Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e) (modifié)

Bonjour à tous, je viens vous solliciter pour un problème à mon avis non négligeable. Depuis ce matin, un logiciel appelé " Malware Defense" ne cesse d'ouvrir des fenêtres et me disant que j'ai tel ou tel virus sur mon pc et que je dois désinstaller toute une série de programme, entre autre mon antivirus. Je n'ai rien accepté de tout ça. Mon pc est également ralentit depuis.

 

Un anti-spyware vient de faire un scan et m'a détecté 8 infections dont 2 dangereuses : "Trojan.FakeAlert" et "Rootkit.TDSS"

 

Mon pc met plus de 5-10 minutes pour démarrer et je ne peux rien faire dessus, après 5 minutes il plante :P

 

Pourriez vous m'aider svp ?

Modifié par Aioros

Posté(e)

Bonsoir,

 

Télécharger load_tdsskiller de Loup Blanc sur le Bureau

Cet outil est conçu pour automatiser différentes tâches proposées par TDSSKiller, un fix de Kaspersky.

  • Lancer load_tdsskiller en double-cliquant dessus :
    l'outil va se connecter au Net pour télécharger une copie à jour de TDSSKiller et lancer le scan
  • Un message dans la fenêtre noire d'invite de commande vous demandera d'appuyer sur une touche pour continuer
  • Le rapport s'affichera automatiquement : copier-coller son contenu dans la prochaine réponse
    (le fichier est également présent ici : C:\tdsskiller\report.txt)
  • Redémarrer le PC

 

Vous allez télécharger Combofix.

Ce logiciel est très puissant et ne doit pas être utilisé sans une aide compétente sous peine de risquer des dommages irréversibles.

Veuillez noter que ce logiciel est régulièrement mis à jour et que la version que vous allez charger sera obsolète dans quelques jours.

 

Télécharger combofix.exe de sUBs

 

Vous devriez avoir une fenêtre vous avertissant que vous téléchargez Combofix depuis un site non-autorisé.

N'en tenez pas compte

 

Lancez Combofix en double cliquant

 

Tout d'abord, Combofix vérifie si la Console de récupération est installée et vous propose de le faire dans le cas contraire.

Certaines infections comme braviax empêcheront son installation.

Les utilisateurs de Windows Vista peuvent utiliser leur CD Windows pour démarrer en mode Vista Recovery Environment (Environnement de réparation Vista)

La Console de récupération Windows vous permettra de démarrer dans un mode spécial de récupération (réparation).

Elle peut être nécessaire si votre ordinateur rencontre un problème après une tentative de nettoyage.

C'est une procédure simple, qui ne vous prendra que peu de temps et pourra peut-être un jour vous sauver la mis

 

Certaines infections (Rootkit en Mbr)ne peuvent être traitées qu'en utilisant la Console de Récupération,

D'importantes procédures que Combofix est susceptible de lancer ne fonctionneront qu'à la condition que la console de récupération(Sous Xp) soit installée

C'est pourquoi il vous est vivement conseillé d' installer d'abord la Console de Récupération sur le pc .

 

Cela permettra de réparer le système au cas ou le pc ne redémarrerait plus suite à la désinfection.

* Après avoir cliqué sur le lien correspondant à votre version de Windows, vous serez dirigé sur une page:

cliquez sur le bouton Télécharger afin de récupérer le package d'installation sur leBureau:

Ne modifiez pas le nom du fichier

Windows XP Service Pack 2 (SP2) > Microsoft Windows XP Professionnel SP2

* Faites un glisser/déposer de ce fichier sur le fichier ComboFix.exe

 

animation2ko5.gif

 

* Suivre les indications à l'écran pour lancer ComboFix et lorsqu'on le demande, accepter le Contrat de Licence d'Utilisateur Final pour installer la Console de Récupération Microsoft.

Après installation,vous devriez voir ce message:

The Recovery Console was successfully installed.

 

Fermez ou désactivez tous les programmes Antivirus, Antispyware, Pare-feu actifs ,Teatimer de Spybot car ils pourraient perturber le fonctionnement de cet outil

Vous devez désactiver vos protections et ne savez pas comment faire

 

Sur Bleeping Computers en Anglais:

 

Sur PCA,En Français

Cela est absolument nécessaire au succès de la procédure.

Bien évidemment, vous les rétablirez ensuite.

Connecter tous les disques amovibles (disque dur externe, clé USB).

*Double cliquer sur combofix.exe pour le lancer.

 

Ne pas fermer la fenêtre qui vient de s'ouvrir , le bureau serait vide et cela pourrait entraîner un plantage du programme!

Pour lancer le scan

 

* Taper sur la touche 1 pour démarrer le scan.

Si pour une raison quelconque combofix ne se lançait pas,

Démarrez en mode sans échec, choisissez le compte Administrateur,(sous Vista désactivez UAC) lancez Combofix

Lorsque ComboFix tourne, ne touchez plus du tout à votre ordinateur, vous risqueriez de planter le programme.

 

* Le scan pourrait prendre un certain temps:

Patientez au moins 30 minutes pendant l'analyse. Si le programme gèle (+ de 30 minutes), fermez le en cliquant le "X" au haut à droite de la fenêtre.

A la fin,,un rapport sera généré : postez en le contenu dans un prochain message.

* Si le rapport est trop long, postez le en deux fois.

Il se trouve à c:\combofix.txt

Posté(e)

Voici les 2 rapports générés par les applications que vous m'avez link :

 

03:08:49:000 4036 TDSSKiller 2.1.1 Dec 20 2009 02:40:02

03:08:49:000 4036 ================================================================================

03:08:49:000 4036 SystemInfo:

 

03:08:49:000 4036 OS Version: 5.1.2600 ServicePack: 3.0

03:08:49:000 4036 Product type: Workstation

03:08:49:000 4036 ComputerName: QUENTIN

03:08:49:000 4036 UserName: HP_Propriétaire

03:08:49:000 4036 Windows directory: C:\WINDOWS

03:08:49:000 4036 Processor architecture: Intel x86

03:08:49:000 4036 Number of processors: 2

03:08:49:000 4036 Page size: 0x1000

03:08:49:000 4036 Boot type: Normal boot

03:08:49:000 4036 ================================================================================

03:08:49:156 4036 ForceUnloadDriver: NtUnloadDriver error 2

03:08:49:187 4036 main: Driver KLMD_Boot successfully unloaded

03:08:49:687 4036 ForceUnloadDriver: NtUnloadDriver error 2

03:08:49:718 4036 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\Drivers\KLMD.sys) returned status 0

03:08:49:718 4036 main: Driver KLMD successfully dropped

03:08:50:062 4036 main: Driver KLMD successfully loaded

03:08:50:062 4036

Scanning Registry ...

