Security-X
Forum Security-X => News => Discussion démarrée par: hyunkel30 le mai 24, 2010, 22:37:11
-
:AAC Bonsoir,
Impressionnant ...
http://forum.malekal.com/vilsel-aejm-trojan-clicker-win32-cycler-whistler-boot-t25956.html
http://blog.novirusthanks.org/2010/02/whistler-bootkit-a-new-powerful-windows-bootkit/
Malware 1 - 0 Antirootkit/Antivirus ...
-
Question ;
Comme il est protégé par un rootkit dans le MBR, si on répare le MBR il ne reviendra plus. Il suffirait ensuite de le supprimer par un outil non ?
-
Re,
Ben apparemment, oui, c'est le truc :
L'outil utilisé : bootkit_remover fais un peu comme un fixmbr je pense :
http://forum.malekal.com/your-protection-t25834.html#p212416
Ensuite, tu as le champ libre pour ce qui sont lancé dans les point de resto ou autre .
Moi je suis surtout impressionné par le fait que même sous Vista et 7 ce truc réussisse à s'insérer et prendre un ring0 ...
-
Salut Hyunkel,
çà ne m'étonne qu'a moitié : mon PC XP "NET" :
:(
-
Bonsoir Multi ;)
Attention, je ne connais pas exactement l'outil, mais je suppose qu'il peux détecter d'autre modif du boot/mbr sans que ce soit réellement un bootkit, je sais pas, genre multiboot/dualboot par exemple ...
Bref ne lance pas la réparation sans être sur de toi ...
:AAN
-
Salut,
merci pour ta remarque, ZHP me dit çà :
Zeb Help Process 2 by Nicolas Coolman - Rapport de synthèse du 24/05/2010 23:52:09
INFORMATION
PROCESSUS SUPERFLU DU SYSTEME
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
PROCESSUS INUTILE (Au démarrage du système)
O4 - Global Startup: Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
PROTECTION DU SYSTEME (Antivirus, FireWall, Anti-Malwares)
Alwil Avast! Antivirus
Trend Micro TrendProtect
ALWIL Software avast! Antivirus
Avira AntiVir PersonalEdition
RAPPORT SIMPLIFIE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\policies\Explorer: [HonorAutoRunSetting] Data=0
O4 - Global Startup: Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O43 - CFD:Common File Directory ----D- C:\Program Files\Commander
O44 - LFC:Last File Created 23/05/2010 - 0:01:22 ---A- C:\WINDOWS\setupapi.log
O44 - LFC:Last File Created 24/05/2010 - 20:50:30 ---A- C:\WINDOWS\WindowsUpdate.log
O44 - LFC:Last File Created 24/05/2010 - 21:09:52 ---A- C:\WINDOWS\wiaservc.log
O44 - LFC:Last File Created 24/05/2010 - 23:28:20 ---A- C:\WINDOWS\wiadebug.log
O44 - LFC:Last File Created 29/04/2010 - 2:29:26 ---A- C:\WINDOWS\System32\jupdate-1.6.0_20-b02.log
O56 - MWPE:[HKCU\...\Policies\Explorer] - "HonorAutoRunSetting"=0
O56 - MWPE:[HKLM\...\Policies\Explorer] - "HonorAutoRunSetting"=0
O58 - SDL:System Drivers List - C:\WINDOWS\system32\drivers\DLKRCB.SYS
O58 - SDL:System Drivers List - C:\WINDOWS\system32\drivers\EnumProcessesDriver.sys
O64 - Services: CurCS - COMODO Internet Security Eradication Driver (cmderd) - LEGACY_CMDERD
O64 - Services: CurCS - EnumProcessesDriver (EnumProcessesDriver) - LEGACY_ENUMPROCESSESDRIVER
O64 - Services: CurCS - kfaiqpoc (kfaiqpoc) - LEGACY_KFAIQPOC
O64 - Services: CurCS - klmd21 (klmd21) - LEGACY_KLMD21
O64 - Services: CurCS - rk_remover-boot (rk_remover-boot) - LEGACY_RK_REMOVER-BOOT
O64 - Services: CS003 - COMODO Internet Security Eradication Driver (cmderd) - LEGACY_CMDERD
O64 - Services: CS003 - EnumProcessesDriver (EnumProcessesDriver) - LEGACY_ENUMPROCESSESDRIVER
O64 - Services: CS003 - kfaiqpoc (kfaiqpoc) - LEGACY_KFAIQPOC
O64 - Services: CS003 - klmd21 (klmd21) - LEGACY_KLMD21
O64 - Services: CS003 - rk_remover-boot (rk_remover-boot) - LEGACY_RK_REMOVER-BOOT
& GMER me dit ceci à première vue :
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-05-25 00:20:07
Windows 5.1.2600 Service Pack 3
Running: v7pzvjh0gmer.exe; Driver: C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\kfaiqpoc.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB2D67AC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB2D678EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB2D67A24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
puis ca en scan complet :
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-25 01:06:16
Windows 5.1.2600 Service Pack 3
