows Live

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-25 02:30 . 2009-12-24 11:12 -------- d-----w- c:\program files\Spyware Doctor
2009-12-25 02:29 . 2009-06-14 00:32 -------- d-----w- c:\program files\DNA
2009-12-24 15:34 . 2005-10-11 18:42 -------- d-----w- c:\program files\Google
2009-12-24 11:17 . 2009-12-24 11:12 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-12-19 09:51 . 2008-10-21 13:58 -------- d-----w- c:\program files\World of Warcraft
2009-12-15 19:18 . 2004-11-23 21:26 86862 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-15 19:18 . 2004-11-23 21:26 515380 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-10 21:58 . 2008-10-21 19:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-09 16:53 . 2008-10-21 15:47 -------- d-----w- c:\program files\Windows Live
2009-12-07 19:24 . 2009-06-03 13:04 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-18 18:04 . 2008-10-23 19:29 -------- d-----w- c:\program files\WowCartographe
2009-11-10 09:28 . 2009-12-24 11:17 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-11-10 09:28 . 2009-12-24 11:17 1640400 ----a-w- c:\windows\PCTBDCore.dll
2009-11-10 09:28 . 2009-12-24 11:17 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-11-10 09:26 . 2009-12-24 11:17 767952 ----a-w- c:\windows\BDTSupport.dll
2009-11-09 10:20 . 2009-12-24 11:13 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-30 10:11 . 2009-12-24 11:13 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-10-29 07:42 . 2004-08-05 18:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-28 00:36 . 2009-12-24 11:17 1152444 ----a-w- c:\windows\UDB.zip
2009-10-21 05:39 . 2004-08-05 18:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:39 . 2004-08-05 18:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-05 18:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:33 . 2004-08-05 18:00 271360 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:39 . 2004-08-05 18:00 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:39 . 2004-08-05 18:00 150528 ----a-w- c:\windows\system32\rastls.dll
2009-10-06 15:31 . 2009-12-24 11:13 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-02 24264488]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 61952]
"SoundMan"="SOUNDMAN.EXE" [2005-05-04 90112]
"AlcWzrd"="ALCWZRD.EXE" [2005-05-04 2805248]
"RemoteControl"="c:\program files\ASUS\ASUS Remote\RemoteControlAppl.exe" [2005-06-10 61440]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"Home Theater SchSvr"="c:\program files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2005-07-18 106496]
"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2005-07-18 262144]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]
"nwiz"="nwiz.exe" [2009-04-30 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-30 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-16 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-12-09 866200]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.4.3-to-3.0.2-frFR-Win-Final-downloader.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-frFR-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-frFR-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-frFR-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-frFR-downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:UDP"= 3724:UDP:Blizzard downloader:3724
"6112:TCP"= 6112:TCP:Blibli downloader
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"27709:TCP"= 27709:TCP:tcp

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [3/06/2009 10:57 28544]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [24/12/2009 12:13 207792]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [24/12/2009 12:17 112592]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/12/2009 17:53 54752]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [24/12/2009 12:13 359624]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [11/10/2005 19:08 2786176]
S2 a2AntiMalware;a-squared Anti-Malware Service;"c:\program files\a-squared Anti-Malware\a2service.exe" --> c:\program files\a-squared Anti-Malware\a2service.exe [?]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/07/2009 20:57 108289]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [5/08/2009 22:48 704864]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - KLMD_BOOT
*NewlyCreated* - KLMD_SYSTEM
*Deregistered* - KLMD
*Deregistered* - KLMD_Boot
*Deregistered* - KLMD_System
*Deregistered* - PCTSDInjDriver32
.
------- Examen supplémentaire -------
.
uStart Page =
uInternet Settings,ProxyOverride = *.local
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\wlot0w3y.default\
FF - prefs.js: browser.startup.homepage - www.jeuxvideo.com
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -

HKCU-Run-Malware Defense - c:\program files\Malware Defense\mdefense.exe
AddRemove-Smart Defrag_is1 - c:\program files\IObit\IObit SmartDefrag\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-25 03:30
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(620)
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll

- - - - - - - > 'lsass.exe'(676)
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
.
Heure de fin: 2009-12-25 03:33:26
ComboFix-quarantined-files.txt 2009-12-25 02:33

Avant-CF: 90.292.166.656 octets libres
Après-CF: 90.348.179.456 octets libres

- - End Of File - - E22D86CA7B92C83D8245A66C9B848239
0

#6 L'utilisateur est hors-ligne   pear 

  • Devil Member !
  • Groupe : Equipe Sécurité
  • Messages : 16496
  • Inscrit(e) : 22-mars 05