03:08:50:062 4036 ScanServices: Searching service UACd.sys

03:08:50:062 4036 ScanServices: Open/Create key error 2

03:08:50:062 4036 ScanServices: Searching service TDSSserv.sys

03:08:50:062 4036 ScanServices: Open/Create key error 2

03:08:50:062 4036 ScanServices: Searching service gaopdxserv.sys

03:08:50:062 4036 ScanServices: Open/Create key error 2

03:08:50:062 4036 ScanServices: Searching service gxvxcserv.sys

03:08:50:062 4036 ScanServices: Open/Create key error 2

03:08:50:062 4036 ScanServices: Searching service MSIVXserv.sys

03:08:50:062 4036 ScanServices: Open/Create key error 2

03:08:50:062 4036 UnhookRegistry: Kernel module file name: C:\windows\system32\ntkrnlpa.exe, base addr: 804D7000

03:08:50:531 4036 UnhookRegistry: Kernel local addr: D10000

03:08:50:531 4036 UnhookRegistry: KeServiceDescriptorTable addr: D95700

03:08:50:531 4036 UnhookRegistry: KiServiceTable addr: D3D460

03:08:50:531 4036 UnhookRegistry: NtEnumerateKey service number (local): 47

03:08:50:531 4036 UnhookRegistry: NtEnumerateKey local addr: E5CFF2

03:08:50:531 4036 KLMD_OpenDevice: Trying to open KLMD device

03:08:50:531 4036 KLMD_GetSystemRoutineAddressA: Trying to get system routine address ZwEnumerateKey

03:08:50:531 4036 KLMD_GetSystemRoutineAddressW: Trying to get system routine address ZwEnumerateKey

03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x805002C9[0x4]

03:08:50:531 4036 UnhookRegistry: NtEnumerateKey service number (kernel): 47

03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x8050457C[0x4]

03:08:50:531 4036 UnhookRegistry: NtEnumerateKey real addr: 80623FF2

03:08:50:531 4036 UnhookRegistry: NtEnumerateKey calc addr: 80623FF2

03:08:50:531 4036 UnhookRegistry: No SDT hooks found on NtEnumerateKey

03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x80623FF2[0xA]

03:08:50:531 4036 UnhookRegistry: No splicing found on NtEnumerateKey

03:08:50:531 4036

Scanning Kernel memory ...

03:08:50:531 4036 KLMD_OpenDevice: Trying to open KLMD device

03:08:50:531 4036 KLMD_GetSystemObjectAddressByNameA: Trying to get system object address by name \Driver\Disk

03:08:50:531 4036 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk

03:08:50:531 4036 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 87167900

03:08:50:531 4036 DetectCureTDL3: KLMD_GetDeviceObjectList returned 11 DevObjects

03:08:50:531 4036 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 86B55030

03:08:50:531 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86B55030

03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x86B55030[0x38]

03:08:50:531 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900

03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]

03:08:50:531 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]

03:08:50:531 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

03:08:50:531 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0

03:08:50:531 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:531 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0

03:08:50:546 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F

03:08:50:546 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F

03:08:50:546 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (:P addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2

03:08:50:546 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB

03:08:50:546 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28

03:08:50:546 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2

03:08:50:546 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82

03:08:50:546 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E

03:08:50:546 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:546 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:546 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]

03:08:50:546 4036 KLMD_ReadMem: DeviceIoControl error 1

03:08:50:546 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code

03:08:50:546 4036 TDL3_FileDetect: Processing driver: Disk

03:08:50:546 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk

03:08:50:546 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys

03:08:50:546 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys

03:08:50:562 4036 DetectCureTDL3: 1 Curr stack PDEVICE_OBJECT: 86E88610

03:08:50:562 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86E88610

03:08:50:562 4036 KLMD_ReadMem: Trying to ReadMemory 0x86E88610[0x38]

03:08:50:562 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900

03:08:50:562 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]

03:08:50:562 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]

03:08:50:562 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

03:08:50:562 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0

03:08:50:562 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0

03:08:50:562 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F

03:08:50:562 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F

03:08:50:562 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (:P addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2

03:08:50:562 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB

03:08:50:562 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28

03:08:50:562 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2

03:08:50:562 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82

03:08:50:562 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E

03:08:50:562 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:562 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:562 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]

03:08:50:562 4036 KLMD_ReadMem: DeviceIoControl error 1

03:08:50:562 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code

03:08:50:562 4036 TDL3_FileDetect: Processing driver: Disk

03:08:50:562 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk

03:08:50:562 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys

03:08:50:562 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys

03:08:50:578 4036 DetectCureTDL3: 2 Curr stack PDEVICE_OBJECT: 86C718F0

03:08:50:578 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86C718F0

03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C718F0[0x38]

03:08:50:578 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900

03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]

03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]

03:08:50:578 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

03:08:50:578 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0

03:08:50:578 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0

03:08:50:578 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F

03:08:50:578 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F

03:08:50:578 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (:P addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2

03:08:50:578 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB

03:08:50:578 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28

03:08:50:578 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2

03:08:50:578 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82

03:08:50:578 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E

03:08:50:578 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:578 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]

03:08:50:578 4036 KLMD_ReadMem: DeviceIoControl error 1

03:08:50:578 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code

03:08:50:578 4036 TDL3_FileDetect: Processing driver: Disk

03:08:50:578 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk

03:08:50:578 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys

03:08:50:578 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys

03:08:50:578 4036 DetectCureTDL3: 3 Curr stack PDEVICE_OBJECT: 86A9D298

03:08:50:578 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A9D298

03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x86A9D298[0x38]

03:08:50:578 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900

03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]

03:08:50:578 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]

03:08:50:578 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

03:08:50:578 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0

03:08:50:578 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0

03:08:50:593 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F

03:08:50:593 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F

03:08:50:593 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (:P addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2

03:08:50:593 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB

03:08:50:593 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28

03:08:50:593 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2

03:08:50:593 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82

03:08:50:593 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E

03:08:50:593 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:593 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]

03:08:50:593 4036 KLMD_ReadMem: DeviceIoControl error 1

03:08:50:593 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code

03:08:50:593 4036 TDL3_FileDetect: Processing driver: Disk

03:08:50:593 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk

03:08:50:593 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys

03:08:50:593 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys

03:08:50:593 4036 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 86B5CAB8

03:08:50:593 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86B5CAB8

03:08:50:593 4036 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 86F9DC80

03:08:50:593 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86F9DC80

03:08:50:593 4036 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 86C8CDE8

03:08:50:593 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86C8CDE8

03:08:50:593 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C8CDE8[0x38]