Running: v7pzvjh0gmer.exe; Driver: C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\kfaiqpoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB2D5AC7A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB2D5AB36]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xB2D5B0EA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB2D5B014]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB2D5A70C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB2D5AC10]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB2D5A64C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB2D5A6B0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB2D5AD30]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xB2D5B1B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB2D5ACF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB2D5AE70]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB2D67AC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB2D678EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB2D67A24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2468 80501CA0 4 Bytes JMP DAB2D5B0
PAGE ntkrnlpa.exe!ZwLoadDriver 805795FA 7 Bytes JMP B2D67A28 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 805A075C 7 Bytes JMP B2D678EE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805B1CE0 5 Bytes JMP B2D63536 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805B8B58 5 Bytes JMP B2D64EC2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805C73EA 7 Bytes JMP B2D67ACA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xF7077510]
init C:\WINDOWS\system32\drivers\o2mmb.sys entry point in "init" section [0xF6FCD320]
? C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\mbr.sys Le fichier spécifié est introuvable. !
---- User code sections - GMER 1.0.15 ----
.text C:\Documents and Settings\Internet\Application Data\FF\firefox.exe[3528] ntdll.dll!LdrLoadDll 7C9263C3 5 Bytes JMP 004013F0 C:\Documents and Settings\Internet\Application Data\FF\firefox.exe (Firefox/Mozilla Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[552] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[552] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
je viens d'essayer Comodo et je teste Avast Free pour le moment,
et pour le fixi.bat ... voici la capture d'écran en dessous ...
D'avance merci pour vos conseils, bonne nuit/journée @+
-
Bonjour
assures toi que l'outil en question remover soit bien sur ton bureau aussi sinon navigue jusqu'au dossier.
CD NOM DU DOSSIER
CD..
-
Ou sinon tu le mets dans ton PATH
-
Salut,
Merci pour vos conseils, je vais réessayé dès que j'ai grignotté un ptit bout ;D^^
Il était sur le Bureau mais je suis en User et je ne peux l' "exécuter en en tant que..."
Donc je vais quitter la session et refaire le test en MSE admin ...
Si c'est le cas, mes deux autres bécane doivent être dans le même jus ...
@ tout ou @+
-
comme tout .bat qui appelle "start" l'application , faut que ça soit dans le meme repertoire c'est tout \o_
-
Salut,
bon j'avais déjà classé remover.exe dans un dossier, +1 pour Laddy & Angélique
Il a bien viré le truc ? ou c'est une fausse alerte ?
Pour le script Avenger, je sèche :D^^ moi jeune MultiPadawan ;) ...
J'en ai profité pour faire un scan RootkitReveal :
HKU\S-1-5-21-1844237615-436374069-1801674531-1003\Console 25/03/2010 1:30 0 bytes Security mismatch.
HKLM\SECURITY\Policy\Secrets\SAC* 25/01/2010 1:07 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 25/01/2010 1:07 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Swearware\backup\winsock2 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017 25/03/2010 1:23 0 bytes Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018 25/03/2010 1:23 0 bytes Security mismatch.
C:\Documents and Settings\Propriétaire\Bureau\RootKitReveler.JPG 25/05/2010 20:19 226.88 KB Hidden from Windows API.
C:\Documents and Settings\Propriétaire\Recent\RootKitReveler.JPG.lnk 25/05/2010 20:19 535 bytes Hidden from Windows API.
Un ptit script Combo*** ?! ... OTM ... les deux rapports RSIT sont dans un .zip en pièce jointe ...
D'avance merci pour votre aide ... je suis pret pour mon exécution en direct ^^ ;) ...
c'est mon PC poubelle/internet ... mais je n'utilise pas de crack ou de log pourris ...
