je ne repère rien de spécial dans les rapports, pas d'alerte.

I updated them both, ran them both, they both keep finding instances of Win32.TDSS.rtk and Rootkit.Trace (along with other stuff) and say that they are deleting them, I can see the Back to top #3 chakakhan chakakhan Topic Starter Members 9 posts OFFLINE Local time:08:23 AM Posted 19 June 2009 - 02:57 PM Hi, that was a quick reply, thanks so Check out the forums and get free advice from the experts. Here is my GMER log:GMER - http://www.gmer.netRootkit scan 2009-06-19 12:45:45Windows 5.1.2600 Service Pack 3---- System - GMER 1.0.15 ----Code 8A63ECCE ZwEnumerateKeyCode 8A88044E ZwFlushInstructionCacheCode 8AD5E655 IofCallDriverCode 8A8A6BDD IofCompleteRequest---- Kernel code sections

Presiona clic sobre el botn "Continue"Para desinfectar correctamente el Sistema, puede solicitarle reiniciar el equipo.Presiona clic sobre el botn

View Answer Related Questions Ubuntu : Squid / Squidclamav / Clamav Not Logging Virus Found Messages I'm currently working on a Squid setup and using squidclamav / clamav for Virus scanning Quelqu'un a une idée autre que combofix (suppression connexion internet si activé sous mon Vista). Upon restart, continue as follows:Close any open browsers.Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. -----------------------------------------------------------Very Important!

Thank you so much!Logfile of Trend Micro HijackThis v2.0.2Scan saved at 6:41:31 PM, on 7/4/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware\AAWService.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\hkcmd.exeC:\Program Files\NavNT\vptray.exeC:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exeC:\Program Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\[email protected] Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\[email protected] C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\[email protected] 0x3D 0xCE 0xEA 0x26 ... View Answer Related Questions You may search : Virus Win32 And Win32 Win32 Tdss Win32 Tdss Virus Win32.Tdss.Reg Search Result Index Os : Invalid Win32 Application: \Boot\Bootsect.Exe Os : Excel.Exe Is It said "no malicious items were detected".

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. That may cause it to stall** 0 #3 Rorschach112 Posted 26 July 2009 - 11:37 AM Rorschach112 Ralphie Retired Staff 47,710 posts Due to lack of feedback, this topic has been Back to top #7 chakakhan chakakhan Topic Starter Members 9 posts OFFLINE Local time:08:23 AM Posted 20 June 2009 - 02:53 AM Hi again JSntgRvr. GMER - http://www.gmer.net Rootkit scan 2009-02-25 18:06:59 Windows 6.0.6001 Service Pack 1 ---- Kernel code sections - GMER 1.0.14 ---- ?

Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{31A158D6-17B2-EEE9-3FC9-F8D8DE8896A8}@hakpilaafjppfndp 0x6E 0x62 0x68 0x63 ... ---- EOF - GMER 1.0.14 ---- J'ai un scan complet de ESET SMART SECURITY en cours je posterai le log à la fin

Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\[email protected] Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\[email protected] C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\[email protected] 0xB0 0x18 0xED 0xA7 ... Step-3. Thanks again for the quick responses.

