TR/Crypt.ZPACK.gen - Page 2

Précédent
  • 1
  • 2
  1. Utilisateur anonyme
     
    tu dois faire l'analyse rapide et l'analyse compléte.
    0
  2. Daxilane Messages postés 22 Date d'inscription   Statut Membre Dernière intervention  
     
    L'analyse complète vient de planter!!!!!

    Si je le branche en esclave sur un autre PC ça marche???
    0
  3. Utilisateur anonyme
     
    On va agir différemment et le killer .

    /!\ A l'attention de ceux qui passent sur ce sujet /!\
    Le logiciel qui suit n'est pas à utiliser à la légère et peut faire des dégâts s'il est mal utilisé ! Ne le faites que si un helpeur du forum qui connait bien cet outil vous l'a recommandé.

    /!\ Désactive tous tes logiciels de protection /!\

    • Télécharge combofix(de sUBs) sur ton Bureau.
    • Double-clique sur ComboFix.exe afin de le lancer.
    • Il va te demander d'installer la console de récupération : accepte. (important en cas de problème)
    • Ne touche à rien pendant le scan.
    • Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\Combofix.txt) dans ta prochaine réponse.
    #Si combofix ne veut pas se lancer renommes le en ccm.exe et éxécutes le en mode sans échec .
    Tutoriel officiel de Combofix : http://www.bleepingcomputer.com/combofix/fr/comment-utiliser¬-combofix
    0
  4. Daxilane Messages postés 22 Date d'inscription   Statut Membre Dernière intervention  
     
    Bonjour, bon, voici les dernières nouvelles du front :

    J'ai monté le HD du PC sur un autre en esclave.
    J'ai ainsi réussi à le scanner avec AVPTool : "RIEN"
    J'en ai profité pour défragmanter le disque...

    Après réinstalation du disque dans le bon PC, voici le rapport de ComboFix :

    ComboFix 09-11-01.04 - Administrateur 02/11/2009 16:50.1.2 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.503.185 [GMT 1:00]
    Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
    AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\Internet Explorer\iekey.dll
    c:\windows\Downloaded Program Files\Install.inf

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2009-10-02 au 2009-11-02 ))))))))))))))))))))))))))))))))))))
    .