@+
-
Salut . . .
Chouette un autre EXO surprise :D^^ . . . (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fwww.multifa7.be%2FWubuntu%2Fforum%2Fimages%2Fsmilies%2Fpendu.gif&hash=6d90365f876c3e81f138c3394f1c9580c8712201)
J'ai un p'tit problème . . . & un peu de mal à répondre à la question posée à chaque démarrage, MSE impossible . . . : ( cf. pièce jointe ) . . .
Je me dis que toutunchacun choisirait "N" ... donc pourquoi pas "Y" ...
Ce bon vieux EliveCD, qu'est ce que je ferais sans lui ...
00000000: 33 C0 8E D0 BC 00 7C FB-50 07 50 1F FC BE 1B 7C 3Àм.|ûP.P.ü¾.|
00000010: BF 1B 06 50 57 B9 E5 01-F3 A4 CB BD BE 07 B1 04 ¿..PW¹å.ó¤Ë½¾.±.
00000020: 38 6E 00 7C 09 75 13 83-C5 10 E2 F4 CD 18 8B F5 8n.|.u.Å.âôÍ.õ
00000030: 83 C6 10 49 74 19 38 2C-74 F6 A0 B5 07 B4 07 8B Æ.It.8,tö µ.´.
00000040: F0 AC 3C 00 74 FC BB 07-00 B4 0E CD 10 EB F2 88 ð¬<.tü»..´.Í.ëò
00000050: 4E 10 E8 46 00 73 2A FE-46 10 80 7E 04 0B 74 0B N.èF.s*þF.~..t.
00000060: 80 7E 04 0C 74 05 A0 B6-07 75 D2 80 46 02 06 83 ~..t. ¶.uÒF..
00000070: 46 08 06 83 56 0A 00 E8-21 00 73 05 A0 B6 07 EB F..V..è!.s. ¶.ë
00000080: BC 81 3E FE 7D 55 AA 74-0B 80 7E 10 00 74 C8 A0 ¼>þ}Uªt.~..tÈ
00000090: B7 07 EB A9 8B FC 1E 57-8B F5 CB BF 05 00 8A 56 ·.ë©ü.WõË¿..V
000000A0: 00 B4 08 CD 13 72 23 8A-C1 24 3F 98 8A DE 8A FC .´.Í.r#Á$?Þü
000000B0: 43 F7 E3 8B D1 86 D6 B1-06 D2 EE 42 F7 E2 39 56 C÷ãÑÖ±.ÒîB÷â9V
000000C0: 0A 77 23 72 05 39 46 08-73 1C B8 01 02 BB 00 7C .w#r.9F.s.¸..».|
000000D0: 8B 4E 02 8B 56 00 CD 13-73 51 4F 74 4E 32 E4 8A N.V.Í.sQOtN2ä
000000E0: 56 00 CD 13 EB E4 8A 56-00 60 BB AA 55 B4 41 CD V.Í.ëäV.`»ªU´AÍ
000000F0: 13 72 36 81 FB 55 AA 75-30 F6 C1 01 74 2B 61 60 .r6ûUªu0öÁ.t+a`
00000100: 6A 00 6A 00 FF 76 0A FF-76 08 6A 00 68 00 7C 6A j.j.ÿv.ÿv.j.h.|j
00000110: 01 6A 10 B4 42 8B F4 CD-13 61 61 73 0E 4F 74 0B .j.´BôÍ.aas.Ot.
00000120: 32 E4 8A 56 00 CD 13 EB-D6 61 F9 C3 49 6E 76 61 2äV.Í.ëÖaùÃInva
00000130: 6C 69 64 20 70 61 72 74-69 74 69 6F 6E 20 74 61 lid partition ta
00000140: 62 6C 65 00 45 72 72 6F-72 20 6C 6F 61 64 69 6E ble.Error loadin
00000150: 67 20 6F 70 65 72 61 74-69 6E 67 20 73 79 73 74 g operating syst
00000160: 65 6D 00 4D 69 73 73 69-6E 67 20 6F 70 65 72 61 em.Missing opera
00000170: 74 69 6E 67 20 73 79 73-74 65 6D 00 00 00 00 00 ting system.....
00000180: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000190: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000001A0: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000001B0: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 80 01 ...............
000001C0: 01 00 07 FE FF FF 3F 00-00 00 00 14 A8 04 00 00 ...þÿÿ?.....¨...
