Rapport de ZHPFix v1.12.3129 par Nicolas Coolman, Update du 27/07/2010
Fichier d'export Registre : C:\ZHPExportRegistry-30-07-2010-21-27-42.txt
Run by Emmanuelle at 30/07/2010 21:27:42
Web site :
http://www.premiumorange.com/zeb-help-process/zhpfix.html
Contact : nicolascoolman@yahoo.fr
========== Processus mémoire ==========
C:\Users\EMMANU~1\LOCALS~1\APPLIC~1\MICROS~1\clipsrv.exe [92672] => Fichier supprimé au reboot
========== Clé(s) du Registre ==========
O69 - SBI: SearchScopes {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}- (Ask Search) -
http://supertoolbar.ask.com => Clé supprimée avec succès
========== Valeur(s) du Registre ==========
O3 - Toolbar: (no name) - {1E796980-9CC5-11D1-A83F-00C04FC99D61} . (.Pas de propriétaire - Pas de description.) -- (.not file.) => Valeur absente
O4 - HKCU\..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (.not file.) => Valeur absente
O4 - HKUS\S-1-5-21-2461817562-3934211950-2688569834-1000\..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (.not file.) => Valeur absente
========== Elément(s) de donnée du Registre ==========
F3 - REG:win.ini: load=C:\Users\EMMANU~1\LOCALS~1\APPLIC~1\MICROS~1\clipsrv.exe => Donnée supprimée avec succès
========== Dossier(s) ==========
C:\Program Files\DaemonTools_WhenUSave_Installer => Supprimé et mis en quarantaine
========== Fichier(s) ==========
========== Logiciel(s) ==========
O42 - Logiciel: SweetIM Toolbar for Internet Explorer 3.1 - (.SweetIM Technologies Ltd..) [HKLM] => Logiciel supprimé avec succès
O42 - Logiciel: PopUp Destroy - (.Pas de propriétaire.) [HKLM] => Logiciel absent
========== Master Boot Record ==========
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x8443E1D8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x8443e1d8
IoDeviceObjectType -> DumpProcedure -> 0x50000000
DeleteProcedure -> 0x8244c8b
ParseProcedure -> 0x89044889
SecurityProcedure -> 0x8508d30
QueryNameProcedure -> 0x4c8d1376
\Device\Harddisk0\DR0 -> DumpProcedure -> 0x50000000
DeleteProcedure -> 0x8244c8b
ParseProcedure -> 0x89044889
SecurityProcedure -> 0x8508d30
QueryNameProcedure -> 0x4c8d1376
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
Resultat après le fix :
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x8443e1d8
IoDeviceObjectType -> DumpProcedure -> 0x50000000
DeleteProcedure -> 0x8244c8b
ParseProcedure -> 0x89044889
SecurityProcedure -> 0x8508d30
QueryNameProcedure -> 0x4c8d1376
\Device\Harddisk0\DR0 -> DumpProcedure -> 0x50000000
DeleteProcedure -> 0x8244c8b
ParseProcedure -> 0x89044889
SecurityProcedure -> 0x8508d30
QueryNameProcedure -> 0x4c8d1376
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x8443E1D8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x8443e1d8
IoDeviceObjectType -> DumpProcedure -> 0x50000000
DeleteProcedure -> 0x8244c8b
ParseProcedure -> 0x89044889
SecurityProcedure -> 0x8508d30
QueryNameProcedure -> 0x4c8d1376
\Device\Harddisk0\DR0 -> DumpProcedure -> 0x50000000
DeleteProcedure -> 0x8244c8b
ParseProcedure -> 0x89044889
SecurityProcedure -> 0x8508d30
QueryNameProcedure -> 0x4c8d1376
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
Resultat après le fix :
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x8443e1d8
IoDeviceObjectType -> DumpProcedure -> 0x50000000
DeleteProcedure -> 0x8244c8b
ParseProcedure -> 0x89044889
SecurityProcedure -> 0x8508d30
QueryNameProcedure -> 0x4c8d1376
\Device\Harddisk0\DR0 -> DumpProcedure -> 0x50000000
DeleteProcedure -> 0x8244c8b
ParseProcedure -> 0x89044889
SecurityProcedure -> 0x8508d30
QueryNameProcedure -> 0x4c8d1376
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
========== Récapitulatif ==========
1 : Processus mémoire
1 : Clé(s) du Registre
3 : Valeur(s) du Registre
1 : Elément(s) de donnée du Registre
1 : Dossier(s)
2 : Logiciel(s)
1 :Master Boot Record
End of the scan