Auteur Sujet: Whistler Bootkit  (Lu 21779 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Re : Whistler Bootkit
« Réponse #1 le: mai 24, 2010, 23:00:42 »
Question ;

Comme il est protégé par un rootkit dans le MBR, si on répare le MBR il ne reviendra plus. Il suffirait ensuite de le supprimer par un outil non ?

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Whistler Bootkit
« Réponse #2 le: mai 24, 2010, 23:09:00 »
Re,

Ben apparemment, oui, c'est le truc :

L'outil utilisé : bootkit_remover fais un peu comme un fixmbr je pense :
http://forum.malekal.com/your-protection-t25834.html#p212416

Ensuite, tu as le champ libre pour ce qui sont lancé dans les point de resto ou autre .

Moi je suis surtout impressionné par le fait que même sous Vista et 7 ce truc réussisse à s'insérer et prendre un ring0 ...

Hors ligne MultiUser

  • Archives
  • Power Members
  • *
  • Messages: 1551
  • "35p3R4n24!#"
Re : Whistler Bootkit
« Réponse #3 le: mai 24, 2010, 23:34:51 »
Salut Hyunkel,

çà ne m'étonne qu'a moitié : mon PC XP "NET" :

:(
"science sans conscience n'est que ruine de l'âme" (Rabelais)
/watch?v=BnP4eUwT1dQ

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Whistler Bootkit
« Réponse #4 le: mai 24, 2010, 23:52:31 »
Bonsoir Multi ;)

Attention, je ne connais pas exactement l'outil, mais je suppose qu'il peux détecter d'autre modif du boot/mbr sans que ce soit réellement un bootkit, je sais pas, genre multiboot/dualboot par exemple ...

Bref ne lance pas la réparation sans être sur de toi ...

 :AAN

Hors ligne MultiUser

  • Archives
  • Power Members
  • *
  • Messages: 1551
  • "35p3R4n24!#"
Re : Whistler Bootkit
« Réponse #5 le: mai 25, 2010, 00:10:56 »
Salut,

merci pour ta remarque, ZHP me dit çà :

Citer
Zeb Help Process 2 by Nicolas Coolman - Rapport de synthèse du 24/05/2010 23:52:09

 INFORMATION

 PROCESSUS SUPERFLU DU SYSTEME
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE    

 PROCESSUS INUTILE (Au démarrage du système)
O4 - Global Startup: Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe    

 PROTECTION DU SYSTEME (Antivirus, FireWall, Anti-Malwares)
Alwil Avast! Antivirus
Trend Micro TrendProtect
ALWIL Software avast! Antivirus
Avira AntiVir PersonalEdition

 RAPPORT SIMPLIFIE
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE    
 O4 - HKLM\..\policies\Explorer: [HonorAutoRunSetting] Data=0    
 O4 - Global Startup: Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe    
 O43 - CFD:Common File Directory ----D- C:\Program Files\Commander
 O44 - LFC:Last File Created 23/05/2010 - 0:01:22 ---A- C:\WINDOWS\setupapi.log    
 O44 - LFC:Last File Created 24/05/2010 - 20:50:30 ---A- C:\WINDOWS\WindowsUpdate.log    
 O44 - LFC:Last File Created 24/05/2010 - 21:09:52 ---A- C:\WINDOWS\wiaservc.log    
 O44 - LFC:Last File Created 24/05/2010 - 23:28:20 ---A- C:\WINDOWS\wiadebug.log    
 O44 - LFC:Last File Created 29/04/2010 - 2:29:26 ---A- C:\WINDOWS\System32\jupdate-1.6.0_20-b02.log    
 O56 - MWPE:[HKCU\...\Policies\Explorer] - "HonorAutoRunSetting"=0    
 O56 - MWPE:[HKLM\...\Policies\Explorer] - "HonorAutoRunSetting"=0    
 O58 - SDL:System Drivers List - C:\WINDOWS\system32\drivers\DLKRCB.SYS
 O58 - SDL:System Drivers List - C:\WINDOWS\system32\drivers\EnumProcessesDriver.sys
 O64 - Services: CurCS - COMODO Internet Security Eradication Driver (cmderd) - LEGACY_CMDERD
 O64 - Services: CurCS - EnumProcessesDriver (EnumProcessesDriver) - LEGACY_ENUMPROCESSESDRIVER
 O64 - Services: CurCS - kfaiqpoc (kfaiqpoc) - LEGACY_KFAIQPOC
 O64 - Services: CurCS - klmd21 (klmd21) - LEGACY_KLMD21
 O64 - Services: CurCS - rk_remover-boot (rk_remover-boot) - LEGACY_RK_REMOVER-BOOT
 O64 - Services: CS003 - COMODO Internet Security Eradication Driver (cmderd) - LEGACY_CMDERD
 O64 - Services: CS003 - EnumProcessesDriver (EnumProcessesDriver) - LEGACY_ENUMPROCESSESDRIVER
 O64 - Services: CS003 - kfaiqpoc (kfaiqpoc) - LEGACY_KFAIQPOC
 O64 - Services: CS003 - klmd21 (klmd21) - LEGACY_KLMD21
 O64 - Services: CS003 - rk_remover-boot (rk_remover-boot) - LEGACY_RK_REMOVER-BOOT

& GMER me dit ceci à première vue :
Citer
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-05-25 00:20:07
Windows 5.1.2600 Service Pack 3
Running: v7pzvjh0gmer.exe; Driver: C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\kfaiqpoc.sys


---- System - GMER 1.0.15 ----

Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)  ZwCreateProcessEx [0xB2D67AC6]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)  ZwCreateSection [0xB2D678EA]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)  ZwLoadDriver [0xB2D67A24]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)  NtCreateSection
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)  ObInsertObject
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)  ObMakeTemporaryObject

