|
|
|
|
Bonjour,
J'ai avst qui m'a détecté des fichiers suspiieux type Rootkit.
Le problème c'est que j'y connaîs pas grand chose.
Par conséquent, j'ai installé un Logiciel "ROOTKIT Detective 1.1".
Si quelqu'un pouvez m'aider, ce serait très sympa. Voilà le rapport et merci :
McAfee(R) Rootkit Detective 1.1 scan report
On 29-11-2008 at 15:21:21
OS-Version 5.1.2600
Service Pack 3.0
====================================
Object-Type: SSDT-hook
Object-Name: ZwClose
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: SSDT-hook
Object-Name: ZwCreateKey
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: SSDT-hook
Object-Name: ZwDeleteValueKey
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: SSDT-hook
Object-Name: ZwDuplicateObject
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: SSDT-hook
Object-Name: ZwOpenKey
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: SSDT-hook
Object-Name: ZwOpenProcess
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: SSDT-hook
Object-Name: ZwOpenThread
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: SSDT-hook
Object-Name: ZwQueryValueKey
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: SSDT-hook
Object-Name: ZwRestoreKey
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: SSDT-hook
Object-Name: ZwSetValueKey
Object-Path: C:\WINDOWS\system32\drivers\aswSP.sys
Object-Type: Registry-key
Object-Name: DataINDOWS\system32\drivers\aswSP.sys
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data
Status: Hidden
Object-Type: Registry-key
Object-Name: a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771 System Provider\*Local Machine*\Data
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771
Status: Hidden
Object-Type: Registry-key
Object-Name: 00000000-0000-0000-0000-000000000000 System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}ystem Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000\{6340E680-FF06-435f-8767-B79D88AEBD4D}
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}.RENm Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000\{6340E680-FF06-435f-8767-B79D88AEBD4D}
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN
Status: Hidden
Object-Type: Registry-value
Object-Name: Item Data
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: 00000000-0000-0000-0000-000000000000.RENtem Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000.REN
Status: Hidden
Object-Type: Registry-value
Object-Name: Display String
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.RENtem Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771\00000000-0000-0000-0000-000000000000.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN
Status: Hidden
Object-Type: Registry-value
Object-Name: Display String
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: Data 2RE\Microsoft\Protected Storage System Provider\*Local Machine*\Data\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2
Status: Hidden
Object-Type: Registry-key
Object-Name: WindowsE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2\Windows
Status: Hidden
Object-Type: Registry-key
Object-Name: Windows.RENcrosoft\Protected Storage System Provider\*Local Machine*\Data 2\Windows
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2\Windows.REN
Status: Hidden
Object-Type: Registry-value
Object-Name: Value
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2\Windows.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: Data 2.RENicrosoft\Protected Storage System Provider\*Local Machine*\Data 2\Windows.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: Data.REN\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN
Status: Hidden
Object-Type: Process
Object-Name: PCMSERVICE.EXE
Pid: 2820
Object-Path: C:\Program Files\Arcade\PCMService.exe
Status: Visible
Object-Type: Process
Object-Name: SVCHOST.EXE
Pid: 836
Object-Path: C:\WINDOWS\System32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: System Idle Process
Pid: 0
Object-Path:
Status: Visible
Object-Type: Process
Object-Name: cidaemon.exe
Pid: 2232
Object-Path: C:\WINDOWS\system32\cidaemon.exe
Status: Visible
Object-Type: Process
Object-Name: CSRSS.EXE
Pid: 496
Object-Path: C:\WINDOWS\system32\csrss.exe
Status: Visible
Object-Type: Process
Object-Name: POWERKEY.EXE
Pid: 2884
Object-Path: C:\Program Files\Launch Manager\PowerKey.exe
Status: Visible
Object-Type: Process
Object-Name: ashDisp.exe
Pid: 3256
Object-Path: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
Status: Visible
Object-Type: Process
Object-Name: SVCHOST.EXE
Pid: 2948
Object-Path: C:\WINDOWS\System32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: EXPLORER.EXE
Pid: 1212
Object-Path: C:\WINDOWS\Explorer.EXE
Status: Visible
Object-Type: Process
Object-Name: ASHSERV.EXE
Pid: 1336
Object-Path: C:\Program Files\Alwil Software\Avast4\ashServ.exe
Status: Visible
Object-Type: Process
Object-Name: SYNTPLPR.EXE
Pid: 2576
Object-Path: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
Status: Visible
Object-Type: Process
Object-Name: OSDCtrl.exe
Pid: 2980