Posté 25 décembre 2009 - 09:58

Bonjour,


Désinstallez Mbam, s'il est installé
Téléchargez MBAM

[Branchez tous les supports amovibles avant de faire ce scan (clé usb/disque dur externe etc)
Si vous utilisez Spybot
Pour désactiver TeaTimer qui ne set à rien et peut faire échouer une désinfection:!
Afficher d'abord le Mode Avancé dans SpyBot
->Options Avancées :
- >menu Mode, Mode Avancé.
Une colonne de menus apparaît dans la partie gauche :
- >cliquer sur Outils,
- >cliquer sur Résident,
Dans Résident :
- >décocher Résident "TeaTimer" pour le désactiver.

* Double cliquez sur l'icône Download_mbam-setup.exe pour lancer le processus d'installation.
Enregistrez le sur le bureau .
Fermer toutes les fenêtres et programmes
Suivez les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet)
N'apportez aucune modification aux réglages par défaut et, en fin d'installation,
Vérifiez que les options Update et Launch soient cochées
MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse.
cliquer sur OK pour fermer la boîte de dialogue..
* Dans l'onglet "mise à jour", cliquez sur le bouton Recherche de mise à jour:
Si le pare-feu demande l'autorisation à MBAM de se connecter, acceptez.
* Une fois la mise à jour terminée, allez dans l'onglet Recherche.
* Sélectionnez "Exécuter un examen rapide"
* Cliquez sur "Rechercher"
* .L' analyse prendra un certain temps, soyez patient !
* A la fin , un message affichera :
L'examen s'est terminé normalement.

*Si MBAM n'a rien trouvé, il le dira aussi.
Cliquez sur "Ok" pour poursuivre.
*Fermez les navigateurs.
Cliquez sur Afficher les résultats .

*Sélectionnez tout et cliquez sur Supprimer la sélection ,
MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
puis ouvrir le Bloc-notes et y copier le rapport d'analyse qui peut être retrouvé sous l'onglet Rapports/logs.
* Copiez-collez ce rapport dans la prochaine réponse.



Scan en ligne
NOTE: Le scan en ligne sera à faire avec Internet Explorer.
Désactiver l'antivirus actuel
Kaspersky
Sous Vista,il faut désactiver l'UAC, et cliquer droit sur Internet Explorer / Exécuter en tant qu'administrateur et coller l'URL de Kaspersky
http://www.kaspersky.com/kos/eng/partner/d...kavwebscan.html
Vider la corbeille.
* Cliquer sur Accept
* Une barre jaune va demander d'accepter l'installation de Kavwebscan_Unicode.cab, installer l'Active X.
* cliquer une nouvelle fois sur "Accept"
* Les bases de mises à jour vont s'installer, patienter un moment
* Cliquer sur Next.
* Cliquer sur My Computer, le scan se met en route;
attendre la fin du scan sans fermer la fenêtre sinon il s'arrêtera.
A la fin du scan, si des objets infectés sont découverts, cliquer sur Save report as...
Choisir bureau et nommer le rapport "rapport Kaspersky" et dans le champ d'enregistrement, choisir "fichiers texte" enregistrer le rapport.
Copier/coller l'entièreté du fichier texte ouvert, par clic droit dessus, sélectionner tout/copier.
Coller ce rapport dans la réponse sur le forum.


Si ce que tu as à dire ne vaut pas mieux que le silence, tais-toi (Confucius)
0

#7 L'utilisateur est hors-ligne   Aioros 

  • Member
  • Groupe : Membres
  • Messages : 34
  • Inscrit(e) : 13-janvier 09

Posté 25 décembre 2009 - 11:36

Désolé de la réponse tardive, voici les 2 rapports demandés :

ComboFix 09-12-24.02 - HP_Propriétaire 25/12/2009 3:23.4.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.304 [GMT 1:00]
Lancé depuis: c:\documents and settings\HP_Propriétaire\Mes documents\Téléchargements\69356-CF.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\LHT1F.tmp
C:\LHT22.tmp
C:\LHT23.tmp
C:\LHT90.tmp
C:\LHTB6.tmp
c:\windows\system32\2492142984.dat
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\H8SRTiqqjcbqjhn.dll
c:\windows\system32\H8SRTmttappehem.dat
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\krl32mainweq.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\ps2.bat
c:\windows\system32\SrchSTS.exe
c:\windows\system32\srcr.dat
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-11-25 au 2009-12-25 ))))))))))))))))))))))))))))))))))))
.