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                 aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                 aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                               aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                              aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                              aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                            aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- EOF - GMER 1.0.15 ----

puis ca en scan complet :
Citer
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-25 01:06:16
Windows 5.1.2600 Service Pack 3
Running: v7pzvjh0gmer.exe; Driver: C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\kfaiqpoc.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwClose [0xB2D5AC7A]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwCreateKey [0xB2D5AB36]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwDeleteKey [0xB2D5B0EA]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwDeleteValueKey [0xB2D5B014]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwDuplicateObject [0xB2D5A70C]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwOpenKey [0xB2D5AC10]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwOpenProcess [0xB2D5A64C]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwOpenThread [0xB2D5A6B0]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwQueryValueKey [0xB2D5AD30]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwRenameKey [0xB2D5B1B8]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwRestoreKey [0xB2D5ACF0]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwSetValueKey [0xB2D5AE70]

Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwCreateProcessEx [0xB2D67AC6]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwCreateSection [0xB2D678EA]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwLoadDriver [0xB2D67A24]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         NtCreateSection
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ObInsertObject
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

.text           ntkrnlpa.exe!ZwCallbackReturn + 2468                                                                          80501CA0 4 Bytes  JMP DAB2D5B0
PAGE            ntkrnlpa.exe!ZwLoadDriver                                                                                     805795FA 7 Bytes  JMP B2D67A28 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!NtCreateSection                                                                                  805A075C 7 Bytes  JMP B2D678EE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!ObMakeTemporaryObject                                                                            805B1CE0 5 Bytes  JMP B2D63536 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!ObInsertObject                                                                                   805B8B58 5 Bytes  JMP B2D64EC2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!ZwCreateProcessEx                                                                                805C73EA 7 Bytes  JMP B2D67ACA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
init            C:\WINDOWS\system32\drivers\ALCXSENS.SYS                                                                      entry point in "init" section [0xF7077510]
init            C:\WINDOWS\system32\drivers\o2mmb.sys                                                                         entry point in "init" section [0xF6FCD320]
?               C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\mbr.sys                                                                    Le fichier spécifié est introuvable. !

---- User code sections - GMER 1.0.15 ----

.text           C:\Documents and Settings\Internet\Application Data\FF\firefox.exe[3528] ntdll.dll!LdrLoadDll                 7C9263C3 5 Bytes  JMP 004013F0 C:\Documents and Settings\Internet\Application Data\FF\firefox.exe (Firefox/Mozilla Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\WINDOWS\system32\services.exe[552] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW]  00380002
IAT             C:\WINDOWS\system32\services.exe[552] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW]        00380000

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                        aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                        aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                      aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                     aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                     aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                   aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- EOF - GMER 1.0.15 ----


je viens d'essayer Comodo et je teste Avast Free pour le moment,
et pour le fixi.bat ... voici la capture d'écran en dessous ...

D'avance merci pour vos conseils, bonne nuit/journée @+
« Modifié: mai 25, 2010, 01:17:55 par MultiUser »
"science sans conscience n'est que ruine de l'âme" (Rabelais)
/watch?v=BnP4eUwT1dQ

Hors ligne Laddy

  • Expert Securité
  • Members
  • ****
  • Messages: 118
Re : Whistler Bootkit
« Réponse #6 le: mai 25, 2010, 11:08:06 »
Bonjour
assures toi que l'outil en question remover soit bien sur ton bureau aussi sinon navigue jusqu'au dossier.
CD NOM DU DOSSIER
CD..

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Re : Whistler Bootkit
« Réponse #7 le: mai 25, 2010, 11:16:15 »
Ou sinon tu le mets dans ton PATH

Hors ligne MultiUser

  • Archives
  • Power Members
  • *
  • Messages: 1551
  • "35p3R4n24!#"
Re : Whistler Bootkit
« Réponse #8 le: mai 25, 2010, 18:42:28 »
Salut,

Merci pour vos conseils, je vais réessayé dès que j'ai grignotté un ptit bout ;D^^

Il était sur le Bureau mais je suis en User et je ne peux l' "exécuter en en tant que..."
Donc je vais quitter la session et refaire le test en MSE admin ...

Si c'est le cas, mes deux autres bécane doivent être dans le même jus ...

@ tout ou @+
« Modifié: mai 25, 2010, 19:36:37 par MultiUser »
"science sans conscience n'est que ruine de l'âme" (Rabelais)
/watch?v=BnP4eUwT1dQ

Hors ligne angelique

  • Expert Securité
  • Members
  • ****
  • Messages: 97
Re : Whistler Bootkit
« Réponse #9 le: mai 25, 2010, 19:33:14 »
comme tout .bat qui appelle "start" l'application , faut que ça soit dans le meme repertoire c'est tout \o_
Avec Gnu_Linux t'as un Noyau ... avec Ѡindows t'as que les pépins
http://angelik.altervista.org/

Hors ligne MultiUser

  • Archives
  • Power Members
  • *
  • Messages: 1551
  • "35p3R4n24!#"
Re : Whistler Bootkit
« Réponse #10 le: mai 25, 2010, 21:12:43 »
Salut,

bon j'avais déjà classé remover.exe dans un dossier, +1 pour Laddy & Angélique
Il a bien viré le truc ? ou c'est une fausse alerte ?
Pour le script Avenger, je sèche :D^^ moi jeune MultiPadawan ;) ...