    2009-11-01 20:13 . 2009-11-01 20:34 -------- d-----w- c:\documents and settings\Administrateur\DoctorWeb
    2009-11-01 15:52 . 2009-11-02 15:43 2236448 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2009-10-27 17:05 . 2001-08-17 20:47 12928 ----a-w- c:\windows\system32\drivers\Dot4Prt.sys
    2009-10-27 17:05 . 2001-08-17 20:47 12928 ----a-w- c:\windows\system32\dllcache\dot4prt.sys
    2009-10-27 17:05 . 2001-08-23 16:11 24064 ----a-w- c:\windows\system32\drivers\Dot4usb.sys
    2009-10-27 17:05 . 2001-08-23 16:11 24064 ----a-w- c:\windows\system32\dllcache\dot4usb.sys
    2009-10-27 17:05 . 2004-08-03 21:58 207360 ----a-w- c:\windows\system32\drivers\Dot4.sys
    2009-10-27 17:05 . 2004-08-03 21:58 207360 ----a-w- c:\windows\system32\dllcache\dot4.sys
    2009-10-25 17:32 . 2009-10-25 17:32 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
    2009-10-25 17:28 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2009-10-25 17:19 . 2009-10-25 17:19 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
    2009-10-25 17:18 . 2009-10-25 17:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-10-25 16:48 . 2009-10-25 16:48 -------- d-sh--w- c:\documents and settings\Administrateur\IECompatCache
    2009-10-25 16:47 . 2009-10-25 16:47 -------- d-sh--w- c:\documents and settings\Administrateur\PrivacIE
    2009-10-25 16:46 . 2009-10-25 16:46 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
    2009-10-25 16:45 . 2009-10-25 16:45 -------- d--h--w- c:\windows\msdownld.tmp
    2009-10-25 16:43 . 2009-10-25 16:44 -------- dc-h--w- c:\windows\ie8
    2009-10-25 16:43 . 2009-10-25 16:44 -------- d-----w- c:\windows\system32\fr-FR
    2009-10-25 12:21 . 2009-10-25 12:21 -------- d-----w- c:\program files\FileHippo.com
    2009-10-25 12:12 . 2009-10-25 12:12 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2009-10-25 12:12 . 2009-10-25 12:12 -------- d-----w- c:\program files\NOS
    2009-10-25 12:05 . 2009-10-25 12:05 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-10-25 12:05 . 2009-10-25 12:05 -------- d-----w- c:\program files\Java
    2009-10-25 12:02 . 2008-02-26 12:00 294912 ------w- c:\windows\system32\dllcache\msctf.dll
    2009-10-25 11:56 . 2009-10-25 11:56 -------- d-----w- c:\program files\WOT
    2009-10-24 18:46 . 2009-11-01 13:40 -------- d-----w- C:\UsbFix
    2009-10-24 13:08 . 2009-10-24 13:08 -------- d-----w- C:\rsit
    2009-10-15 16:31 . 2009-10-15 16:31 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
    2009-10-15 16:31 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-10-15 16:31 . 2009-10-15 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-10-15 16:31 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-10-15 16:31 . 2009-10-15 16:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-11-02 15:50 . 2006-05-08 09:33 76384 ----a-w- c:\windows\system32\perfc00C.dat
    2009-11-02 15:50 . 2006-05-08 09:33 471246 ----a-w- c:\windows\system32\perfh00C.dat
    2009-11-02 15:43 . 2009-11-01 15:52 27284 --sha-w- c:\windows\system32\drivers\fidbox.idx
    2009-11-01 13:42 . 2007-10-10 10:13 -------- d-----w- c:\program files\Trend Micro
    2009-10-31 23:19 . 2009-05-20 16:09 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Winamp
    2009-10-26 20:10 . 2008-05-04 22:18 -------- d-----w- c:\documents and settings\Administrateur\Application Data\vlc
    2009-10-25 17:18 . 2009-02-27 13:00 -------- d-----w- c:\program files\Lavasoft
    2009-10-25 17:02 . 2009-05-20 16:09 -------- d-----w- c:\program files\Winamp
    2009-10-25 12:19 . 2007-03-01 07:06 -------- d-----w- c:\program files\Fichiers communs\Adobe
    2009-10-18 21:42 . 2008-07-12 11:53 -------- d-----w- c:\documents and settings\Administrateur\Application Data\dvdcss
    2009-09-27 21:13 . 2008-04-23 14:59 -------- d-----w- c:\program files\PIElectronique
    2009-08-19 12:23 . 2009-08-03 10:13 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-19 1667584]
    "FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2009-09-28 155648]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WinVNC"="c:\program files\UltraVNC\WinVNC.exe" [2006-06-18 712704]
    "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
    "SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
    "SDMSSplash"="c:\program files\HP_SDMS\SDMSSplash\launcher.exe" [2006-03-10 86016]
    "Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-04-24 888832]
    "Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-03-31 761856]
    "Recguard"="c:\windows\Sminst\Recguard.exe" [2006-05-12 1138688]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-06-11 30192]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-25 149280]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
    "Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
    "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-07-04 16250880]
    "Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\SMINST\\Scheduler.exe"=
    "c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
    "c:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "15251:TCP"= 15251:TCP:NortonAV
    "13175:TCP"= 13175:TCP:NortonAV
    "12757:TCP"= 12757:TCP:NortonAV
    "17956:TCP"= 17956:TCP:NortonAV
    "12660:TCP"= 12660:TCP:NortonAV
    "14840:TCP"= 14840:TCP:NortonAV
    "13799:TCP"= 13799:TCP:NortonAV
    "17802:TCP"= 17802:TCP:NortonAV
    "14784:TCP"= 14784:TCP:NortonAV
    "12960:TCP"= 12960:TCP:NortonAV
    "12010:TCP"= 12010:TCP:NortonAV
    "14752:TCP"= 14752:TCP:NortonAV
    "15379:TCP"= 15379:TCP:NortonAV
    "14979:TCP"= 14979:TCP:NortonAV
    "18722:TCP"= 18722:TCP:NortonAV
    "18239:TCP"= 18239:TCP:NortonAV
    "18440:TCP"= 18440:TCP:NortonAV
    "16021:TCP"= 16021:TCP:NortonAV
    "17636:TCP"= 17636:TCP:NortonAV
    "18444:TCP"= 18444:TCP:NortonAV
    "14642:TCP"= 14642:TCP:NortonAV
    "14654:TCP"= 14654:TCP:NortonAV
    "18357:TCP"= 18357:TCP:NortonAV
    "17677:TCP"= 17677:TCP:NortonAV
    "13899:TCP"= 13899:TCP:NortonAV
    "18387:TCP"= 18387:TCP:NortonAV
    "13328:TCP"= 13328:TCP:NortonAV
    "13320:TCP"= 13320:TCP:NortonAV
    "5170:TCP"= 5170:TCP:qwwmp

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [25/10/2009 18:28 64288]
    R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [03/08/2009 11:13 108289]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 12:17 1169232]
    R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [02/03/2007 12:12 6016]
    S2 hebvn;Task Update;c:\windows\system32\svchost.exe -k netsvcs [02/03/2006 03:00 14336]
    S2 movjweg;Monitor Config;c:\windows\system32\svchost.exe -k netsvcs [02/03/2006 03:00 14336]
    S2 qdxwzw;Helper Driver;c:\windows\system32\svchost.exe -k netsvcs [02/03/2006 03:00 14336]
    S3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe -k getPlusHelper [02/03/2006 03:00 14336]
    S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [11/06/2009 19:42 30192]