000001D0: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000001E0: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000001F0: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 55 AA ..............Uª
ComboFix 10-05-25.02 - Propriétaire 26/05/2010 5:52.2.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.32.1036.18.1023.739 [GMT 1:00]
Lancé depuis: c:\documents and settings\Propriétaire\Bureau\CoLAl.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-04-26 au 2010-05-26 ))))))))))))))))))))))))))))))))))))
2010-05-25 19:25 . 2010-05-25 19:25 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-05-25 19:10 . 2010-05-25 19:10 -------- d-----w- c:\program files\burnatonce
2010-05-25 04:32 . 2010-05-25 04:32 -------- d-----w- c:\program files\Blender Foundation
2010-05-12 05:02 . 2010-05-06 20:33 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-12 05:02 . 2010-05-06 20:39 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-12 05:02 . 2010-05-06 20:34 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-12 05:02 . 2010-05-06 20:39 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-12 05:02 . 2010-05-06 20:33 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-12 05:02 . 2010-05-06 20:33 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-12 05:02 . 2010-05-06 20:33 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-12 05:02 . 2010-05-06 20:59 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-12 05:02 . 2010-04-14 16:47 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-12 05:02 . 2010-05-12 05:02 -------- d-----w- c:\program files\Alwil Software
2010-05-12 05:02 . 2010-05-12 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-06 05:43 . 2010-05-06 05:43 -------- d-----w- c:\program files\Fichiers communs\Borland Shared
2010-05-06 05:43 . 1999-01-20 04:01 210032 ----a-w- c:\windows\system32\DBCLIENT.DLL
2010-05-06 05:42 . 2010-05-24 22:46 -------- d-----w- c:\program files\ZebHelpProcess
2010-05-05 01:24 . 2010-05-05 02:00 -------- d-----w- c:\windows\system32\hdined32.nls.{00021401-0000-0000-C000-000000000046}
2010-05-03 05:57 . 2010-05-03 05:57 -------- d-----w- c:\documents and settings\Internet\Application Data\InterVideo
2010-04-29 01:29 . 2010-04-12 16:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
2010-05-22 23:57 . 2010-04-10 03:53 -------- d-----w- c:\documents and settings\Internet\Application Data\vlc
2010-05-19 16:49 . 2010-03-01 10:37 22080 ----a-w- c:\documents and settings\Internet\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-12 04:51 . 2010-04-11 18:32 -------- d-----w- c:\program files\COMODO
2010-05-12 04:49 . 2010-01-25 01:38 -------- d-----w- c:\program files\CCleaner
2010-05-03 05:16 . 2010-03-04 06:34 1 ----a-w- c:\documents and settings\Internet\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-04-29 01:29 . 2010-04-10 00:24 -------- d-----w- c:\program files\Java
2010-04-22 03:45 . 2010-04-19 17:23 -------- d-----w- c:\program files\Trend Micro
2010-03-29 23:46 . 2010-01-25 01:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 23:45 . 2010-01-25 01:29 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-25 00:15 . 2010-03-25 00:15 50176 ----a-w- c:\windows\system32\drivers\rk_remover.sys
2010-03-14 14:25 . 2010-03-14 14:25 503808 ----a-w- c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-11f6eb45-n\msvcp71.dll
2010-03-14 14:25 . 2010-03-14 14:25 499712 ----a-w- c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-11f6eb45-n\jmc.dll
2010-03-14 14:25 . 2010-03-14 14:25 348160 ----a-w- c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-11f6eb45-n\msvcr71.dll
2010-03-14 14:25 . 2010-03-14 14:25 61440 ----a-w- c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-552e1546-n\decora-sse.dll
2010-03-14 14:25 . 2010-03-14 14:25 12800 ----a-w- c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-552e1546-n\decora-d3d.dll
2010-03-10 06:16 . 2009-02-01 07:21 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-26 19:30 . 2010-02-26 19:30 20898 ----a-w- c:\windows\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
2010-02-25 06:17 . 2009-02-01 07:21 916480 ----a-w- c:\windows\system32\wininet.dll