03:08:50:593 4036 DetectCureTDL3: DRIVER_OBJECT addr: 86C97AE8

03:08:50:593 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C97AE8[0xA8]

03:08:50:593 4036 KLMD_ReadMem: Trying to ReadMemory 0xE227FBA8[0x208]

03:08:50:593 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

03:08:50:593 4036 DetectCureTDL3: IrpHandler (0) addr: F7A69218

03:08:50:593 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:593 4036 DetectCureTDL3: IrpHandler (2) addr: F7A69218

03:08:50:609 4036 DetectCureTDL3: IrpHandler (3) addr: F7A6923C

03:08:50:609 4036 DetectCureTDL3: IrpHandler (4) addr: F7A6923C

03:08:50:609 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (:) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (14) addr: F7A69180

03:08:50:609 4036 DetectCureTDL3: IrpHandler (15) addr: F7A649E6

03:08:50:609 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (22) addr: F7A685F0

03:08:50:609 4036 DetectCureTDL3: IrpHandler (23) addr: F7A66A6E

03:08:50:609 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:609 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:609 4036 KLMD_ReadMem: Trying to ReadMemory 0xF7A65F26[0x400]

03:08:50:609 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 0, 0

03:08:50:609 4036 TDL3_FileDetect: Processing driver: USBSTOR

03:08:50:609 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\usbstor.sys, C:\WINDOWS\system32\Drivers\usbstor.tsk, SYSTEM\CurrentControlSet\Services\USBSTOR, system32\Drivers\usbstor.tsk

03:08:50:609 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\usbstor.sys

03:08:50:609 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\usbstor.sys

03:08:50:625 4036 DetectCureTDL3: 5 Curr stack PDEVICE_OBJECT: 86AD9338

03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86AD9338

03:08:50:625 4036 DetectCureTDL3: 5 Curr stack PDEVICE_OBJECT: 86A2C108

03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A2C108

03:08:50:625 4036 DetectCureTDL3: 5 Curr stack PDEVICE_OBJECT: 869D8AE0

03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 869D8AE0

03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0x869D8AE0[0x38]

03:08:50:625 4036 DetectCureTDL3: DRIVER_OBJECT addr: 86C97AE8

03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C97AE8[0xA8]

03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0xE227FBA8[0x208]

03:08:50:625 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

03:08:50:625 4036 DetectCureTDL3: IrpHandler (0) addr: F7A69218

03:08:50:625 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (2) addr: F7A69218

03:08:50:625 4036 DetectCureTDL3: IrpHandler (3) addr: F7A6923C

03:08:50:625 4036 DetectCureTDL3: IrpHandler (4) addr: F7A6923C

03:08:50:625 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (;) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (14) addr: F7A69180

03:08:50:625 4036 DetectCureTDL3: IrpHandler (15) addr: F7A649E6

03:08:50:625 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (22) addr: F7A685F0

03:08:50:625 4036 DetectCureTDL3: IrpHandler (23) addr: F7A66A6E

03:08:50:625 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0xF7A65F26[0x400]

03:08:50:625 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 0, 0

03:08:50:625 4036 TDL3_FileDetect: Processing driver: USBSTOR

03:08:50:625 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\usbstor.sys, C:\WINDOWS\system32\Drivers\usbstor.tsk, SYSTEM\CurrentControlSet\Services\USBSTOR, system32\Drivers\usbstor.tsk

03:08:50:625 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\usbstor.sys

03:08:50:625 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\usbstor.sys

03:08:50:625 4036 DetectCureTDL3: 6 Curr stack PDEVICE_OBJECT: 86A7C518

03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A7C518

03:08:50:625 4036 DetectCureTDL3: 6 Curr stack PDEVICE_OBJECT: 86C96CE0

03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86C96CE0

03:08:50:625 4036 DetectCureTDL3: 6 Curr stack PDEVICE_OBJECT: 869DDCC0

03:08:50:625 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 869DDCC0

03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0x869DDCC0[0x38]

03:08:50:625 4036 DetectCureTDL3: DRIVER_OBJECT addr: 86C97AE8

03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C97AE8[0xA8]

03:08:50:625 4036 KLMD_ReadMem: Trying to ReadMemory 0xE227FBA8[0x208]

03:08:50:625 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

03:08:50:625 4036 DetectCureTDL3: IrpHandler (0) addr: F7A69218

03:08:50:625 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (2) addr: F7A69218

03:08:50:625 4036 DetectCureTDL3: IrpHandler (3) addr: F7A6923C

03:08:50:625 4036 DetectCureTDL3: IrpHandler (4) addr: F7A6923C

03:08:50:625 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:625 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (;) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (14) addr: F7A69180

03:08:50:640 4036 DetectCureTDL3: IrpHandler (15) addr: F7A649E6

03:08:50:640 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (22) addr: F7A685F0

03:08:50:640 4036 DetectCureTDL3: IrpHandler (23) addr: F7A66A6E

03:08:50:640 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0xF7A65F26[0x400]

03:08:50:640 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 0, 0

03:08:50:640 4036 TDL3_FileDetect: Processing driver: USBSTOR

03:08:50:640 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\usbstor.sys, C:\WINDOWS\system32\Drivers\usbstor.tsk, SYSTEM\CurrentControlSet\Services\USBSTOR, system32\Drivers\usbstor.tsk

03:08:50:640 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\usbstor.sys

03:08:50:640 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\usbstor.sys

03:08:50:640 4036 DetectCureTDL3: 7 Curr stack PDEVICE_OBJECT: 86FA3AB8

03:08:50:640 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86FA3AB8

03:08:50:640 4036 DetectCureTDL3: 7 Curr stack PDEVICE_OBJECT: 86A36288

03:08:50:640 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A36288

03:08:50:640 4036 DetectCureTDL3: 7 Curr stack PDEVICE_OBJECT: 86A75D50

03:08:50:640 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86A75D50

03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0x86A75D50[0x38]

03:08:50:640 4036 DetectCureTDL3: DRIVER_OBJECT addr: 86C97AE8

03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0x86C97AE8[0xA8]

03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0xE227FBA8[0x208]

03:08:50:640 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

03:08:50:640 4036 DetectCureTDL3: IrpHandler (0) addr: F7A69218

03:08:50:640 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (2) addr: F7A69218

03:08:50:640 4036 DetectCureTDL3: IrpHandler (3) addr: F7A6923C

03:08:50:640 4036 DetectCureTDL3: IrpHandler (4) addr: F7A6923C

03:08:50:640 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (:) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (14) addr: F7A69180