    --- Autres Services/Pilotes en mémoire ---

    *NewlyCreated* - MBR
    *Deregistered* - mbr

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper REG_MULTI_SZ getPlusHelper

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    movjweg
    hebvn
    qdxwzw
    .
    Contenu du dossier 'Tâches planifiées'

    2009-11-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:06]

    2009-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

    2009-11-02 c:\windows\Tasks\User_Feed_Synchronization-{3354AC77-BF99-4DB9-9EBC-93FD95794CAD}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.fr/
    uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
    uInternet Settings,ProxyServer = ftp=217.19.195.242:8082;http=217.19.195.242:80;https=217.19.195.242:8081
    uInternet Settings,ProxyOverride = 217.19.195.242;152.50.*;*.local
    uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    TCP: {C9AF0287-9531-4196-89DE-095FCCABAB58} = 217.19.192.128,217.19.192.137
    DPF: {5D80A6D1-B500-47DA-82B8-EB9875F85B4D} - hxxp://dl.google.com/dl/desktop/nv/GoogleGadgetPluginIEWin.cab
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    Notify-NavLogon - (no file)
    AddRemove-iasuw - c:\documents and settings\administrateur\local settings\application data\iasuw.exe

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-11-02 16:57
    Windows 5.1.2600 Service Pack 2 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hebvn]
    "ServiceDll"="c:\windows\system32\pxotq.dll"
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    Télécharger Avenger : iciet décompressez sur votre bureau.
    Ouvrir Avenger. Assurez-vous que la case "Scan for rootkits" et "Automatically disable any rootkits found"soit cochée.Répondez Oui pour exécuter un scan antirootkit :La première étape étant finie, The Avenger a désormais besoin de redémarrer votre PC pour finir
    Cliquez sur Oui

    Votre ordinateur redémarrera alors automatiquement
    Au redémarrage, le rapport de The Avenger s'ouvrira automatiquement
    Post ce rapport.
    0
  7. Daxilane Messages postés 22 Date d'inscription   Statut Membre Dernière intervention  
     
    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows XP

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!

    Completed script processing.

    *******************

    Finished! Terminate.
    0
  8. Utilisateur anonyme
     
    je ne vois aucune infection.
    0
  9. Daxilane Messages postés 22 Date d'inscription   Statut Membre Dernière intervention  
     
    Curieusement, depuis cette après-midi, je n'ai plus eu d'alerte AVIRA.

    Par contre le PC rame toujour autant malgré la défragmentation.
    Et au bout de quelque minutes d'utilisation, j'ai un message d'erreur :

    svchost.exe - Erreur d'application

    L'instruction à "0x011cf496" emploie l'adresse mémoire "0x011cf496". La mémoire ne peut pas pas être "Written".

    Cliquez sur OK pour terminer le programme.
    Cliquez sur Annuler pour débloque le programme

    Si je clique sur OK, ça me bloque tout le PC. Et si je clique sur Annuler, ça ralentit le PC, le déconnecte du réseau et désactive le son.
    0
  10. Utilisateur anonyme
     
    Ce problème est lié à la gestion des adresses mémoire par mémoire.

    Les causes de ce problème peuvent être les suivantes :

    * 1. Problème matériel (défaillance d'une ou plusieurs barrettes mémoire)
    * 2. Problème lié à la mauvaise utilisation d'une ressource logicielle par une application ou par plusieurs applications lancées simultanément.
    * 3. Insuffisance de la mémoire vive (mémoire en quantité insuffisante et disque dur saturé empêchant la création d'un fichier swap (mémoire virtuelle).

    Vérifier le fonctionnement des barrettes mémoire

    Tester ses barrettes de RAM : https://www.commentcamarche.net/informatique/composants/1437-tester-la-memoire-vive-ram-d-un-ordinateur-avec-memtest86/

    Vérifier la configuration de Windows

    Si le problème survient lors de l'ouverture d'un dossier contenant de nombreux fichiers multimédias, le problème peut être lié à l'extraction par Windows des informations contenues dans les fichiers, ce qui provoque un fort ralentissement. Pour y remédier, il suffit de suivre la procédure suivante :
    Processeur utilisé à 100%: https://www.commentcamarche.net/faq/896-windows-xp-explorer-exe-utilise-le-cpu-a-99-ou-100

    Si le problème survient lors de l'exécution d'une application spécifique, essayez de la désinstaller et de la réinstaller.
    Nettoyer le disque dur

    Supprimer au maximum les fichiers inutiles du disque dur (notamment le dossier "Temporary Internet Files") et libérez la mémoire en arrêtant les processus (applications fonctionnant en arrière-plan) non nécessaires.
    Vider le cache Internet; https://www.commentcamarche.net/faq/3037-vider-le-cache-du-navigateur-chrome-firefox-safari-et-ie

    0
Précédent
  • 1
  • 2