donc voila d'abord la copie du rapport List-Kill_em par contre je n'arrive pas à sauvegarder le fichier de scan de ZHPDiag : quand je clique sur la disquette rien ne se passe.... Que faire ? Merci de et pour ton aide !
¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.3.6 ¤¤¤¤¤¤¤¤¤¤
User : watashi (Administrateurs)
Update on 23/02/2011 by g3n-h@ckm@n ::::: 02.20
Start at: 03:22:13 | 01/03/2011
Intel(R) Core(TM)2 Duo CPU T7100 @ 1.80GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.19019
WebSite : Soon
Thx to MPuissanceIV for the icon
Windows Firewall Status : Disabled
AV : avast! antivirus 4.8.1335 [VPS 090321-0] 4.8.1335 [ Enabled | Updated ]
C:\ -> Disque fixe local | 51,29 Go (8,03 Go free) [Système] | NTFS
D:\ -> Disque fixe local | 52,01 Go (1,07 Go free) [Donnees] | NTFS
E:\ -> Disque fixe local | 2 Go (1,92 Go free) [Temporaire] | NTFS
F:\ -> Disque fixe local | 6,49 Go (2,37 Go free) [Reinitialisation] | NTFS
G:\ -> Disque CD-ROM
H:\ -> Disque CD-ROM
Boot: Safeboot
Killed : PID 1568 'explorer.exe'
¤¤¤¤¤¤¤¤¤¤ Fichiers | Dossiers
Mis en quarantaine : C:\ProgramData\eDlJgCg05606\eDlJgCg05606.exe
Mis en quarantaine : D:\Users\watashi\AppData\Local\d3d9caps.dat
Mis en quarantaine : D:\Users\watashi\AppData\Local\GDIPFONTCACHEV1.DAT
Mis en quarantaine : C:\Program Files\Tencent
Mis en quarantaine : C:\Windows\System32\x64
¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤
C:\Windows\System32\Drivers\etc\hosts
127.0.0.1 localhost
¤¤¤¤¤¤¤¤¤¤ Registre ¤¤¤¤¤¤¤¤¤¤
Suppression : HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce : eDlJgCg05606
Suppression : HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions : support@predictad.com
¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
Local Page = C:\WINDOWS\system32\blank.htm
Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page =
http://www.google.com/
Local Page = C:\WINDOWS\system32\blank.htm
Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
¤¤¤¤¤¤¤¤¤¤ Centre de securite ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
cval = 1 (0x1)
FirstRunDisabled = 1 (0x1)
AntiVirusDisableNotify = 0 (0x0)
FirewallDisableNotify = 0 (0x0)
UpdatesDisableNotify = 0 (0x0)
AntiVirusOverride = 0 (0x0)
FirewallOverride = 0 (0x0)
¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤
Ndisuio -> Start = 3
EapHost -> Start = 2
Wlansvc -> Start = 2
SharedAccess -> Start = 2
windefend -> Start = 2
wuauserv -> Start = 2
wscsvc -> Start = 2
¤¤¤¤¤¤¤¤¤¤ Winlogon
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell = 1 (0x1)
Shell = explorer.exe
Userinit = C:\Windows\System32\userinit.exe,
VMapplet = rundll32 shell32,Control_RunDLL sysdm.cpl
System =
PowerdownAfterShutdown = 1
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Disk Cleaned
Prefetch cleaned
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
TDSS | svchost | Internet Explorer:
====================================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 6.0.6002 Disk: WDC_WD1200BEVS-60RST0 rev.04.01G04 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x84F031F8]<<
1 ntkrnlpa!IofCallDriver[0x82880912] -> \Device\Harddisk0\DR0[0x8515F030]
3 CLASSPNP[0x871A98B3] -> ntkrnlpa!IofCallDriver[0x82880912] -> \Device\Ide\IdeDeviceP2T0L0-4[0x84FFB8A0]
\Driver\atapi[0x84F86428] -> IRP_MJ_CREATE -> 0x84F031F8
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi -> 0x84f031f8
user & kernel MBR OK
Warning: possible MBR rootkit infection !
Fin du Nettoyage : 3:24:02
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