J'en ai profité pour faire un scan RootkitReveal :
Citer
HKU\S-1-5-21-1844237615-436374069-1801674531-1003\Console   25/03/2010 1:30   0 bytes   Security mismatch.
HKLM\SECURITY\Policy\Secrets\SAC*   25/01/2010 1:07   0 bytes   Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI*   25/01/2010 1:07   0 bytes   Key name contains embedded nulls (*)
HKLM\SOFTWARE\Swearware\backup\winsock2   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017   25/03/2010 1:23   0 bytes   Security mismatch.
HKLM\SOFTWARE\Swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018   25/03/2010 1:23   0 bytes   Security mismatch.
C:\Documents and Settings\Propriétaire\Bureau\RootKitReveler.JPG   25/05/2010 20:19   226.88 KB   Hidden from Windows API.
C:\Documents and Settings\Propriétaire\Recent\RootKitReveler.JPG.lnk   25/05/2010 20:19   535 bytes   Hidden from Windows API.

Un ptit script Combo*** ?! ... OTM ... les deux rapports RSIT sont dans un .zip en pièce jointe ...

D'avance merci pour votre aide ... je suis pret pour mon exécution en direct ^^ ;) ...
c'est mon PC poubelle/internet ... mais je n'utilise pas de crack ou de log pourris ...

@+
« Modifié: mai 25, 2010, 21:51:04 par MultiUser »
"science sans conscience n'est que ruine de l'âme" (Rabelais)
/watch?v=BnP4eUwT1dQ

Hors ligne MultiUser

  • Archives
  • Power Members
  • *
  • Messages: 1551
  • "35p3R4n24!#"
Re : Whistler Bootkit
« Réponse #11 le: mai 26, 2010, 07:58:57 »
Salut . . .

Chouette un autre EXO surprise :D^^ . . .

J'ai un p'tit problème . . .  & un peu de mal à répondre à la question posée à chaque démarrage, MSE impossible . . . : ( cf. pièce jointe ) . . .
Je me dis que toutunchacun choisirait "N" ... donc pourquoi pas "Y" ...

Ce bon vieux EliveCD, qu'est ce que je ferais sans lui ...

Citation de: MBR Dump
00000000:  33 C0 8E D0 BC 00 7C FB-50 07 50 1F FC BE 1B 7C  3ÀŽÐ¼.|ûP.P.ü¾.|

00000010:  BF 1B 06 50 57 B9 E5 01-F3 A4 CB BD BE 07 B1 04  ¿..PW¹å.ó¤Ë½¾.±.

00000020:  38 6E 00 7C 09 75 13 83-C5 10 E2 F4 CD 18 8B F5  8n.|.u.ƒÅ.âôÍ.‹õ

00000030:  83 C6 10 49 74 19 38 2C-74 F6 A0 B5 07 B4 07 8B  ƒÆ.It.8,tö µ.´.‹

00000040:  F0 AC 3C 00 74 FC BB 07-00 B4 0E CD 10 EB F2 88  ð¬<.tü»..´.Í.ëòˆ

00000050:  4E 10 E8 46 00 73 2A FE-46 10 80 7E 04 0B 74 0B  N.èF.s*þF.€~..t.

00000060:  80 7E 04 0C 74 05 A0 B6-07 75 D2 80 46 02 06 83  €~..t. ¶.uҀF..ƒ

00000070:  46 08 06 83 56 0A 00 E8-21 00 73 05 A0 B6 07 EB  F..ƒV..è!.s. ¶.ë

00000080:  BC 81 3E FE 7D 55 AA 74-0B 80 7E 10 00 74 C8 A0  ¼>þ}Uªt.€~..tÈ

00000090:  B7 07 EB A9 8B FC 1E 57-8B F5 CB BF 05 00 8A 56  ·.멋ü.W‹õË¿..ŠV

000000A0:  00 B4 08 CD 13 72 23 8A-C1 24 3F 98 8A DE 8A FC  .´.Í.r#ŠÁ$?˜ŠÞŠü

000000B0:  43 F7 E3 8B D1 86 D6 B1-06 D2 EE 42 F7 E2 39 56  C÷ã‹Ñ†Ö±.ÒîB÷â9V

000000C0:  0A 77 23 72 05 39 46 08-73 1C B8 01 02 BB 00 7C  .w#r.9F.s.¸..».|

000000D0:  8B 4E 02 8B 56 00 CD 13-73 51 4F 74 4E 32 E4 8A  ‹N.‹V.Í.sQOtN2äŠ

000000E0:  56 00 CD 13 EB E4 8A 56-00 60 BB AA 55 B4 41 CD  V.Í.ëäŠV.`»ªU´AÍ

000000F0:  13 72 36 81 FB 55 AA 75-30 F6 C1 01 74 2B 61 60  .r6ûUªu0öÁ.t+a`

00000100:  6A 00 6A 00 FF 76 0A FF-76 08 6A 00 68 00 7C 6A  j.j.ÿv.ÿv.j.h.|j

00000110:  01 6A 10 B4 42 8B F4 CD-13 61 61 73 0E 4F 74 0B  .j.´B‹ôÍ.aas.Ot.

00000120:  32 E4 8A 56 00 CD 13 EB-D6 61 F9 C3 49 6E 76 61  2äŠV.Í.ëÖaùÃInva

00000130:  6C 69 64 20 70 61 72 74-69 74 69 6F 6E 20 74 61  lid partition ta

00000140:  62 6C 65 00 45 72 72 6F-72 20 6C 6F 61 64 69 6E  ble.Error loadin

00000150:  67 20 6F 70 65 72 61 74-69 6E 67 20 73 79 73 74  g operating syst

00000160:  65 6D 00 4D 69 73 73 69-6E 67 20 6F 70 65 72 61  em.Missing opera

00000170:  74 69 6E 67 20 73 79 73-74 65 6D 00 00 00 00 00  ting system.....