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Propriétaire\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-04-19 135664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-01-09 65536]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-02-18 248040]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
c:\documents and settings\All Users\Menu Dmarrer\Programmes\Dmarrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2010-2-3 110592]
Assistant d'Acrobat.lnk - c:\program files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
2001-09-04 15:24 28672 ----a-w- c:\windows\system32\Ati2mdxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-03-03 11:00 335872 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
2002-07-12 17:15 106496 ----a-w- c:\windows\SiSUSBrg.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
R0 EnumProcessesDriver;EnumProcessesDriver;c:\windows\system32\drivers\EnumProcessesDriver.sys [19/04/2010 18:39 15888]
R0 rk_remover-boot;rk_remover-boot;c:\windows\system32\drivers\rk_remover.sys [25/03/2010 1:15 50176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [12/05/2010 6:02 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/05/2010 6:02 19024]
R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [25/01/2010 1:35 190465]
R3 DLKRCB;D-Link DFE-690TXD CardBus PC Card;c:\windows\system32\drivers\DLKRCB.SYS [5/02/2010 0:20 25434]
R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [25/01/2010 1:35 5817]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - RKREVEAL150
Contenu du dossier 'Tâches planifiées'
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-26 05:55
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]
@Denied: (Full) (Administrators)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(564)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2010-05-26 05:57:02
ComboFix-quarantined-files.txt 2010-05-26 04:56
Avant-CF: 9.974.153.216 octets libres
Après-CF: 9.965.522.944 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
- - End Of File - - C053A2043831918744BD29AD17C3AC09
D'avance merci pour votre aide . . . & bonne journée . . _ . . ' ' ' _ . . ¹~²¬- ° (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fwww.multifa7.be%2FWubuntu%2Fforum%2Fimages%2Fsmilies%2Fhelp_New1.gif&hash=4b906e209133451f15fb29f246badd32e17fae5f) °
-
Salut,
Merci pour vos conseils, je vais réessayé dès que j'ai grignotté un ptit bout ;D^^
Il était sur le Bureau mais je suis en User et je ne peux l' "exécuter en en tant que..."
Donc je vais quitter la session et refaire le test en MSE admin ...
Si c'est le cas, mes deux autres bécane doivent être dans le même jus ...
@ tout ou @+
Si tu es sous vista/seven pour effectuer la manipulation tu dois executer sans doute ton invite de commande En tant qu'administrateur : cmd
-
Si tu es sous vista/seven pour effectuer la manipulation tu dois executer sans doute ton invite de commande En tant qu'administrateur : cmd
Salut Laddy :)
je suis sur XPhomeSP3 avec Avast5 ... hihihi ... no comment ...
j'ai fais la manipulation qui s'est apparemment bien passée,
puis j'ai utilisé MBR Dump, ATF puis CCleaner pour finir avec
Combofix ... tout çà en admin. => puis reboot . . .
Si je n'appuie pas successivement sur "Del" & "Esc" le BIOS
ne se lance pas comme il devrait et le EliveCD ne se lance pas,
& j'ai ce message de ouf qu'il y a sur la photo juste au dessus.
C'est quoi ce Boot.BAK à la racine du C ? . . . ( 2eme capture )
Voilou ... bonne journée
-
Bonjour
pour les captures je ne vois pas pour le moment
pour le boot.bak c'est une sauvegarde de ton boot.ini qui a été surement modifié par un outil notamment combofix si tu as installé la console de répération comme demandé.
Une idée :
tu as peut etre un antivirus ou un systeme de protection de secteur de boot dans ton bios
regarde pour désactiver l'option.
voir au niveau d'avast aussi
Une autre idée :
Réparer le secteur de boot : fixboot
effectuer une restauration du mbr : fixmbr C:
http://www.zebulon.fr/dossiers/61-7-reparer-mbr.html
http://www.zebulon.fr/dossiers/61-6-reparer-secteur-boot.html
-
Salut Laddy,
merci pour ta réponse, Avast a été désactivé "définitivement" (reprise manuelle)
Un bug à ce niveau là ? ...
Par contre au vue du log Gmer, il n'aurait pas viré un composant du nouveau Avast (FP) ?
Tout les outils dont les rapports sont présent ici ont été passé avant le reboot, j'ai fini
par Combo (la sauvegarde des ruches système s'est passée correctement) . . .
