Merci !Voici les rapports :
17:56:46:000 5200 TDSSKiller 2.1.1 Dec 20 2009 02:40:02
17:56:46:000 5200 ================================================================================
17:56:46:000 5200 SystemInfo:
17:56:46:000 5200 OS Version: 5.1.2600 ServicePack: 3.0
17:56:46:000 5200 Product type: Workstation
17:56:46:000 5200 ComputerName: MIKE
17:56:46:000 5200 UserName: Hishiro
17:56:46:000 5200 Windows directory: C:\WINDOWS
17:56:46:000 5200 Processor architecture: Intel x86
17:56:46:000 5200 Number of processors: 1
17:56:46:000 5200 Page size: 0x1000
17:56:46:015 5200 Boot type: Normal boot
17:56:46:015 5200 ================================================================================
17:56:46:015 5200 main: Driver KLMD successfully unloaded
17:56:46:515 5200 ForceUnloadDriver: NtUnloadDriver error 2
17:56:46:515 5200 ForceUnloadDriver: NtUnloadDriver error 2
17:56:46:515 5200 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\Drivers\KLMD.sys) returned status 0
17:56:46:515 5200 main: Driver KLMD successfully dropped
17:56:46:515 5200 main: Driver KLMD successfully loaded
17:56:46:515 5200
Scanning Registry ...
17:56:46:515 5200 ScanServices: Searching service UACd.sys
17:56:46:515 5200 ScanServices: Open/Create key error 2
17:56:46:515 5200 ScanServices: Searching service TDSSserv.sys
17:56:46:515 5200 ScanServices: Open/Create key error 2
17:56:46:515 5200 ScanServices: Searching service gaopdxserv.sys
17:56:46:515 5200 ScanServices: Open/Create key error 2
17:56:46:515 5200 ScanServices: Searching service gxvxcserv.sys
17:56:46:515 5200 ScanServices: Open/Create key error 2
17:56:46:515 5200 ScanServices: Searching service MSIVXserv.sys
17:56:46:515 5200 ScanServices: Open/Create key error 2
17:56:46:515 5200 UnhookRegistry: Kernel module file name: C:\windows\system32\ntkrnlpa.exe, base addr: 804D7000
17:56:46:515 5200 UnhookRegistry: Kernel local addr: DF0000
17:56:46:515 5200 UnhookRegistry: KeServiceDescriptorTable addr: E6C020
17:56:46:515 5200 UnhookRegistry: KiServiceTable addr: E1AB9C
17:56:46:515 5200 UnhookRegistry: NtEnumerateKey service number (local): 47
17:56:46:515 5200 UnhookRegistry: NtEnumerateKey local addr: F33B70
17:56:46:531 5200 KLMD_OpenDevice: Trying to open KLMD device
17:56:46:531 5200 KLMD_GetSystemRoutineAddressA: Trying to get system routine address ZwEnumerateKey
17:56:46:531 5200 KLMD_GetSystemRoutineAddressW: Trying to get system routine address ZwEnumerateKey
17:56:46:531 5200 KLMD_ReadMem: Trying to ReadMemory 0x804FE335[0x4]
17:56:46:531 5200 UnhookRegistry: NtEnumerateKey service number (kernel): 47
17:56:46:531 5200 KLMD_ReadMem: Trying to ReadMemory 0x80501CB8[0x4]
17:56:46:531 5200 UnhookRegistry: NtEnumerateKey real addr: 8061AB70
17:56:46:531 5200 UnhookRegistry: NtEnumerateKey calc addr: 8061AB70
17:56:46:531 5200 UnhookRegistry: No SDT hooks found on NtEnumerateKey
17:56:46:531 5200 KLMD_ReadMem: Trying to ReadMemory 0x8061AB70[0xA]
17:56:46:531 5200 UnhookRegistry: No splicing found on NtEnumerateKey
17:56:46:531 5200
Scanning Kernel memory ...