00000180:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................

00000190:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................

000001A0:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................

000001B0:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 80 01  ..............€.

000001C0:  01 00 07 FE FF FF 3F 00-00 00 00 14 A8 04 00 00  ...þÿÿ?.....¨...

000001D0:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................

000001E0:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................

000001F0:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 55 AA  ..............Uª


Citer
ComboFix 10-05-25.02 - Propriétaire 26/05/2010   5:52.2.1 - x86

Microsoft Windows XP Édition familiale  5.1.2600.3.1252.32.1036.18.1023.739 [GMT 1:00]

Lancé depuis: c:\documents and settings\Propriétaire\Bureau\CoLAl.exe

AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}


((((((((((((((((((((((((((((((((((((   Autres suppressions   ))))))))))))))))))))))))))))))))))))))))))))))))

c:\windows\system32\404Fix.exe

c:\windows\system32\Agent.OMZ.Fix.exe

c:\windows\system32\dumphive.exe

c:\windows\system32\IEDFix.exe

c:\windows\system32\o4Patch.exe

c:\windows\system32\Process.exe

c:\windows\system32\SrchSTS.exe

c:\windows\system32\tmp.reg

c:\windows\system32\VACFix.exe

c:\windows\system32\VCCLSID.exe

c:\windows\system32\WS2Fix.exe
.

(((((((((((((((((((((((((((((   Fichiers créés du 2010-04-26 au 2010-05-26  ))))))))))))))))))))))))))))))))))))

2010-05-25 19:25 . 2010-05-25 19:25   --------   d-sh--w-   c:\documents and settings\LocalService\IETldCache

2010-05-25 19:10 . 2010-05-25 19:10   --------   d-----w-   c:\program files\burnatonce

2010-05-25 04:32 . 2010-05-25 04:32   --------   d-----w-   c:\program files\Blender Foundation

2010-05-12 05:02 . 2010-05-06 20:33   19024   ----a-w-   c:\windows\system32\drivers\aswFsBlk.sys

2010-05-12 05:02 . 2010-05-06 20:39   164048   ----a-w-   c:\windows\system32\drivers\aswSP.sys

2010-05-12 05:02 . 2010-05-06 20:34   23376   ----a-w-   c:\windows\system32\drivers\aswRdr.sys

2010-05-12 05:02 . 2010-05-06 20:39   46672   ----a-w-   c:\windows\system32\drivers\aswTdi.sys

2010-05-12 05:02 . 2010-05-06 20:33   100432   ----a-w-   c:\windows\system32\drivers\aswmon2.sys

2010-05-12 05:02 . 2010-05-06 20:33   94800   ----a-w-   c:\windows\system32\drivers\aswmon.sys

2010-05-12 05:02 . 2010-05-06 20:33   28880   ----a-w-   c:\windows\system32\drivers\aavmker4.sys

2010-05-12 05:02 . 2010-05-06 20:59   165032   ----a-w-   c:\windows\system32\aswBoot.exe

2010-05-12 05:02 . 2010-04-14 16:47   38848   ----a-w-   c:\windows\system32\avastSS.scr

2010-05-12 05:02 . 2010-05-12 05:02   --------   d-----w-   c:\program files\Alwil Software

2010-05-12 05:02 . 2010-05-12 05:02   --------   d-----w-   c:\documents and settings\All Users\Application Data\Alwil Software

2010-05-06 05:43 . 2010-05-06 05:43   --------   d-----w-   c:\program files\Fichiers communs\Borland Shared

2010-05-06 05:43 . 1999-01-20 04:01   210032   ----a-w-   c:\windows\system32\DBCLIENT.DLL

2010-05-06 05:42 . 2010-05-24 22:46   --------   d-----w-   c:\program files\ZebHelpProcess

2010-05-05 01:24 . 2010-05-05 02:00   --------   d-----w-   c:\windows\system32\hdined32.nls.{00021401-0000-0000-C000-000000000046}

2010-05-03 05:57 . 2010-05-03 05:57   --------   d-----w-   c:\documents and settings\Internet\Application Data\InterVideo

2010-04-29 01:29 . 2010-04-12 16:29   411368   ----a-w-   c:\windows\system32\deployJava1.dll
.

((((((((((((((((((((((((((((((((((   Compte-rendu de Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))

2010-05-22 23:57 . 2010-04-10 03:53   --------   d-----w-   c:\documents and settings\Internet\Application Data\vlc

2010-05-19 16:49 . 2010-03-01 10:37   22080   ----a-w-   c:\documents and settings\Internet\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-05-12 04:51 . 2010-04-11 18:32   --------   d-----w-   c:\program files\COMODO

2010-05-12 04:49 . 2010-01-25 01:38   --------   d-----w-   c:\program files\CCleaner

2010-05-03 05:16 . 2010-03-04 06:34   1   ----a-w-   c:\documents and settings\Internet\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys

2010-04-29 01:29 . 2010-04-10 00:24   --------   d-----w-   c:\program files\Java

2010-04-22 03:45 . 2010-04-19 17:23   --------   d-----w-   c:\program files\Trend Micro

2010-03-29 23:46 . 2010-01-25 01:29   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys

2010-03-29 23:45 . 2010-01-25 01:29   20824   ----a-w-   c:\windows\system32\drivers\mbam.sys

2010-03-25 00:15 . 2010-03-25 00:15   50176   ----a-w-   c:\windows\system32\drivers\rk_remover.sys

2010-03-14 14:25 . 2010-03-14 14:25   503808   ----a-w-   c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-11f6eb45-n\msvcp71.dll