Un autre truc bizard, lors de l'allumage, un deuxième bip plus aigu
se fait entendre puis je peux voir en bas à droite de l'écran d'affichage du BIOS :
une série de 4 caractères qui se modifient en fonction des opérations suivantes :
6B3B => apparition du BIOS ( 1 fraction de seconde )
003B => affichage du BIOS ( listing composants )
0060 => idem ( vérification de la RAM )
0075 => idem ( vérification DD )
0078 => idem ( vérification LecteurDVDRAM )
00A7 => transition ( 1 fraction de seconde )
00A9 => récapitulatif matériel : 9 .. 8 ... 7 .. 6 ... ( Esc )
...C => Boot ( 1 fraction de seconde )
=> ECRAN DE OUF :
" Boot Sector Write !!
VIRUS : Continue ( Y / N ) ? "
Je n'ai pas mis de "sécurité virus" via le BIOS, juste un mod de passe Sup.
mais je n'y ai plus accès donc je ne peux vérifier la configuration ...
Bonne journée
[EDIT]
J'ai fais péter la Pile pendant une petite demi heure ;D ... j'en ai profité pour
le désosser(DD/RAM/CG/DVD/BAT/VENT) et faire un peu de dépoussiérage ...
Le disque mis sur un autre XPproSP3+TrendIS me demandais un mot de passe
pour tous les comptes, donc données inaccessibles. J'ai tout remis comme avant,
démarré l'ordi. => avertissements BOOT CMOS => F2 : SETUP => reconfiguré le
BIOS + MDP SUP. + BOOT ( INTEL EX.. & Removable Distribution(1erePos) virés )
Cà fonctionne, je ne vois rien dans l'Observateur d'événement à par des erreurs
GoogleUpDater ou le Centre de Sécurité Microsoft qui se manifeste ...
J'espère que les outils ont fait leurs taffs ??? ...
-------------------------------
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
-------------------------------
00000000: 33 C0 8E D0 BC 00 7C FB-50 07 50 1F FC BE 1B 7C 3ÀŽÐ¼.|ûP.P.ü¾.|
00000010: BF 1B 06 50 57 B9 E5 01-F3 A4 CB BD BE 07 B1 04 ¿..PW¹å.ó¤Ë½¾.±.
00000020: 38 6E 00 7C 09 75 13 83-C5 10 E2 F4 CD 18 8B F5 8n.|.u.ƒÅ.âôÍ.‹õ
00000030: 83 C6 10 49 74 19 38 2C-74 F6 A0 B5 07 B4 07 8B ƒÆ.It.8,tö µ.´.‹
00000040: F0 AC 3C 00 74 FC BB 07-00 B4 0E CD 10 EB F2 88 ð¬<.tü»..´.Í.ëòˆ
00000050: 4E 10 E8 46 00 73 2A FE-46 10 80 7E 04 0B 74 0B N.èF.s*þF.€~..t.
00000060: 80 7E 04 0C 74 05 A0 B6-07 75 D2 80 46 02 06 83 €~..t. ¶.uÒ€F..ƒ
00000070: 46 08 06 83 56 0A 00 E8-21 00 73 05 A0 B6 07 EB F..ƒV..è!.s. ¶.ë
00000080: BC 81 3E FE 7D 55 AA 74-0B 80 7E 10 00 74 C8 A0 ¼>þ}Uªt.€~..tÈ
00000090: B7 07 EB A9 8B FC 1E 57-8B F5 CB BF 05 00 8A 56 ·.ë©‹ü.W‹õË¿..ŠV
000000A0: 00 B4 08 CD 13 72 23 8A-C1 24 3F 98 8A DE 8A FC .´.Í.r#ŠÁ$?˜ŠÞŠü
000000B0: 43 F7 E3 8B D1 86 D6 B1-06 D2 EE 42 F7 E2 39 56 C÷ã‹Ñ†Ö±.ÒîB÷â9V
000000C0: 0A 77 23 72 05 39 46 08-73 1C B8 01 02 BB 00 7C .w#r.9F.s.¸..».|
000000D0: 8B 4E 02 8B 56 00 CD 13-73 51 4F 74 4E 32 E4 8A ‹N.‹V.Í.sQOtN2äŠ
000000E0: 56 00 CD 13 EB E4 8A 56-00 60 BB AA 55 B4 41 CD V.Í.ëäŠV.`»ªU´AÍ
000000F0: 13 72 36 81 FB 55 AA 75-30 F6 C1 01 74 2B 61 60 .r6ûUªu0öÁ.t+a`
00000100: 6A 00 6A 00 FF 76 0A FF-76 08 6A 00 68 00 7C 6A j.j.ÿv.ÿv.j.h.|j
00000110: 01 6A 10 B4 42 8B F4 CD-13 61 61 73 0E 4F 74 0B .j.´B‹ôÍ.aas.Ot.