03:08:50:640 4036 DetectCureTDL3: IrpHandler (15) addr: F7A649E6

03:08:50:640 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (22) addr: F7A685F0

03:08:50:640 4036 DetectCureTDL3: IrpHandler (23) addr: F7A66A6E

03:08:50:640 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:640 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:640 4036 KLMD_ReadMem: Trying to ReadMemory 0xF7A65F26[0x400]

03:08:50:640 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 0, 0

03:08:50:640 4036 TDL3_FileDetect: Processing driver: USBSTOR

03:08:50:640 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\usbstor.sys, C:\WINDOWS\system32\Drivers\usbstor.tsk, SYSTEM\CurrentControlSet\Services\USBSTOR, system32\Drivers\usbstor.tsk

03:08:50:640 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\usbstor.sys

03:08:50:640 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\usbstor.sys

03:08:50:656 4036 DetectCureTDL3: 8 Curr stack PDEVICE_OBJECT: 8713EC68

03:08:50:656 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8713EC68

03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x8713EC68[0x38]

03:08:50:656 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900

03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]

03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]

03:08:50:656 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

03:08:50:656 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0

03:08:50:656 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0

03:08:50:656 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F

03:08:50:656 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F

03:08:50:656 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (:D addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2

03:08:50:656 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB

03:08:50:656 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28

03:08:50:656 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2

03:08:50:656 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82

03:08:50:656 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E

03:08:50:656 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]

03:08:50:656 4036 KLMD_ReadMem: DeviceIoControl error 1

03:08:50:656 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code

03:08:50:656 4036 TDL3_FileDetect: Processing driver: Disk

03:08:50:656 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk

03:08:50:656 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys

03:08:50:656 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys

03:08:50:656 4036 DetectCureTDL3: 9 Curr stack PDEVICE_OBJECT: 8713F9F0

03:08:50:656 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8713F9F0

03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x8713F9F0[0x38]

03:08:50:656 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87167900

03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0x87167900[0xA8]

03:08:50:656 4036 KLMD_ReadMem: Trying to ReadMemory 0xE19D83A8[0x208]

03:08:50:656 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

03:08:50:656 4036 DetectCureTDL3: IrpHandler (0) addr: F76C2BB0

03:08:50:656 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (2) addr: F76C2BB0

03:08:50:656 4036 DetectCureTDL3: IrpHandler (3) addr: F76BCD1F

03:08:50:656 4036 DetectCureTDL3: IrpHandler (4) addr: F76BCD1F

03:08:50:656 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (:lol: addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (9) addr: F76BD2E2

03:08:50:656 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:656 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (14) addr: F76BD3BB

03:08:50:671 4036 DetectCureTDL3: IrpHandler (15) addr: F76C0F28

03:08:50:671 4036 DetectCureTDL3: IrpHandler (16) addr: F76BD2E2

03:08:50:671 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (22) addr: F76BEC82

03:08:50:671 4036 DetectCureTDL3: IrpHandler (23) addr: F76C399E

03:08:50:671 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]

03:08:50:671 4036 KLMD_ReadMem: DeviceIoControl error 1

03:08:50:671 4036 TDL3_StartIoHookDetect: Unable to get StartIo handler code

03:08:50:671 4036 TDL3_FileDetect: Processing driver: Disk

03:08:50:671 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\disk.tsk, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\disk.tsk

03:08:50:671 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys

03:08:50:671 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys

03:08:50:671 4036 DetectCureTDL3: 10 Curr stack PDEVICE_OBJECT: 87160AB8

03:08:50:671 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87160AB8

03:08:50:671 4036 DetectCureTDL3: 10 Curr stack PDEVICE_OBJECT: 87142958

03:08:50:671 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87142958

03:08:50:671 4036 DetectCureTDL3: 10 Curr stack PDEVICE_OBJECT: 87165B00

03:08:50:671 4036 KLMD_GetLowerDeviceObject: Trying to get lower device object for 87165B00

03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0x87165B00[0x38]

03:08:50:671 4036 DetectCureTDL3: DRIVER_OBJECT addr: 87188510

03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0x87188510[0xA8]

03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0xE1012910[0x208]

03:08:50:671 4036 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi

03:08:50:671 4036 DetectCureTDL3: IrpHandler (0) addr: F74CE6F2

03:08:50:671 4036 DetectCureTDL3: IrpHandler (1) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (2) addr: F74CE6F2

03:08:50:671 4036 DetectCureTDL3: IrpHandler (3) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (4) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (5) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (6) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (7) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (:mhh: addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (9) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (10) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (11) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (12) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (13) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (14) addr: F74CE712

03:08:50:671 4036 DetectCureTDL3: IrpHandler (15) addr: F74CA852

03:08:50:671 4036 DetectCureTDL3: IrpHandler (16) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (17) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (18) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (19) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (20) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (21) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (22) addr: F74CE73C

03:08:50:671 4036 DetectCureTDL3: IrpHandler (23) addr: F74D5336

03:08:50:671 4036 DetectCureTDL3: IrpHandler (24) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (25) addr: 804F4562

03:08:50:671 4036 DetectCureTDL3: IrpHandler (26) addr: 804F4562

03:08:50:671 4036 KLMD_ReadMem: Trying to ReadMemory 0xF74CB864[0x400]

03:08:50:671 4036 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 316, 0

03:08:50:671 4036 TDL3_FileDetect: Processing driver: atapi

03:08:50:671 4036 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\atapi.sys, C:\WINDOWS\system32\Drivers\atapi.tsk, SYSTEM\CurrentControlSet\Services\atapi, system32\Drivers\atapi.tsk

03:08:50:671 4036 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\atapi.sys

03:08:50:671 4036 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\atapi.sys

03:08:50:703 4036

Completed

 

Results:

03:08:50:703 4036 Infected objects in memory: 0

03:08:50:703 4036 Cured objects in memory: 0

03:08:50:703 4036 Infected objects on disk: 0

03:08:50:703 4036 Objects on disk cured on reboot: 0

03:08:50:703 4036 Objects on disk deleted on reboot: 0

03:08:50:703 4036 Registry nodes deleted on reboot: 0

03:08:50:703 4036

 

 

 

 

 

 

 

 

 

 

 

ComboFix 09-12-24.02 - HP_Propriétaire 25/12/2009 3:23.4.2 - x86

Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.304 [GMT 1:00]

Lancé depuis: c:\documents and settings\HP_Propriétaire\Mes documents\Téléchargements\69356-CF.exe

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\LHT1F.tmp

C:\LHT22.tmp

C:\LHT23.tmp

C:\LHT90.tmp

C:\LHTB6.tmp

c:\windows\system32\2492142984.dat

c:\windows\system32\404Fix.exe

c:\windows\system32\Agent.OMZ.Fix.exe

c:\windows\system32\dumphive.exe

c:\windows\system32\H8SRTiqqjcbqjhn.dll

c:\windows\system32\H8SRTmttappehem.dat

c:\windows\system32\IEDFix.C.exe

c:\windows\system32\IEDFix.exe

c:\windows\system32\krl32mainweq.dll

c:\windows\system32\o4Patch.exe

c:\windows\system32\Process.exe

c:\windows\system32\ps2.bat

c:\windows\system32\SrchSTS.exe

c:\windows\system32\srcr.dat

c:\windows\system32\tmp.reg

c:\windows\system32\VACFix.exe

c:\windows\system32\VCCLSID.exe

c:\windows\system32\WS2Fix.exe

 

.