2010-03-14 14:25 . 2010-03-14 14:25   499712   ----a-w-   c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-11f6eb45-n\jmc.dll

2010-03-14 14:25 . 2010-03-14 14:25   348160   ----a-w-   c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-11f6eb45-n\msvcr71.dll

2010-03-14 14:25 . 2010-03-14 14:25   61440   ----a-w-   c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-552e1546-n\decora-sse.dll

2010-03-14 14:25 . 2010-03-14 14:25   12800   ----a-w-   c:\documents and settings\Internet\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-552e1546-n\decora-d3d.dll

2010-03-10 06:16 . 2009-02-01 07:21   420352   ----a-w-   c:\windows\system32\vbscript.dll

2010-02-26 19:30 . 2010-02-26 19:30   20898   ----a-w-   c:\windows\system32\SpoonUninstall-dBpowerAMP Music Converter.dat

2010-02-25 06:17 . 2009-02-01 07:21   916480   ----a-w-   c:\windows\system32\wininet.dll


(((((((((((((((((((((((((((((((((   Points de chargement Reg   ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Google Update"="c:\documents and settings\Propriétaire\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-04-19 135664]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMan"="SOUNDMAN.EXE" [2004-01-09 65536]

"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-02-18 248040]

"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]


c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\

Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2010-2-3 110592]

Assistant d'Acrobat.lnk - c:\program files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"HonorAutoRunSetting"= 0 (0x0)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"HonorAutoRunSetting"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]

2001-09-04 15:24   28672   ----a-w-   c:\windows\system32\Ati2mdxx.exe


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]

2004-03-03 11:00   335872   ----a-w-   c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 10:50   155648   ----a-w-   c:\windows\system32\NeroCheck.exe


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]

2002-07-12 17:15   106496   ----a-w-   c:\windows\SiSUSBrg.exe


[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=


R0 EnumProcessesDriver;EnumProcessesDriver;c:\windows\system32\drivers\EnumProcessesDriver.sys [19/04/2010 18:39 15888]

R0 rk_remover-boot;rk_remover-boot;c:\windows\system32\drivers\rk_remover.sys [25/03/2010 1:15 50176]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [12/05/2010 6:02 164048]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/05/2010 6:02 19024]

R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [25/01/2010 1:35 190465]

R3 DLKRCB;D-Link DFE-690TXD CardBus PC Card;c:\windows\system32\drivers\DLKRCB.SYS [5/02/2010 0:20 25434]

R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [25/01/2010 1:35 5817]


--- Autres Services/Pilotes en mémoire ---


*Deregistered* - RKREVEAL150


Contenu du dossier 'Tâches planifiées'

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-05-26 05:55

Windows 5.1.2600 Service Pack 3 NTFS


Recherche de processus cachés ...


Recherche d'éléments en démarrage automatique cachés ...


Recherche de fichiers cachés ...


Scan terminé avec succès

Fichiers cachés: 0


**************************************************************************
.

--------------------- CLES DE REGISTRE BLOQUEES ---------------------


[HKEY_LOCAL_MACHINE\software\Classes\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]

@Denied: (Full) (Administrators)
.

--------------------- DLLs chargées dans les processus actifs ---------------------


- - - - - - - > 'winlogon.exe'(564)

c:\windows\system32\Ati2evxx.dll
.

Heure de fin: 2010-05-26  05:57:02

ComboFix-quarantined-files.txt  2010-05-26 04:56


Avant-CF: 9.974.153.216 octets libres

Après-CF: 9.965.522.944 octets libres


WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

- - End Of File - - C053A2043831918744BD29AD17C3AC09

D'avance merci pour votre aide . . . & bonne journée  . . _ . .  ' ' ' _ . . ¹~²¬- ° °
« Modifié: mai 26, 2010, 08:27:22 par MultiUser »
"science sans conscience n'est que ruine de l'âme" (Rabelais)
/watch?v=BnP4eUwT1dQ

Hors ligne Laddy

  • Expert Securité
  • Members
  • ****
  • Messages: 118
Re : Re : Whistler Bootkit
« Réponse #12 le: mai 26, 2010, 08:47:16 »
Salut,

Merci pour vos conseils, je vais réessayé dès que j'ai grignotté un ptit bout ;D^^

Il était sur le Bureau mais je suis en User et je ne peux l' "exécuter en en tant que..."
Donc je vais quitter la session et refaire le test en MSE admin ...

Si c'est le cas, mes deux autres bécane doivent être dans le même jus ...

@ tout ou @+
Si tu es sous vista/seven pour effectuer la manipulation tu dois executer sans doute ton invite de commande En tant qu'administrateur : cmd

Hors ligne MultiUser

  • Archives
  • Power Members
  • *
  • Messages: 1551
  • "35p3R4n24!#"
Re : Re : Re : Whistler Bootkit
« Réponse #13 le: mai 26, 2010, 09:01:25 »
Si tu es sous vista/seven pour effectuer la manipulation tu dois executer sans doute ton invite de commande En tant qu'administrateur : cmd
Salut Laddy :)

je suis sur XPhomeSP3 avec Avast5 ... hihihi ... no comment ...

j'ai fais la manipulation qui s'est apparemment bien passée,
puis j'ai utilisé MBR Dump, ATF puis CCleaner pour finir avec
Combofix ... tout çà en admin. => puis reboot . . .
Si je n'appuie pas successivement sur "Del" & "Esc" le BIOS
ne se lance pas comme il devrait et le EliveCD ne se lance pas,
& j'ai ce message de ouf qu'il y a sur la photo juste au dessus.