00000120: 32 E4 8A 56 00 CD 13 EB-D6 61 F9 C3 49 6E 76 61 2äŠV.Í.ëÖaùÃInva
00000130: 6C 69 64 20 70 61 72 74-69 74 69 6F 6E 20 74 61 lid partition ta
00000140: 62 6C 65 00 45 72 72 6F-72 20 6C 6F 61 64 69 6E ble.Error loadin
00000150: 67 20 6F 70 65 72 61 74-69 6E 67 20 73 79 73 74 g operating syst
00000160: 65 6D 00 4D 69 73 73 69-6E 67 20 6F 70 65 72 61 em.Missing opera
00000170: 74 69 6E 67 20 73 79 73-74 65 6D 00 00 00 00 00 ting system.....
00000180: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000190: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000001A0: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000001B0: 00 00 00 00 00 00 00 00-FD 2F CD 3B 00 00 80 01 ........ý/Í;..€.
000001C0: 01 00 07 FE FF FF 3F 00-00 00 00 14 A8 04 00 00 ...þÿÿ?.....¨...
000001D0: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000001E0: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000001F0: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 55 AA ..............Uª
-------------------------------
Je peux virer ce dossier du registre ?!
HKLM\SOFTWARE\Swearware\ ... d'avance merci ...
@+
-
Salut,
UP :NNN ... un p'tit consils vite fait ...
s'il vous plait ...
@+
-
Yop, ton MBR est bon ( en tout cas celui qui est affiché .. :hi: )
Le code exécutable ( offsets 00 => 12B )
00000000: 33 C0 8E D0 BC 00 7C FB-50 07 50 1F FC BE 1B 7C 3ÀŽÐ¼.|ûP.P.ü¾.|
00000010: BF 1B 06 50 57 B9 E5 01-F3 A4 CB BD BE 07 B1 04 ¿..PW¹å.ó¤Ë½¾.±.
00000020: 38 6E 00 7C 09 75 13 83-C5 10 E2 F4 CD 18 8B F5 8n.|.u.ƒÅ.âôÍ.‹õ
00000030: 83 C6 10 49 74 19 38 2C-74 F6 A0 B5 07 B4 07 8B ƒÆ.It.8,tö µ.´.‹
00000040: F0 AC 3C 00 74 FC BB 07-00 B4 0E CD 10 EB F2 88 ð¬<.tü»..´.Í.ëòˆ
00000050: 4E 10 E8 46 00 73 2A FE-46 10 80 7E 04 0B 74 0B N.èF.s*þF.€~..t.
00000060: 80 7E 04 0C 74 05 A0 B6-07 75 D2 80 46 02 06 83 €~..t. ¶.uÒ€F..ƒ
00000070: 46 08 06 83 56 0A 00 E8-21 00 73 05 A0 B6 07 EB F..ƒV..è!.s. ¶.ë
00000080: BC 81 3E FE 7D 55 AA 74-0B 80 7E 10 00 74 C8 A0 ¼>þ}Uªt.€~..tÈ
00000090: B7 07 EB A9 8B FC 1E 57-8B F5 CB BF 05 00 8A 56 ·.ë©‹ü.W‹õË¿..ŠV
000000A0: 00 B4 08 CD 13 72 23 8A-C1 24 3F 98 8A DE 8A FC .´.Í.r#ŠÁ$?˜ŠÞŠü
000000B0: 43 F7 E3 8B D1 86 D6 B1-06 D2 EE 42 F7 E2 39 56 C÷ã‹Ñ†Ö±.ÒîB÷â9V
000000C0: 0A 77 23 72 05 39 46 08-73 1C B8 01 02 BB 00 7C .w#r.9F.s.¸..».|
000000D0: 8B 4E 02 8B 56 00 CD 13-73 51 4F 74 4E 32 E4 8A ‹N.‹V.Í.sQOtN2äŠ
000000E0: 56 00 CD 13 EB E4 8A 56-00 60 BB AA 55 B4 41 CD V.Í.ëäŠV.`»ªU´AÍ
000000F0: 13 72 36 81 FB 55 AA 75-30 F6 C1 01 74 2B 61 60 .r6ûUªu0öÁ.t+a`
00000100: 6A 00 6A 00 FF 76 0A FF-76 08 6A 00 68 00 7C 6A j.j.ÿv.ÿv.j.h.|j
00000110: 01 6A 10 B4 42 8B F4 CD-13 61 61 73 0E 4F 74 0B .j.´B‹ôÍ.aas.Ot.