((((((((((((((((((((((((((((( Fichiers créés du 2009-11-25 au 2009-12-25 ))))))))))))))))))))))))))))))))))))

.

 

2009-12-25 01:54 . 2009-12-25 02:08 -------- d-----w- C:\tdsskiller

2009-12-24 14:45 . 2009-12-24 14:45 -------- d-sh--w- c:\documents and settings\Administrateur\PrivacIE

2009-12-24 14:43 . 2009-12-24 14:43 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache

2009-12-24 13:49 . 2009-12-24 13:49 -------- d-----w- C:\sh4ldr

2009-12-24 13:48 . 2009-12-24 13:48 -------- d-----w- c:\program files\Enigma Software Group

2009-12-24 11:12 . 2009-12-24 11:12 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools

2009-12-24 11:12 . 2009-12-25 02:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2009-12-09 16:53 . 2009-12-11 21:18 -------- d-----w- c:\program files\Microsoft Silverlight

2009-12-09 16:53 . 2009-12-09 16:53 -------- d-----w- c:\program files\Microsoft Office Outlook Connector

2009-12-09 16:53 . 2009-08-05 21:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys

2009-12-09 16:52 . 2009-12-09 16:52 -------- d-----w- c:\program files\Microsoft Sync Framework

2009-12-09 16:51 . 2006-11-29 12:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll

2009-12-09 16:51 . 2009-12-09 16:51 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition

2009-12-09 16:49 . 2009-12-09 16:53 -------- d-----w- c:\program files\Microsoft

2009-12-09 16:49 . 2009-12-09 16:49 -------- d-----w- c:\program files\Windows Live SkyDrive

2009-12-09 16:43 . 2009-12-09 16:43 -------- d-----w- c:\program files\Fichiers communs\Windows Live

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-12-25 02:30 . 2009-12-24 11:12 -------- d-----w- c:\program files\Spyware Doctor

2009-12-25 02:29 . 2009-06-14 00:32 -------- d-----w- c:\program files\DNA

2009-12-24 15:34 . 2005-10-11 18:42 -------- d-----w- c:\program files\Google

2009-12-24 11:17 . 2009-12-24 11:12 -------- d-----w- c:\program files\Fichiers communs\PC Tools

2009-12-19 09:51 . 2008-10-21 13:58 -------- d-----w- c:\program files\World of Warcraft

2009-12-15 19:18 . 2004-11-23 21:26 86862 ----a-w- c:\windows\system32\perfc00C.dat

2009-12-15 19:18 . 2004-11-23 21:26 515380 ----a-w- c:\windows\system32\perfh00C.dat

2009-12-10 21:58 . 2008-10-21 19:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2009-12-09 16:53 . 2008-10-21 15:47 -------- d-----w- c:\program files\Windows Live

2009-12-07 19:24 . 2009-06-03 13:04 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2009-11-18 18:04 . 2008-10-23 19:29 -------- d-----w- c:\program files\WowCartographe

2009-11-10 09:28 . 2009-12-24 11:17 149456 ----a-w- c:\windows\SGDetectionTool.dll

2009-11-10 09:28 . 2009-12-24 11:17 1640400 ----a-w- c:\windows\PCTBDCore.dll

2009-11-10 09:28 . 2009-12-24 11:17 165840 ----a-w- c:\windows\PCTBDRes.dll

2009-11-10 09:26 . 2009-12-24 11:17 767952 ----a-w- c:\windows\BDTSupport.dll

2009-11-09 10:20 . 2009-12-24 11:13 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2009-10-30 10:11 . 2009-12-24 11:13 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2009-10-29 07:42 . 2004-08-05 18:00 916480 ----a-w- c:\windows\system32\wininet.dll

2009-10-28 00:36 . 2009-12-24 11:17 1152444 ----a-w- c:\windows\UDB.zip

2009-10-21 05:39 . 2004-08-05 18:00 75776 ----a-w- c:\windows\system32\strmfilt.dll

2009-10-21 05:39 . 2004-08-05 18:00 25088 ----a-w- c:\windows\system32\httpapi.dll

2009-10-20 16:20 . 2004-08-05 18:00 265728 ----a-w- c:\windows\system32\drivers\http.sys

2009-10-13 10:33 . 2004-08-05 18:00 271360 ----a-w- c:\windows\system32\oakley.dll

2009-10-12 13:39 . 2004-08-05 18:00 79872 ----a-w- c:\windows\system32\raschap.dll

2009-10-12 13:39 . 2004-08-05 18:00 150528 ----a-w- c:\windows\system32\rastls.dll

2009-10-06 15:31 . 2009-12-24 11:13 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll

2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll

.

 

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-02 24264488]

"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]

"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 61952]

"SoundMan"="SOUNDMAN.EXE" [2005-05-04 90112]

"AlcWzrd"="ALCWZRD.EXE" [2005-05-04 2805248]

"RemoteControl"="c:\program files\ASUS\ASUS Remote\RemoteControlAppl.exe" [2005-06-10 61440]

"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]

"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]

"Home Theater SchSvr"="c:\program files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2005-07-18 106496]

"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2005-07-18 262144]

"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]

"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]

"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]

"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]

"nwiz"="nwiz.exe" [2009-04-30 1657376]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-30 86016]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-16 148888]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]

"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]

"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-12-09 866200]

 

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

@="Service"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\eMule\\emule.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-2.4.3-to-3.0.2-frFR-Win-Final-downloader.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\World of Warcraft\\Launcher.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=

"c:\\Program Files\\DNA\\btdna.exe"=

"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-frFR-downloader.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-frFR-downloader.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-frFR-downloader.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-frFR-downloader.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3724:UDP"= 3724:UDP:Blizzard downloader:3724

"6112:TCP"= 6112:TCP:Blibli downloader

"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

"27709:TCP"= 27709:TCP:tcp

 

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [3/06/2009 10:57 28544]

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [24/12/2009 12:13 207792]

R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [24/12/2009 12:17 112592]

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/12/2009 17:53 54752]

R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [24/12/2009 12:13 359624]

R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [11/10/2005 19:08 2786176]

S2 a2AntiMalware;a-squared Anti-Malware Service;"c:\program files\a-squared Anti-Malware\a2service.exe" --> c:\program files\a-squared Anti-Malware\a2service.exe [?]