C'est quoi ce Boot.BAK à la racine du C ? . . . ( 2eme capture )

Voilou ... bonne journée
« Modifié: mai 26, 2010, 09:07:58 par MultiUser »
"science sans conscience n'est que ruine de l'âme" (Rabelais)
/watch?v=BnP4eUwT1dQ

Hors ligne Laddy

  • Expert Securité
  • Members
  • ****
  • Messages: 118
Re : Whistler Bootkit
« Réponse #14 le: mai 26, 2010, 10:21:53 »
Bonjour
pour les captures je ne vois pas pour le moment

pour le boot.bak c'est une sauvegarde de ton boot.ini qui a été surement modifié par un outil notamment combofix si tu as installé la console de répération comme demandé.

Une idée :
tu as peut etre un antivirus ou un systeme de protection de secteur de boot dans ton bios
regarde pour désactiver l'option.
voir au niveau d'avast aussi
Une autre idée  :
Réparer le secteur de boot : fixboot
effectuer une restauration du mbr : fixmbr C:
http://www.zebulon.fr/dossiers/61-7-reparer-mbr.html
http://www.zebulon.fr/dossiers/61-6-reparer-secteur-boot.html
« Modifié: mai 26, 2010, 10:29:48 par Laddy »

Hors ligne MultiUser

  • Archives
  • Power Members
  • *
  • Messages: 1551
  • "35p3R4n24!#"
Re : Whistler Bootkit
« Réponse #15 le: mai 26, 2010, 18:05:40 »
Salut Laddy,

merci pour ta réponse, Avast a été désactivé "définitivement" (reprise manuelle)
Un bug à ce niveau là ? ...
Par contre au vue du log Gmer, il n'aurait pas viré un composant du nouveau Avast (FP) ?

Tout les outils dont les rapports sont présent ici ont été passé avant le reboot, j'ai fini
par Combo (la sauvegarde des ruches système s'est passée correctement) . . .

Un autre truc bizard, lors de l'allumage, un deuxième bip plus aigu
se fait entendre puis je peux voir en bas à droite de l'écran d'affichage du BIOS :
une série de 4 caractères qui se modifient en fonction des opérations suivantes :

6B3B => apparition du BIOS ( 1 fraction de seconde )
003B => affichage du BIOS ( listing composants )
0060 => idem ( vérification de la RAM )
0075 => idem ( vérification DD )
0078 => idem ( vérification LecteurDVDRAM )
00A7 => transition ( 1 fraction de seconde )
00A9 => récapitulatif matériel : 9 .. 8 ... 7 .. 6 ... ( Esc )
...C => Boot ( 1 fraction de seconde )

=> ECRAN DE OUF :
" Boot Sector Write !!
  VIRUS : Continue ( Y / N ) ?  "


Je n'ai pas mis de "sécurité virus" via le BIOS, juste un mod de passe Sup.
mais je n'y ai plus accès donc je ne peux vérifier la configuration ...

Bonne journée



[EDIT]
J'ai fais péter la Pile pendant une petite demi heure ;D ... j'en ai profité pour
le désosser(DD/RAM/CG/DVD/BAT/VENT) et faire un peu de dépoussiérage ...  

Le disque mis sur un autre XPproSP3+TrendIS me demandais un mot de passe
pour tous les comptes, donc données inaccessibles. J'ai tout remis comme avant,
démarré l'ordi. => avertissements BOOT CMOS => F2 : SETUP => reconfiguré le
BIOS + MDP SUP. + BOOT ( INTEL EX.. & Removable Distribution(1erePos) virés )

Cà fonctionne, je ne vois rien dans l'Observateur d'événement à par des erreurs
GoogleUpDater ou le Centre de Sécurité Microsoft qui se manifeste ...

J'espère que les outils ont fait leurs taffs ??? ...