Object-Path: C:\Program Files\Launch Manager\OSDCtrl.exe
Status: Visible
Object-Type: Process
Object-Name: qttask.exe
Pid: 3228
Object-Path: C:\Program Files\QuickTime\qttask.exe
Status: Visible
Object-Type: Process
Object-Name: SVCHOST.EXE
Pid: 128
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: System
Pid: 4
Object-Path:
Status: Visible
Object-Type: Process
Object-Name: MAXIMEMO.EXE
Pid: 3416
Object-Path: C:\Program Files\MaxiMemo\MaxiMemo.exe
Status: Visible
Object-Type: Process
Object-Name: SMSS.EXE
Pid: 440
Object-Path: C:\WINDOWS\System32\smss.exe
Status: Visible
Object-Type: Process
Object-Name: SERVICES.EXE
Pid: 564
Object-Path: C:\WINDOWS\system32\services.exe
Status: Visible
Object-Type: Process
Object-Name: HKCMD.EXE
Pid: 2548
Object-Path: C:\WINDOWS\system32\hkcmd.exe
Status: Visible
Object-Type: Process
Object-Name: LAUNCHAP.EXE
Pid: 2860
Object-Path: C:\Program Files\Launch Manager\LaunchAp.exe
Status: Visible
Object-Type: Process
Object-Name: ANBMSERV.EXE
Pid: 1744
Object-Path: C:\Acer\eManager\anbmServ.exe
Status: Visible
Object-Type: Process
Object-Name: SVCHOST.EXE
Pid: 1032
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: SYNTPENH.EXE
Pid: 2584
Object-Path: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Status: Visible
Object-Type: Process
Object-Name: Monitor.exe
Pid: 3080
Object-Path: C:\Program Files\Acer\eRecovery\Monitor.exe
Status: Visible
Object-Type: Process
Object-Name: SVCHOST.EXE
Pid: 724
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: WMIPRVSE.EXE
Pid: 2988
Object-Path: C:\WINDOWS\system32\wbem\wmiprvse.exe
Status: Visible
Object-Type: Process
Object-Name: iexplore.exe
Pid: 2524
Object-Path: C:\Program Files\Internet Explorer\iexplore.exe
Status: Visible
Object-Type: Process
Object-Name: WLLoginProxy.ex
Pid: 1284
Object-Path: C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
Status: Visible
Object-Type: Process
Object-Name: SVCHOST.EXE
Pid: 912
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: brctrcen.exe
Pid: 3208
Object-Path: C:\Program Files\Brother\ControlCenter2\brctrcen.exe
Status: Visible
Object-Type: Process
Object-Name: ASWUPDSV.EXE
Pid: 1288
Object-Path: C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
Status: Visible
Object-Type: Process
Object-Name: BRMFRMPS.EXE
Pid: 1908
Object-Path: C:\WINDOWS\system32\Brmfrmps.exe
Status: Visible
Object-Type: Process
Object-Name: CTFMON.EXE
Pid: 1164
Object-Path: C:\WINDOWS\system32\ctfmon.exe
Status: Visible
Object-Type: Process
Object-Name: MsnMsgr.Exe
Pid: 3304
Object-Path: C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
Status: Visible
Object-Type: Process
Object-Name: LSASS.EXE
Pid: 576
Object-Path: C:\WINDOWS\system32\lsass.exe
Status: Visible
Object-Type: Process
Object-Name: BRSVC01A.EXE
Pid: 1568
Object-Path: C:\WINDOWS\system32\brsvc01a.exe
Status: Visible
Object-Type: Process
Object-Name: CISVC.EXE
Pid: 1940
Object-Path: C:\WINDOWS\system32\cisvc.exe
Status: Visible
Object-Type: Process
Object-Name: SOUNDMAN.EXE
Pid: 2560
Object-Path: C:\WINDOWS\SOUNDMAN.EXE
Status: Visible
Object-Type: Process
Object-Name: BRSS01A.EXE
Pid: 1600
Object-Path: C:\WINDOWS\system32\brss01a.exe
Status: Visible
Object-Type: Process
Object-Name: Wbutton.exe
Pid: 2996
Object-Path: C:\Program Files\Launch Manager\Wbutton.exe
Status: Visible
Object-Type: Process
Object-Name: jusched.exe
Pid: 3244
Object-Path: C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
Status: Visible
Object-Type: Process
Object-Name: SVCHOST.EXE
Pid: 796
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: IGFXTRAY.EXE
Pid: 2532
Object-Path: C:\WINDOWS\system32\igfxtray.exe
Status: Visible
Object-Type: Process
Object-Name: ASHWEBSV.EXE
Pid: 208
Object-Path: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
Status: Visible
Object-Type: Process
Object-Name: EPM-DM.EXE
Pid: 2596
Object-Path: C:\acer\epm\epm-dm.exe
Status: Visible
Object-Type: Process
Object-Name: WINLOGON.EXE
Pid: 520
Object-Path: C:\WINDOWS\system32\winlogon.exe
Status: Visible
Object-Type: Process
Object-Name: ASHMAISV.EXE
Pid: 1884
Object-Path: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
Status: Visible
Object-Type: Process
Object-Name: HOTKEYAPP.EXE
Pid: 2908
Object-Path: C:\Program Files\Launch Manager\HotkeyApp.exe
Status: Visible
Object-Type: Process
Object-Name: pptd40nt.exe
Pid: 3156
Object-Path: C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
Status: Visible
Object-Type: Process
Object-Name: Rootkit_Detecti
Pid: 4088
Object-Path: C:\Documents and Settings\cecilia\Bureau\McafeeRootkitDetective\Rootkit_Detective.exe
Status: Visible
Object-Type: Process
Object-Name: SPOOLSV.EXE
Pid: 1608
Object-Path: C:\WINDOWS\system32\spoolsv.exe
Status: Visible
Object-Type: Process
Object-Name: ALG.EXE
Pid: 1236
Object-Path: C:\WINDOWS\System32\alg.exe
Status: Visible
Scan complete. Hidden registry keys/values: 16
Merci.
Configuration: Windows XP Internet Explorer 7.0
>>>>>>>Fais une analyse antivirus complete avec bitdfender online(avec internet explorer) puis pose le rapport.
|
Après ça!
|
Bonjour,
|