2009-12-25 01:54 . 2009-12-25 02:08 -------- d-----w- C:\tdsskiller
2009-12-24 14:45 . 2009-12-24 14:45 -------- d-sh--w- c:\documents and settings\Administrateur\PrivacIE
2009-12-24 14:43 . 2009-12-24 14:43 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
2009-12-24 13:49 . 2009-12-24 13:49 -------- d-----w- C:\sh4ldr
2009-12-24 13:48 . 2009-12-24 13:48 -------- d-----w- c:\program files\Enigma Software Group
2009-12-24 11:12 . 2009-12-24 11:12 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-24 11:12 . 2009-12-25 02:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-09 16:53 . 2009-12-11 21:18 -------- d-----w- c:\program files\Microsoft Silverlight
2009-12-09 16:53 . 2009-12-09 16:53 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-12-09 16:53 . 2009-08-05 21:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-12-09 16:52 . 2009-12-09 16:52 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-12-09 16:51 . 2006-11-29 12:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-12-09 16:51 . 2009-12-09 16:51 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-09 16:49 . 2009-12-09 16:53 -------- d-----w- c:\program files\Microsoft
2009-12-09 16:49 . 2009-12-09 16:49 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-12-09 16:43 . 2009-12-09 16:43 -------- d-----w- c:\program files\Fichiers communs\Windows Live

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-25 02:30 . 2009-12-24 11:12 -------- d-----w- c:\program files\Spyware Doctor
2009-12-25 02:29 . 2009-06-14 00:32 -------- d-----w- c:\program files\DNA
2009-12-24 15:34 . 2005-10-11 18:42 -------- d-----w- c:\program files\Google
2009-12-24 11:17 . 2009-12-24 11:12 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-12-19 09:51 . 2008-10-21 13:58 -------- d-----w- c:\program files\World of Warcraft
2009-12-15 19:18 . 2004-11-23 21:26 86862 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-15 19:18 . 2004-11-23 21:26 515380 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-10 21:58 . 2008-10-21 19:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-09 16:53 . 2008-10-21 15:47 -------- d-----w- c:\program files\Windows Live
2009-12-07 19:24 . 2009-06-03 13:04 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-18 18:04 . 2008-10-23 19:29 -------- d-----w- c:\program files\WowCartographe
2009-11-10 09:28 . 2009-12-24 11:17 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-11-10 09:28 . 2009-12-24 11:17 1640400 ----a-w- c:\windows\PCTBDCore.dll
2009-11-10 09:28 . 2009-12-24 11:17 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-11-10 09:26 . 2009-12-24 11:17 767952 ----a-w- c:\windows\BDTSupport.dll
2009-11-09 10:20 . 2009-12-24 11:13 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-30 10:11 . 2009-12-24 11:13 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-10-29 07:42 . 2004-08-05 18:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-28 00:36 . 2009-12-24 11:17 1152444 ----a-w- c:\windows\UDB.zip
2009-10-21 05:39 . 2004-08-05 18:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:39 . 2004-08-05 18:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-05 18:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:33 . 2004-08-05 18:00 271360 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:39 . 2004-08-05 18:00 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:39 . 2004-08-05 18:00 150528 ----a-w- c:\windows\system32\rastls.dll
2009-10-06 15:31 . 2009-12-24 11:13 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-02 24264488]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 61952]
"SoundMan"="SOUNDMAN.EXE" [2005-05-04 90112]
"AlcWzrd"="ALCWZRD.EXE" [2005-05-04 2805248]
"RemoteControl"="c:\program files\ASUS\ASUS Remote\RemoteControlAppl.exe" [2005-06-10 61440]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"Home Theater SchSvr"="c:\program files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2005-07-18 106496]
"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2005-07-18 262144]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]
"nwiz"="nwiz.exe" [2009-04-30 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-30 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-16 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-12-09 866200]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.4.3-to-3.0.2-frFR-Win-Final-downloader.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-frFR-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-frFR-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-frFR-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-frFR-downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:UDP"= 3724:UDP:Blizzard downloader:3724
"6112:TCP"= 6112:TCP:Blibli downloader
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"27709:TCP"= 27709:TCP:tcp

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [3/06/2009 10:57 28544]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [24/12/2009 12:13 207792]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [24/12/2009 12:17 112592]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/12/2009 17:53 54752]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [24/12/2009 12:13 359624]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [11/10/2005 19:08 2786176]
S2 a2AntiMalware;a-squared Anti-Malware Service;"c:\program files\a-squared Anti-Malware\a2service.exe" --> c:\program files\a-squared Anti-Malware\a2service.exe [?]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/07/2009 20:57 108289]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [5/08/2009 22:48 704864]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - KLMD_BOOT
*NewlyCreated* - KLMD_SYSTEM
*Deregistered* - KLMD
*Deregistered* - KLMD_Boot
*Deregistered* - KLMD_System
*Deregistered* - PCTSDInjDriver32
.
------- Examen supplémentaire -------
.
uStart Page =
uInternet Settings,ProxyOverride = *.local
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\wlot0w3y.default\
FF - prefs.js: browser.startup.homepage - www.jeuxvideo.com
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -

HKCU-Run-Malware Defense - c:\program files\Malware Defense\mdefense.exe
AddRemove-Smart Defrag_is1 - c:\program files\IObit\IObit SmartDefrag\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-25 03:30
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(620)
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll

- - - - - - - > 'lsass.exe'(676)
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
.
Heure de fin: 2009-12-25 03:33:26
ComboFix-quarantined-files.txt 2009-12-25 02:33

Avant-CF: 90.292.166.656 octets libres
Après-CF: 90.348.179.456 octets libres

- - End Of File - - E22D86CA7B92C83D8245A66C9B848239








--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Friday, December 25, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Friday, December 25, 2009 11:16:07
Records in database: 3410334
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Objects scanned: 88537
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 02:34:42


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTiqqjcbqjhn.dll.vir Infected: Packed.Win32.TDSS.aa 1

Selected area has been scanned.

Je n'ai plus le logiciel "malware defense" ainsi que toutes les autres anomalies apparues hier matin mais mon pc reste d'une lenteur affreuse...

Merci de vos réponses
0

#8 L'utilisateur est hors-ligne   pear 

  • Devil Member !
  • Groupe : Equipe Sécurité
  • Messages : 16496
  • Inscrit(e) : 22-mars 05

Posté 26 décembre 2009 - 10:46

Vous avez mal lu mon dernier message.

J'attendais les rapports Mbam et Kaspersky.
Si ce que tu as à dire ne vaut pas mieux que le silence, tais-toi (Confucius)
0

#9 L'utilisateur est hors-ligne   Aioros 

  • Member
  • Groupe : Membres
  • Messages : 34
  • Inscrit(e) : 13-janvier 09

Posté 26 décembre 2009 - 11:05

Excusez-moi j'ai posté le mauvais rapport

Les voici :

Malwarebytes' Anti-Malware 1.42
Version de la base de données: 3427
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

25/12/2009 12:42:05
mbam-log-2009-12-25 (12-42-05).txt

Type de recherche: Examen rapide
Eléments examinés: 127364
Temps écoulé: 5 minute(s), 18 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)



--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Friday, December 25, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Friday, December 25, 2009 11:16:07
Records in database: 3410334
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Objects scanned: 88537
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 02:34:42


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTiqqjcbqjhn.dll.vir Infected: Packed.Win32.TDSS.aa 1

Selected area has been scanned.
0

#10 L'utilisateur est hors-ligne   pear 

  • Devil Member !
  • Groupe : Equipe Sécurité
  • Messages : 16496
  • Inscrit(e) : 22-mars 05

Posté 26 décembre 2009 - 12:28

C'est parfait !

Veuillez noter que ce logiciel est régulièrement mis à jour et que la version que vous avez chargée sera obsolète dans quelques jours.
Pour supprimer Combofix:
Démarrer > Exécuter ->ComboFix /uninstall

Supprimez C:\qoobox si vous le trouvez

Il ne vous servirait à rien de garder des outils de désinfection qui sont constamment mis à jours et seraient obsolètes en quelques jours.

Pour enlever les programmes utilisés pendant la procédure.
Télécharger ToolsCleaner2 de A.Rothstein
* Enregistrer ToolsCleaner2.exe sur le Bureau.
Sous Vista,Clic-droit > Exécuter en tant que Administrateur
* Double-cliquer dessus, puis cliquer sur Recherche --> Le programme va chercher les utilitaires installés
------> Il se peut que la fenêtre devienne blanche pendant le scan, c'est normal !
L'outil supprimera sans que vous ayez à intervenir.


Si vous estimez votre problème résolu, éditez l'en tête de votre premier message et y indiquez Résolu pour que ceux qui la recherchent y trouvent une solution.
Si ce que tu as à dire ne vaut pas mieux que le silence, tais-toi (Confucius)
0

  • (2 Pages)
  • +
  • 1
  • 2
  • Vous ne pouvez pas commencer un sujet
  • Vous ne pouvez pas répondre à ce sujet



1 utilisateur(s) en train de lire ce sujet
0 membre(s), 1 invité(s), 0 utilisateur(s) anonyme(s)



    Page officielle Zebulon.fr