-------------------------------

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

-------------------------------

00000000:  33 C0 8E D0 BC 00 7C FB-50 07 50 1F FC BE 1B 7C  3ÀŽÐ¼.|ûP.P.ü¾.|
00000010:  BF 1B 06 50 57 B9 E5 01-F3 A4 CB BD BE 07 B1 04  ¿..PW¹å.ó¤Ë½¾.±.
00000020:  38 6E 00 7C 09 75 13 83-C5 10 E2 F4 CD 18 8B F5  8n.|.u.ƒÅ.âôÍ.‹õ
00000030:  83 C6 10 49 74 19 38 2C-74 F6 A0 B5 07 B4 07 8B  ƒÆ.It.8,tö µ.´.‹
00000040:  F0 AC 3C 00 74 FC BB 07-00 B4 0E CD 10 EB F2 88  ð¬<.tü»..´.Í.ëòˆ
00000050:  4E 10 E8 46 00 73 2A FE-46 10 80 7E 04 0B 74 0B  N.èF.s*þF.€~..t.
00000060:  80 7E 04 0C 74 05 A0 B6-07 75 D2 80 46 02 06 83  €~..t. ¶.uÒ€F..ƒ
00000070:  46 08 06 83 56 0A 00 E8-21 00 73 05 A0 B6 07 EB  F..ƒV..è!.s. ¶.ë
00000080:  BC 81 3E FE 7D 55 AA 74-0B 80 7E 10 00 74 C8 A0  ¼>þ}Uªt.€~..tÈ
00000090:  B7 07 EB A9 8B FC 1E 57-8B F5 CB BF 05 00 8A 56  ·.ë©‹ü.W‹õË¿..ŠV
000000A0:  00 B4 08 CD 13 72 23 8A-C1 24 3F 98 8A DE 8A FC  .´.Í.r#ŠÁ$?˜ŠÞŠü
000000B0:  43 F7 E3 8B D1 86 D6 B1-06 D2 EE 42 F7 E2 39 56  C÷ã‹Ñ†Ö±.ÒîB÷â9V
000000C0:  0A 77 23 72 05 39 46 08-73 1C B8 01 02 BB 00 7C  .w#r.9F.s.¸..».|
000000D0:  8B 4E 02 8B 56 00 CD 13-73 51 4F 74 4E 32 E4 8A  ‹N.‹V.Í.sQOtN2äŠ
000000E0:  56 00 CD 13 EB E4 8A 56-00 60 BB AA 55 B4 41 CD  V.Í.ëäŠV.`»ªU´AÍ
000000F0:  13 72 36 81 FB 55 AA 75-30 F6 C1 01 74 2B 61 60  .r6ûUªu0öÁ.t+a`
00000100:  6A 00 6A 00 FF 76 0A FF-76 08 6A 00 68 00 7C 6A  j.j.ÿv.ÿv.j.h.|j
00000110:  01 6A 10 B4 42 8B F4 CD-13 61 61 73 0E 4F 74 0B  .j.´B‹ôÍ.aas.Ot.
00000120:  32 E4 8A 56 00 CD 13 EB-D6 61 F9 C3 49 6E 76 61  2äŠV.Í.ëÖaùÃInva
00000130:  6C 69 64 20 70 61 72 74-69 74 69 6F 6E 20 74 61  lid partition ta
00000140:  62 6C 65 00 45 72 72 6F-72 20 6C 6F 61 64 69 6E  ble.Error loadin
00000150:  67 20 6F 70 65 72 61 74-69 6E 67 20 73 79 73 74  g operating syst
00000160:  65 6D 00 4D 69 73 73 69-6E 67 20 6F 70 65 72 61  em.Missing opera
00000170:  74 69 6E 67 20 73 79 73-74 65 6D 00 00 00 00 00  ting system.....
00000180:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................
00000190:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................
000001A0:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................
000001B0:  00 00 00 00 00 00 00 00-FD 2F CD 3B 00 00 80 01  ........ý/Í;..€.
000001C0:  01 00 07 FE FF FF 3F 00-00 00 00 14 A8 04 00 00  ...þÿÿ?.....¨...
000001D0:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................
000001E0:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00  ................
000001F0:  00 00 00 00 00 00 00 00-00 00 00 00 00 00 55 AA  ..............Uª

-------------------------------
Je peux virer ce dossier du registre ?!
HKLM\SOFTWARE\Swearware\ ... d'avance merci ...

@+
« Modifié: mai 26, 2010, 23:35:46 par MultiUser »
"science sans conscience n'est que ruine de l'âme" (Rabelais)
/watch?v=BnP4eUwT1dQ

Hors ligne MultiUser

  • Archives
  • Power Members
  • *
  • Messages: 1551
  • "35p3R4n24!#"
Re : Whistler Bootkit
« Réponse #16 le: mai 28, 2010, 22:55:44 »
Salut,

UP  :NNN ... un p'tit consils vite fait ...

s'il vous plait ...

@+
"science sans conscience n'est que ruine de l'âme" (Rabelais)
/watch?v=BnP4eUwT1dQ

Hors ligne Eric_71

  • Fondateurs
  • Power Members
  • *****
  • Messages: 1968
Re : Whistler Bootkit
« Réponse #17 le: mai 29, 2010, 10:05:27 »

Yop, ton MBR est bon ( en tout cas celui qui est affiché ..  :hi: )

Le code exécutable ( offsets  00 => 12B )

00000000:  33 C0 8E D0 BC 00 7C FB-50 07 50 1F FC BE 1B 7C  3ÀŽÐ¼.|ûP.P.ü¾.|
00000010:  BF 1B 06 50 57 B9 E5 01-F3 A4 CB BD BE 07 B1 04  ¿..PW¹å.ó¤Ë½¾.±.
00000020:  38 6E 00 7C 09 75 13 83-C5 10 E2 F4 CD 18 8B F5  8n.|.u.ƒÅ.âôÍ.‹õ
00000030:  83 C6 10 49 74 19 38 2C-74 F6 A0 B5 07 B4 07 8B  ƒÆ.It.8,tö µ.´.‹
00000040:  F0 AC 3C 00 74 FC BB 07-00 B4 0E CD 10 EB F2 88  ð¬<.tü»..´.Í.ëòˆ
00000050:  4E 10 E8 46 00 73 2A FE-46 10 80 7E 04 0B 74 0B  N.èF.s*þF.€~..t.
00000060:  80 7E 04 0C 74 05 A0 B6-07 75 D2 80 46 02 06 83  €~..t. ¶.uÒ€F..ƒ
00000070:  46 08 06 83 56 0A 00 E8-21 00 73 05 A0 B6 07 EB  F..ƒV..è!.s. ¶.ë
00000080:  BC 81 3E FE 7D 55 AA 74-0B 80 7E 10 00 74 C8 A0  ¼>þ}Uªt.€~..tÈ
00000090:  B7 07 EB A9 8B FC 1E 57-8B F5 CB BF 05 00 8A 56  ·.ë©‹ü.W‹õË¿..ŠV
000000A0:  00 B4 08 CD 13 72 23 8A-C1 24 3F 98 8A DE 8A FC  .´.Í.r#ŠÁ$?˜ŠÞŠü
000000B0:  43 F7 E3 8B D1 86 D6 B1-06 D2 EE 42 F7 E2 39 56  C÷ã‹Ñ†Ö±.ÒîB÷â9V
000000C0:  0A 77 23 72 05 39 46 08-73 1C B8 01 02 BB 00 7C  .w#r.9F.s.¸..».|
000000D0:  8B 4E 02 8B 56 00 CD 13-73 51 4F 74 4E 32 E4 8A  ‹N.‹V.Í.sQOtN2äŠ
000000E0:  56 00 CD 13 EB E4 8A 56-00 60 BB AA 55 B4 41 CD  V.Í.ëäŠV.`»ªU´AÍ
000000F0:  13 72 36 81 FB 55 AA 75-30 F6 C1 01 74 2B 61 60  .r6ûUªu0öÁ.t+a`
00000100:  6A 00 6A 00 FF 76 0A FF-76 08 6A 00 68 00 7C 6A  j.j.ÿv.ÿv.j.h.|j
00000110:  01 6A 10 B4 42 8B F4 CD-13 61 61 73 0E 4F 74 0B  .j.´B‹ôÍ.aas.Ot.
00000120:  32 E4 8A 56 00 CD 13 EB-D6 61 F9 C3