17:56:46:531 5200 KLMD_OpenDevice: Trying to open KLMD device
17:56:46:531 5200 KLMD_GetSystemObjectAddressByNameA: Trying to get system object address by name \Driver\Disk
17:56:46:531 5200 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
17:56:46:531 5200 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 868FB230
17:56:46:531 5200 DetectCureTDL3: KLMD_GetDeviceObjectList returned 3 DevObjects
17:56:46:531 5200 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 8690C030
17:56:46:531 5200 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8690C030
17:56:46:531 5200 KLMD_ReadMem: Trying to ReadMemory 0x8690C030[0x38]
17:56:46:531 5200 DetectCureTDL3: DRIVER_OBJECT addr: 868FB230
17:56:46:531 5200 KLMD_ReadMem: Trying to ReadMemory 0x868FB230[0xA8]
17:56:46:531 5200 KLMD_ReadMem: Trying to ReadMemory 0xE1012370[0x208]
17:56:46:531 5200 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:56:46:531 5200 DetectCureTDL3: IrpHandler (0) addr: F764EBB0
17:56:46:531 5200 DetectCureTDL3: IrpHandler (1) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (2) addr: F764EBB0
17:56:46:531 5200 DetectCureTDL3: IrpHandler (3) addr: F7648D1F
17:56:46:531 5200 DetectCureTDL3: IrpHandler (4) addr: F7648D1F
17:56:46:531 5200 DetectCureTDL3: IrpHandler (5) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (6) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (7) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler ( addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (9) addr: F76492E2
17:56:46:531 5200 DetectCureTDL3: IrpHandler (10) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (11) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (12) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (13) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (14) addr: F76493BB
17:56:46:531 5200 DetectCureTDL3: IrpHandler (15) addr: F764CF28
17:56:46:531 5200 DetectCureTDL3: IrpHandler (16) addr: F76492E2
17:56:46:531 5200 DetectCureTDL3: IrpHandler (17) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (18) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (19) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (20) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (21) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (22) addr: F764AC82
17:56:46:531 5200 DetectCureTDL3: IrpHandler (23) addr: F764F99E
17:56:46:531 5200 DetectCureTDL3: IrpHandler (24) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (25) addr: 804F355A
17:56:46:531 5200 DetectCureTDL3: IrpHandler (26) addr: 804F355A
17:56:46:531 5200 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
17:56:46:531 5200 KLMD_ReadMem: DeviceIoControl error 1
17:56:46:531 5200 TDL3_StartIoHookDetect: Unable to get StartIo handler code
17:56:46:531 5200 TDL3_FileDetect: Processing driver: Disk
17:56:46:531 5200 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk
17:56:46:531 5200 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
17:56:46:531 5200 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
17:56:46:562 5200 DetectCureTDL3: 1 Curr stack PDEVICE_OBJECT: 8690D548
17:56:46:562 5200 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8690D548
17:56:46:562 5200 KLMD_ReadMem: Trying to ReadMemory 0x8690D548[0x38]
17:56:46:562 5200 DetectCureTDL3: DRIVER_OBJECT addr: 868FB230
17:56:46:562 5200 KLMD_ReadMem: Trying to ReadMemory 0x868FB230[0xA8]
17:56:46:562 5200 KLMD_ReadMem: Trying to ReadMemory 0xE1012370[0x208]
17:56:46:562 5200 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:56:46:562 5200 DetectCureTDL3: IrpHandler (0) addr: F764EBB0
17:56:46:562 5200 DetectCureTDL3: IrpHandler (1) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (2) addr: F764EBB0
17:56:46:562 5200 DetectCureTDL3: IrpHandler (3) addr: F7648D1F
17:56:46:562 5200 DetectCureTDL3: IrpHandler (4) addr: F7648D1F
17:56:46:562 5200 DetectCureTDL3: IrpHandler (5) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (6) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (7) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler ( addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (9) addr: F76492E2
17:56:46:562 5200 DetectCureTDL3: IrpHandler (10) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (11) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (12) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (13) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (14) addr: F76493BB
17:56:46:562 5200 DetectCureTDL3: IrpHandler (15) addr: F764CF28
17:56:46:562 5200 DetectCureTDL3: IrpHandler (16) addr: F76492E2
17:56:46:562 5200 DetectCureTDL3: IrpHandler (17) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (18) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (19) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (20) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (21) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (22) addr: F764AC82
17:56:46:562 5200 DetectCureTDL3: IrpHandler (23) addr: F764F99E
17:56:46:562 5200 DetectCureTDL3: IrpHandler (24) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (25) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (26) addr: 804F355A
17:56:46:562 5200 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
17:56:46:562 5200 KLMD_ReadMem: DeviceIoControl error 1
17:56:46:562 5200 TDL3_StartIoHookDetect: Unable to get StartIo handler code
17:56:46:562 5200 TDL3_FileDetect: Processing driver: Disk
17:56:46:562 5200 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk
17:56:46:562 5200 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
17:56:46:562 5200 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
17:56:46:562 5200 DetectCureTDL3: 2 Curr stack PDEVICE_OBJECT: 868FF388
17:56:46:562 5200 KLMD_GetLowerDeviceObject: Trying to get lower device object for 868FF388
17:56:46:562 5200 DetectCureTDL3: 2 Curr stack PDEVICE_OBJECT: 868FC3B8
17:56:46:562 5200 KLMD_GetLowerDeviceObject: Trying to get lower device object for 868FC3B8
17:56:46:562 5200 DetectCureTDL3: 2 Curr stack PDEVICE_OBJECT: 868FBD98
17:56:46:562 5200 KLMD_GetLowerDeviceObject: Trying to get lower device object for 868FBD98
17:56:46:562 5200 KLMD_ReadMem: Trying to ReadMemory 0x868FBD98[0x38]
17:56:46:562 5200 DetectCureTDL3: DRIVER_OBJECT addr: 869A5868
17:56:46:562 5200 KLMD_ReadMem: Trying to ReadMemory 0x869A5868[0xA8]
17:56:46:562 5200 KLMD_ReadMem: Trying to ReadMemory 0xE1011FE0[0x208]
17:56:46:562 5200 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
17:56:46:562 5200 DetectCureTDL3: IrpHandler (0) addr: F7317B40
17:56:46:562 5200 DetectCureTDL3: IrpHandler (1) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (2) addr: F7317B40
17:56:46:562 5200 DetectCureTDL3: IrpHandler (3) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (4) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (5) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (6) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (7) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler ( addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (9) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (10) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (11) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (12) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (13) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (14) addr: F7317B40
17:56:46:562 5200 DetectCureTDL3: IrpHandler (15) addr: F7317B40
17:56:46:562 5200 DetectCureTDL3: IrpHandler (16) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (17) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (18) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (19) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (20) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (21) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (22) addr: F7317B40
17:56:46:562 5200 DetectCureTDL3: IrpHandler (23) addr: F7317B40
17:56:46:562 5200 DetectCureTDL3: IrpHandler (24) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (25) addr: 804F355A
17:56:46:562 5200 DetectCureTDL3: IrpHandler (26) addr: 804F355A
17:56:46:562 5200 KLMD_ReadMem: Trying to ReadMemory 0xF7315864[0x400]
17:56:46:562 5200 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 316, 0
17:56:46:562 5200 TDL3_FileDetect: Processing driver: atapi
17:56:46:562 5200 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\atapi.sys, C:\WINDOWS\system32\Drivers\atapi.tsk, SYSTEM\CurrentControlSet\Services\atapi, system32\Drivers\atapi.tsk
17:56:46:562 5200 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\atapi.sys
17:56:46:562 5200 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\atapi.sys
17:56:46:562 5200
Completed
Results:
17:56:46:562 5200 Infected objects in memory: 0
17:56:46:562 5200 Cured objects in memory: 0
17:56:46:562 5200 Infected objects on disk: 0
17:56:46:562 5200 Objects on disk cured on reboot: 0
17:56:46:562 5200 Objects on disk deleted on reboot: 0
17:56:46:562 5200 Registry nodes deleted on reboot: 0
17:56:46:562 5200
Malwarebytes' Anti-Malware 1.43
Version de la base de données: 3479
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/01/2010 18:53:26
mbam-log-2010-01-02 (18-53-26).txt
Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|)
Eléments examinés: 327175
Temps écoulé: 38 minute(s), 36 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 5
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
\\?\globalroot\systemroot\system32\H8SRTumvalkwnke.dll (Rootkit.TDSS) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\settdebugx.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
\\?\globalroot\systemroot\system32\H8SRTumvalkwnke.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
D:\Documents and Settings\Hishiro\Local Settings\Temp\settdebugx.exe (Rogue.Installer) -> Quarantined and deleted successfully.
D:\Documents and Settings\Hishiro\Local Settings\Temporary Internet Files\Content.IE5\BEOSC11I\eH8df1cff7V03006f35002Ra5a024c7102Tc6ca3b85Q0000028b901807F0020000aJ0200050
1l000c317P000000070[1] (Trojan.Downloader) -> Quarantined and deleted successfully.
D:\Documents and Settings\Hishiro\Mes documents\Mes fichiers reçus\Axdxoxbxe Axlxl Pxrodxucts Kxexyxmxaker\keygen.exe (Malware.Tool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\krl32mainweq.dll (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Au rédémarrage apres analyse MBM, j'ai eu une erreur systeme ( écran bleu ). J'ai eteint/rallumer la tour et redémarrage correct.