S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/07/2009 20:57 108289]

S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [5/08/2009 22:48 704864]

 

--- Autres Services/Pilotes en mémoire ---

 

*NewlyCreated* - KLMD_BOOT

*NewlyCreated* - KLMD_SYSTEM

*Deregistered* - KLMD

*Deregistered* - KLMD_Boot

*Deregistered* - KLMD_System

*Deregistered* - PCTSDInjDriver32

.

------- Examen supplémentaire -------

.

uStart Page =

uInternet Settings,ProxyOverride = *.local

IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html

IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html

IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html

IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html

DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab

FF - ProfilePath - c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\wlot0w3y.default\

FF - prefs.js: browser.startup.homepage - www.jeuxvideo.com

FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll

FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

- - - - ORPHELINS SUPPRIMES - - - -

 

HKCU-Run-Malware Defense - c:\program files\Malware Defense\mdefense.exe

AddRemove-Smart Defrag_is1 - c:\program files\IObit\IObit SmartDefrag\unins000.exe

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-12-25 03:30

Windows 5.1.2600 Service Pack 3 NTFS

 

detected NTDLL code modification:

ZwClose

 

Recherche de processus cachés ...

 

Recherche d'éléments en démarrage automatique cachés ...

 

Recherche de fichiers cachés ...

 

Scan terminé avec succès

Fichiers cachés: 0

 

**************************************************************************

.

--------------------- DLLs chargées dans les processus actifs ---------------------

 

- - - - - - - > 'winlogon.exe'(620)

c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll

 

- - - - - - - > 'lsass.exe'(676)

c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll

.

Heure de fin: 2009-12-25 03:33:26

ComboFix-quarantined-files.txt 2009-12-25 02:33

 

Avant-CF: 90.292.166.656 octets libres

Après-CF: 90.348.179.456 octets libres

 

- - End Of File - - E22D86CA7B92C83D8245A66C9B848239

Posté(e)

Bonjour,

 

Désinstallez Mbam, s'il est installé

Téléchargez MBAM

 

[branchez tous les supports amovibles avant de faire ce scan (clé usb/disque dur externe etc)

Si vous utilisez Spybot

Pour désactiver TeaTimer qui ne set à rien et peut faire échouer une désinfection:!

Afficher d'abord le Mode Avancé dans SpyBot

->Options Avancées :

- >menu Mode, Mode Avancé.

Une colonne de menus apparaît dans la partie gauche :

- >cliquer sur Outils,

- >cliquer sur Résident,

Dans Résident :

- >décocher Résident "TeaTimer" pour le désactiver.

* Double cliquez sur l'icône Download_mbam-setup.exe pour lancer le processus d'installation.

Enregistrez le sur le bureau .

Fermer toutes les fenêtres et programmes

Suivez les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet)

N'apportez aucune modification aux réglages par défaut et, en fin d'installation,

Vérifiez que les options Update et Launch soient cochées

MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse.

cliquer sur OK pour fermer la boîte de dialogue..

* Dans l'onglet "mise à jour", cliquez sur le bouton Recherche de mise à jour:

Si le pare-feu demande l'autorisation à MBAM de se connecter, acceptez.

* Une fois la mise à jour terminée, allez dans l'onglet Recherche.

* Sélectionnez "Exécuter un examen rapide"

* Cliquez sur "Rechercher"

* .L' analyse prendra un certain temps, soyez patient !

* A la fin , un message affichera :

L'examen s'est terminé normalement.

 

*Si MBAM n'a rien trouvé, il le dira aussi.

Cliquez sur "Ok" pour poursuivre.

*Fermez les navigateurs.

Cliquez sur Afficher les résultats .

 

*Sélectionnez tout et cliquez sur Supprimer la sélection ,

MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

puis ouvrir le Bloc-notes et y copier le rapport d'analyse qui peut être retrouvé sous l'onglet Rapports/logs.

* Copiez-collez ce rapport dans la prochaine réponse.

 

Scan en ligne

NOTE: Le scan en ligne sera à faire avec Internet Explorer.

Désactiver l'antivirus actuel

Kaspersky

Sous Vista,il faut désactiver l'UAC, et cliquer droit sur Internet Explorer / Exécuter en tant qu'administrateur et coller l'URL de Kaspersky

http://www.kaspersky.com/kos/eng/partner/d...kavwebscan.html

Vider la corbeille.

* Cliquer sur Accept

* Une barre jaune va demander d'accepter l'installation de Kavwebscan_Unicode.cab, installer l'Active X.

* cliquer une nouvelle fois sur "Accept"

* Les bases de mises à jour vont s'installer, patienter un moment

* Cliquer sur Next.

* Cliquer sur My Computer, le scan se met en route;

attendre la fin du scan sans fermer la fenêtre sinon il s'arrêtera.

A la fin du scan, si des objets infectés sont découverts, cliquer sur Save report as...

Choisir bureau et nommer le rapport "rapport Kaspersky" et dans le champ d'enregistrement, choisir "fichiers texte" enregistrer le rapport.

Copier/coller l'entièreté du fichier texte ouvert, par clic droit dessus, sélectionner tout/copier.

Coller ce rapport dans la réponse sur le forum.

 

Posté(e)

Désolé de la réponse tardive, voici les 2 rapports demandés :

 

ComboFix 09-12-24.02 - HP_Propriétaire 25/12/2009 3:23.4.2 - x86

Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.304 [GMT 1:00]

Lancé depuis: c:\documents and settings\HP_Propriétaire\Mes documents\Téléchargements\69356-CF.exe

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\LHT1F.tmp

C:\LHT22.tmp

C:\LHT23.tmp

C:\LHT90.tmp

C:\LHTB6.tmp

c:\windows\system32\2492142984.dat

c:\windows\system32\404Fix.exe

c:\windows\system32\Agent.OMZ.Fix.exe

c:\windows\system32\dumphive.exe

c:\windows\system32\H8SRTiqqjcbqjhn.dll

c:\windows\system32\H8SRTmttappehem.dat

c:\windows\system32\IEDFix.C.exe

c:\windows\system32\IEDFix.exe

c:\windows\system32\krl32mainweq.dll

c:\windows\system32\o4Patch.exe

c:\windows\system32\Process.exe

c:\windows\system32\ps2.bat

c:\windows\system32\SrchSTS.exe

c:\windows\system32\srcr.dat

c:\windows\system32\tmp.reg

c:\windows\system32\VACFix.exe

c:\windows\system32\VCCLSID.exe

c:\windows\system32\WS2Fix.exe

 

.