et les deux derniers octets du MBR :

55AA
C'est ce que le BIOS cherche , ceci indique que le secteur est exécutable , le BIOS va donc exécuter le code du MBR et non celui d'un virus ( qui remplace le MBR par son code , il ajoute 55AA à la fin puis exécute une copie du MBR pour passer inaperçu .. )


Hors ligne Cyrrus

  • Ancien du Staff
  • Members
  • ****
  • Messages: 495
Re : Whistler Bootkit
« Réponse #18 le: mai 29, 2010, 10:57:54 »
Plop,

/mode gonflant on

Citer
Je peux virer ce dossier du registre ?!

Ya toujours pas de dossier dans le registre  :red:

/mode gonflant off
« Modifié: mai 29, 2010, 10:58:24 par Cyrrus »

Cyrrus aka Birkoff

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Whistler Bootkit
« Réponse #19 le: mai 29, 2010, 11:01:45 »
[mode troll on]
 :BBB

 ;D  :NNN

[/mode troll off]

Je crois que tu nous fais un peu mode parano là Multi non ?
De tout ce que tu nous a posté (pour ce que j'ai lu, et compris  :NNN ) y'a jamais eu aucune infection ...

Hors ligne Sham_Rock

  • Fondateurs
  • Power Members
  • *****
  • Messages: 2080
  • <@_@>
Re : Whistler Bootkit
« Réponse #20 le: mai 29, 2010, 21:36:57 »
ouaip, c'est un peu comme ça que j'avais lu aussi...
t'avais choppé un dropper bootkit?
car ça pourrait intéresser certains ;o)

lecture:
hXXp://www.blackhat.com/presentations/bh-usa-09/KLEISSNER/BHUSA09-Kleissner-StonedBootkit-PAPER.pdf
Certains ont des dons prémonitoires




Hors ligne MultiUser

  • Archives
  • Power Members
  • *
  • Messages: 1551
  • "35p3R4n24!#"
Re : Whistler Bootkit
« Réponse #21 le: mai 30, 2010, 06:38:13 »
Salut @ tous,

merci pour cette réponse collective :)

Juste une petite précision et très franchement,
j'ai tellement de choses à faire que j'ai vraiment
autre chose à faire que de vous faire perde votre temps.

Thanks pour l'explication Eric !

Citer
Ya toujours pas de dossier dans le registre
MultiSorry ... vous m'avez compris ... :D^^

@ Hyunkel : on ne lâche pas un filon qui marche hein ;)

Citer
t'avais choppé un dropper bootkit?
car ça pourrait intéresser certains ;o)
J'espère pas. Un peu parano, peut-être ... mais pas tebê ;) ... sincèrement
je ne vais pas chercher à le remonter mais plutôt à m'en débarrasser quoi que ce soit.

Citer
lecture:
hXXp://www.blackhat.com/presentations/bh-usa-09/KLEISSNER/BHUSA09-Kleissner-StonedBootkit-PAPER.pdf
Certains ont des dons prémonitoires
J'étais Cleaner pendant un an sur une grosse borde de Warez,
çà ne fais pas pour autant de moi un ChapeauTurlut... juste un bon apprentissage.
Je n'ai jamais hacké personne ! Quand il y a un truc bizarre, je creuse et je piste
c'est tout. :) ... " MultiPadawanPasMéchant ... paranos, vous etes aussi " ;D^^
Quand aux dons prémonitoires, j'en doute fort ... some times quelques paranos
du noob
s'avisent bien placées ...

Pour ne plus vous saouler, je terminerai donc avec ceci :
lors de la MultiPsychose, la seule solution pour récupérer
le mot de passe changé du Bios (Sup). fut
cette bonne vieille pile X3PC + déconnexion périph. !

Puis, je dédie l'ordi. portable au net, ... je fais des p'tits essais :
Trend => Antivir+ComodoFW => ComosoSS ... pas de soucis.
Je teste Avast, quelques jour passe, quelques scan d'outils aussi
=> Plantage cf. plus haut. "Seule soluce rapide" = La pile, bête
SystemD mais qui a le don de déboussoler plus d'une horloge
+ déconneXions de tous les périphériques RAM/CG/DD/Lecteur/BAT.
Voilou, je ne vais pas vous inventer une histoire ... je me répète ^^ ...
Le démarrage est très lent (ini sys & log sess), je suis sur AVGSecuritySuite(30j).
Il est 6:45, Paris s'éveille ^^ ... oups ...

Bonne journée @ tous :AAN
« Modifié: mai 30, 2010, 06:49:38 par MultiUser »
"science sans conscience n'est que ruine de l'âme" (Rabelais)
/watch?v=BnP4eUwT1dQ

Tags: