Rapport Wort:
===== Rapport WareOut Removal Tool =====
version 3.6.2
analyse effectuée le 11/08/2009 à 10:45:37,14
Résultats de l'analyse :
========================
~~~~ Recherche d'infections dans C:\ ~~~~
~~~~ Recherche d'infections dans C:\Program Files\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system32\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system32\drivers\ ~~~~
~~~~ Recherche d'infections dans C:\Users\julien\AppData\Roaming\ ~~~~
~~~~ Recherche d'infections dans C:\Users\julien\Bureau\ ~~~~
~~~~ Recherche de détournement de DNS ~~~~
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2A130B8B-CBE1-43B5-A8BD-95C59D92AD81}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{4E5C72C1-474A-4E59-A5C2-66EE7E3B8FDE}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
DhcpNameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{2A130B8B-CBE1-43B5-A8BD-95C59D92AD81}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{4E5C72C1-474A-4E59-A5C2-66EE7E3B8FDE}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
DhcpNameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{2A130B8B-CBE1-43B5-A8BD-95C59D92AD81}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{4E5C72C1-474A-4E59-A5C2-66EE7E3B8FDE}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
DhcpNameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\Tcpip\Parameters\Interfaces\{2A130B8B-CBE1-43B5-A8BD-95C59D92AD81}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\Tcpip\Parameters\Interfaces\{4E5C72C1-474A-4E59-A5C2-66EE7E3B8FDE}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
DhcpNameServer REG_SZ 85.255.112.182,85.255.112.119
~~~~ Recherche de Rootkits ~~~~
_______________________________________________________________________
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-11 10:45:50
Windows 6.0.6000 NTFS
scanning hidden files ...
disk error: C:\Windows\system32\
please note that you need administrator rights to perform deep scan
_______________________________________________________________________
~~~~ Recherche d'infections dans C:\Users\julien\AppData\Local\Temp\ ~~~~
~~~~ Recherche d'infections dans C:\Users\julien\Start Menu\Programs\ ~~~~
~~~~ Nettoyage du registre ~~~~
~~~~ Tentative de réparation des entrées suivantes: ~~~~
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] = "System"
[HKLM\SYSTEM\CurrentControlSet\Services\Windows Tribute Service]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Windows Tribute Service]
~~~~ Vérification: ~~~~
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System REG_SZ
_________________________________
développé par http://pc-system.fr
_________________________________
RAPPORT HIJACKTHIS:
===== Rapport WareOut Removal Tool =====
version 3.6.2
analyse effectuée le 11/08/2009 à 10:45:37,14
Résultats de l'analyse :
========================
~~~~ Recherche d'infections dans C:\ ~~~~
~~~~ Recherche d'infections dans C:\Program Files\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system32\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system32\drivers\ ~~~~
~~~~ Recherche d'infections dans C:\Users\julien\AppData\Roaming\ ~~~~
~~~~ Recherche d'infections dans C:\Users\julien\Bureau\ ~~~~
~~~~ Recherche de détournement de DNS ~~~~
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2A130B8B-CBE1-43B5-A8BD-95C59D92AD81}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{4E5C72C1-474A-4E59-A5C2-66EE7E3B8FDE}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
DhcpNameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{2A130B8B-CBE1-43B5-A8BD-95C59D92AD81}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{4E5C72C1-474A-4E59-A5C2-66EE7E3B8FDE}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
DhcpNameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{2A130B8B-CBE1-43B5-A8BD-95C59D92AD81}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{4E5C72C1-474A-4E59-A5C2-66EE7E3B8FDE}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
DhcpNameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\Tcpip\Parameters\Interfaces\{2A130B8B-CBE1-43B5-A8BD-95C59D92AD81}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\Tcpip\Parameters\Interfaces\{4E5C72C1-474A-4E59-A5C2-66EE7E3B8FDE}]
NameServer REG_SZ 85.255.112.182,85.255.112.119
DhcpNameServer REG_SZ 85.255.112.182,85.255.112.119
~~~~ Recherche de Rootkits ~~~~
_______________________________________________________________________
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-11 10:45:50
Windows 6.0.6000 NTFS
scanning hidden files ...
disk error: C:\Windows\system32\
please note that you need administrator rights to perform deep scan
_______________________________________________________________________
~~~~ Recherche d'infections dans C:\Users\julien\AppData\Local\Temp\ ~~~~
~~~~ Recherche d'infections dans C:\Users\julien\Start Menu\Programs\ ~~~~
~~~~ Nettoyage du registre ~~~~
~~~~ Tentative de réparation des entrées suivantes: ~~~~
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] = "System"
[HKLM\SYSTEM\CurrentControlSet\Services\Windows Tribute Service]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Windows Tribute Service]
~~~~ Vérification: ~~~~
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System REG_SZ
_________________________________
développé par http://pc-system.fr
_________________________________
Par contre je ne peux pas te donner le nouveau rapport GenProc car lorsqu'il teste les differentes infection apres une minute environ il stop et n'affiche aucun rapport.