((((((((((((((((((((((((((((( Fichiers créés du 2009-11-25 au 2009-12-25 ))))))))))))))))))))))))))))))))))))

.

 

2009-12-25 01:54 . 2009-12-25 02:08 -------- d-----w- C:\tdsskiller

2009-12-24 14:45 . 2009-12-24 14:45 -------- d-sh--w- c:\documents and settings\Administrateur\PrivacIE

2009-12-24 14:43 . 2009-12-24 14:43 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache

2009-12-24 13:49 . 2009-12-24 13:49 -------- d-----w- C:\sh4ldr

2009-12-24 13:48 . 2009-12-24 13:48 -------- d-----w- c:\program files\Enigma Software Group

2009-12-24 11:12 . 2009-12-24 11:12 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools

2009-12-24 11:12 . 2009-12-25 02:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2009-12-09 16:53 . 2009-12-11 21:18 -------- d-----w- c:\program files\Microsoft Silverlight

2009-12-09 16:53 . 2009-12-09 16:53 -------- d-----w- c:\program files\Microsoft Office Outlook Connector

2009-12-09 16:53 . 2009-08-05 21:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys

2009-12-09 16:52 . 2009-12-09 16:52 -------- d-----w- c:\program files\Microsoft Sync Framework

2009-12-09 16:51 . 2006-11-29 12:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll

2009-12-09 16:51 . 2009-12-09 16:51 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition

2009-12-09 16:49 . 2009-12-09 16:53 -------- d-----w- c:\program files\Microsoft

2009-12-09 16:49 . 2009-12-09 16:49 -------- d-----w- c:\program files\Windows Live SkyDrive

2009-12-09 16:43 . 2009-12-09 16:43 -------- d-----w- c:\program files\Fichiers communs\Windows Live

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-12-25 02:30 . 2009-12-24 11:12 -------- d-----w- c:\program files\Spyware Doctor

2009-12-25 02:29 . 2009-06-14 00:32 -------- d-----w- c:\program files\DNA

2009-12-24 15:34 . 2005-10-11 18:42 -------- d-----w- c:\program files\Google

2009-12-24 11:17 . 2009-12-24 11:12 -------- d-----w- c:\program files\Fichiers communs\PC Tools

2009-12-19 09:51 . 2008-10-21 13:58 -------- d-----w- c:\program files\World of Warcraft

2009-12-15 19:18 . 2004-11-23 21:26 86862 ----a-w- c:\windows\system32\perfc00C.dat

2009-12-15 19:18 . 2004-11-23 21:26 515380 ----a-w- c:\windows\system32\perfh00C.dat

2009-12-10 21:58 . 2008-10-21 19:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2009-12-09 16:53 . 2008-10-21 15:47 -------- d-----w- c:\program files\Windows Live

2009-12-07 19:24 . 2009-06-03 13:04 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2009-11-18 18:04 . 2008-10-23 19:29 -------- d-----w- c:\program files\WowCartographe

2009-11-10 09:28 . 2009-12-24 11:17 149456 ----a-w- c:\windows\SGDetectionTool.dll

2009-11-10 09:28 . 2009-12-24 11:17 1640400 ----a-w- c:\windows\PCTBDCore.dll

2009-11-10 09:28 . 2009-12-24 11:17 165840 ----a-w- c:\windows\PCTBDRes.dll

2009-11-10 09:26 . 2009-12-24 11:17 767952 ----a-w- c:\windows\BDTSupport.dll

2009-11-09 10:20 . 2009-12-24 11:13 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2009-10-30 10:11 . 2009-12-24 11:13 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2009-10-29 07:42 . 2004-08-05 18:00 916480 ----a-w- c:\windows\system32\wininet.dll

2009-10-28 00:36 . 2009-12-24 11:17 1152444 ----a-w- c:\windows\UDB.zip

2009-10-21 05:39 . 2004-08-05 18:00 75776 ----a-w- c:\windows\system32\strmfilt.dll

2009-10-21 05:39 . 2004-08-05 18:00 25088 ----a-w- c:\windows\system32\httpapi.dll

2009-10-20 16:20 . 2004-08-05 18:00 265728 ----a-w- c:\windows\system32\drivers\http.sys

2009-10-13 10:33 . 2004-08-05 18:00 271360 ----a-w- c:\windows\system32\oakley.dll

2009-10-12 13:39 . 2004-08-05 18:00 79872 ----a-w- c:\windows\system32\raschap.dll

2009-10-12 13:39 . 2004-08-05 18:00 150528 ----a-w- c:\windows\system32\rastls.dll

2009-10-06 15:31 . 2009-12-24 11:13 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll

2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll

.

 

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-02 24264488]

"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]

"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 61952]

"SoundMan"="SOUNDMAN.EXE" [2005-05-04 90112]

"AlcWzrd"="ALCWZRD.EXE" [2005-05-04 2805248]

"RemoteControl"="c:\program files\ASUS\ASUS Remote\RemoteControlAppl.exe" [2005-06-10 61440]

"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]

"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]

"Home Theater SchSvr"="c:\program files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2005-07-18 106496]

"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2005-07-18 262144]

"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]

"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]

"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]

"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]

"nwiz"="nwiz.exe" [2009-04-30 1657376]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-30 86016]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-16 148888]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]

"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]

"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-12-09 866200]

 

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

@="Service"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\eMule\\emule.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-2.4.3-to-3.0.2-frFR-Win-Final-downloader.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\World of Warcraft\\Launcher.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=

"c:\\Program Files\\DNA\\btdna.exe"=

"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-frFR-downloader.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-frFR-downloader.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-frFR-downloader.exe"=

"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-frFR-downloader.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3724:UDP"= 3724:UDP:Blizzard downloader:3724

"6112:TCP"= 6112:TCP:Blibli downloader

"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

"27709:TCP"= 27709:TCP:tcp

 

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [3/06/2009 10:57 28544]

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [24/12/2009 12:13 207792]

R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [24/12/2009 12:17 112592]

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/12/2009 17:53 54752]

R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [24/12/2009 12:13 359624]

R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [11/10/2005 19:08 2786176]

S2 a2AntiMalware;a-squared Anti-Malware Service;"c:\program files\a-squared Anti-Malware\a2service.exe" --> c:\program files\a-squared Anti-Malware\a2service.exe [?]