00000120: 32 E4 8A 56 00 CD 13 EB-D6 61 F9 C3
et les deux derniers octets du MBR :
55AA
C'est ce que le BIOS cherche , ceci indique que le secteur est exécutable , le BIOS va donc exécuter le code du MBR et non celui d'un virus ( qui remplace le MBR par son code , il ajoute 55AA à la fin puis exécute une copie du MBR pour passer inaperçu .. )
-
Plop,
/mode gonflant on
Je peux virer ce dossier du registre ?!
Ya toujours pas de dossier dans le registre :red:
/mode gonflant off
-
[mode troll on]
:BBB
;D :NNN
[/mode troll off]
Je crois que tu nous fais un peu mode parano là Multi non ?
De tout ce que tu nous a posté (pour ce que j'ai lu, et compris :NNN ) y'a jamais eu aucune infection ...
-
ouaip, c'est un peu comme ça que j'avais lu aussi...
t'avais choppé un dropper bootkit?
car ça pourrait intéresser certains ;o)
lecture:
hXXp://www.blackhat.com/presentations/bh-usa-09/KLEISSNER/BHUSA09-Kleissner-StonedBootkit-PAPER.pdf
Certains ont des dons prémonitoires (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi263.photobucket.com%2Falbums%2Fii126%2FSham_Rock1%2Fredface.gif&hash=d7aa2375f60e6bb9ba61cf63671dc2018fb8d7fd)
-
Salut @ tous,
merci pour cette réponse collective :)
Juste une petite précision et très franchement,
j'ai tellement de choses à faire que j'ai vraiment
autre chose à faire que de vous faire perde votre temps.
Thanks pour l'explication Eric !
Ya toujours pas de dossier dans le registre
MultiSorry ... vous m'avez compris ... :D^^
@ Hyunkel : on ne lâche pas un filon qui marche hein ;)
t'avais choppé un dropper bootkit?
car ça pourrait intéresser certains ;o)
J'espère pas. Un peu parano, peut-être ... mais pas tebê ;) ... sincèrement
je ne vais pas chercher à le remonter mais plutôt à m'en débarrasser quoi que ce soit.
lecture:
hXXp://www.blackhat.com/presentations/bh-usa-09/KLEISSNER/BHUSA09-Kleissner-StonedBootkit-PAPER.pdf
Certains ont des dons prémonitoires
J'étais Cleaner pendant un an sur une grosse borde de Warez,
çà ne fais pas pour autant de moi un ChapeauTurlut... juste un bon apprentissage.
Je n'ai jamais hacké personne ! Quand il y a un truc bizarre, je creuse et je piste
c'est tout. :) ... " MultiPadawanPasMéchant ... paranos, vous etes aussi " ;D^^
Quand aux dons prémonitoires, j'en doute fort ... some times quelques paranos
du noob (http://forum.malekal.com/antivir-webguard-malekal-com-t22384.html) s'avisent bien placées ...
Pour ne plus vous saouler, je terminerai donc avec ceci :
lors de la MultiPsychose, la seule solution pour récupérer
le mot de passe changé du Bios (Sup). fut
cette bonne vieille pile X3PC + déconnexion périph. !
Puis, je dédie l'ordi. portable au net, ... je fais des p'tits essais :
Trend => Antivir+ComodoFW => ComosoSS ... pas de soucis.
Je teste Avast, quelques jour passe, quelques scan d'outils aussi
=> Plantage cf. plus haut. "Seule soluce rapide" = La pile, bête
SystemD mais qui a le don de déboussoler plus d'une horloge
+ déconneXions de tous les périphériques RAM/CG/DD/Lecteur/BAT.
Voilou, je ne vais pas vous inventer une histoire ... je me répète ^^ ...
Le démarrage est très lent (ini sys & log sess), je suis sur AVGSecuritySuite(30j).
Il est 6:45, Paris s'éveille ^^ ... oups ...
Bonne journée @ tous :AAN