S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/07/2009 20:57 108289]

S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [5/08/2009 22:48 704864]

 

--- Autres Services/Pilotes en mémoire ---

 

*NewlyCreated* - KLMD_BOOT

*NewlyCreated* - KLMD_SYSTEM

*Deregistered* - KLMD

*Deregistered* - KLMD_Boot

*Deregistered* - KLMD_System

*Deregistered* - PCTSDInjDriver32

.

------- Examen supplémentaire -------

.

uStart Page =

uInternet Settings,ProxyOverride = *.local

IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html

IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html

IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html

IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html

DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab

FF - ProfilePath - c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\wlot0w3y.default\

FF - prefs.js: browser.startup.homepage - www.jeuxvideo.com

FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll

FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

- - - - ORPHELINS SUPPRIMES - - - -

 

HKCU-Run-Malware Defense - c:\program files\Malware Defense\mdefense.exe

AddRemove-Smart Defrag_is1 - c:\program files\IObit\IObit SmartDefrag\unins000.exe

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-12-25 03:30

Windows 5.1.2600 Service Pack 3 NTFS

 

detected NTDLL code modification:

ZwClose

 

Recherche de processus cachés ...

 

Recherche d'éléments en démarrage automatique cachés ...

 

Recherche de fichiers cachés ...

 

Scan terminé avec succès

Fichiers cachés: 0

 

**************************************************************************

.

--------------------- DLLs chargées dans les processus actifs ---------------------

 

- - - - - - - > 'winlogon.exe'(620)

c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll

 

- - - - - - - > 'lsass.exe'(676)

c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll

.

Heure de fin: 2009-12-25 03:33:26

ComboFix-quarantined-files.txt 2009-12-25 02:33

 

Avant-CF: 90.292.166.656 octets libres

Après-CF: 90.348.179.456 octets libres

 

- - End Of File - - E22D86CA7B92C83D8245A66C9B848239

 

 

 

 

 

 

 

 

--------------------------------------------------------------------------------

KASPERSKY ONLINE SCANNER 7.0: scan report

Friday, December 25, 2009

Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)

Kaspersky Online Scanner version: 7.0.26.13

Last database update: Friday, December 25, 2009 11:16:07

Records in database: 3410334

--------------------------------------------------------------------------------

 

Scan settings:

scan using the following database: extended

Scan archives: yes

Scan e-mail databases: yes

 

Scan area - My Computer:

C:\

D:\

E:\

F:\

G:\

H:\

I:\

J:\

 

Scan statistics:

Objects scanned: 88537

Threats found: 1

Infected objects found: 1

Suspicious objects found: 0

Scan duration: 02:34:42

 

 

File name / Threat / Threats count

C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTiqqjcbqjhn.dll.vir Infected: Packed.Win32.TDSS.aa 1

 

Selected area has been scanned.

 

Je n'ai plus le logiciel "malware defense" ainsi que toutes les autres anomalies apparues hier matin mais mon pc reste d'une lenteur affreuse...

 

Merci de vos réponses

Posté(e)

Excusez-moi j'ai posté le mauvais rapport

 

Les voici :

 

Malwarebytes' Anti-Malware 1.42

Version de la base de données: 3427

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

25/12/2009 12:42:05

mbam-log-2009-12-25 (12-42-05).txt

 

Type de recherche: Examen rapide

Eléments examinés: 127364

Temps écoulé: 5 minute(s), 18 second(s)

 

Processus mémoire infecté(s): 0

Module(s) mémoire infecté(s): 0

Clé(s) du Registre infectée(s): 0

Valeur(s) du Registre infectée(s): 0

Elément(s) de données du Registre infecté(s): 0

Dossier(s) infecté(s): 0

Fichier(s) infecté(s): 0

 

Processus mémoire infecté(s):

(Aucun élément nuisible détecté)

 

Module(s) mémoire infecté(s):

(Aucun élément nuisible détecté)

 

Clé(s) du Registre infectée(s):

(Aucun élément nuisible détecté)

 

Valeur(s) du Registre infectée(s):

(Aucun élément nuisible détecté)

 

Elément(s) de données du Registre infecté(s):

(Aucun élément nuisible détecté)

 

Dossier(s) infecté(s):

(Aucun élément nuisible détecté)

 

Fichier(s) infecté(s):

(Aucun élément nuisible détecté)

 

 

 

--------------------------------------------------------------------------------

KASPERSKY ONLINE SCANNER 7.0: scan report

Friday, December 25, 2009

Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)

Kaspersky Online Scanner version: 7.0.26.13

Last database update: Friday, December 25, 2009 11:16:07

Records in database: 3410334

--------------------------------------------------------------------------------

 

Scan settings:

scan using the following database: extended

Scan archives: yes

Scan e-mail databases: yes

 

Scan area - My Computer:

C:\

D:\

E:\

F:\

G:\

H:\

I:\

J:\

 

Scan statistics:

Objects scanned: 88537

Threats found: 1

Infected objects found: 1

Suspicious objects found: 0

Scan duration: 02:34:42

 

 

File name / Threat / Threats count

C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTiqqjcbqjhn.dll.vir Infected: Packed.Win32.TDSS.aa 1

 

Selected area has been scanned.

Posté(e)

C'est parfait !

 

Veuillez noter que ce logiciel est régulièrement mis à jour et que la version que vous avez chargée sera obsolète dans quelques jours.

Pour supprimer Combofix:

Démarrer > Exécuter ->ComboFix /uninstall

 

Supprimez C:\qoobox si vous le trouvez

 

Il ne vous servirait à rien de garder des outils de désinfection qui sont constamment mis à jours et seraient obsolètes en quelques jours.

 

Pour enlever les programmes utilisés pendant la procédure.

Télécharger ToolsCleaner2 de A.Rothstein

* Enregistrer ToolsCleaner2.exe sur le Bureau.

Sous Vista,Clic-droit > Exécuter en tant que Administrateur

* Double-cliquer dessus, puis cliquer sur Recherche --> Le programme va chercher les utilitaires installés

------> Il se peut que la fenêtre devienne blanche pendant le scan, c'est normal !

L'outil supprimera sans que vous ayez à intervenir.

 

Si vous estimez votre problème résolu, éditez l'en tête de votre premier message et y indiquez Résolu pour que ceux qui la recherchent y trouvent une solution.

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...