Prescan a l'air bloque pendant desinfection
Résolu
desperateml
Messages postés
31
Date d'inscription
Statut
Membre
Dernière intervention
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
mon pc est infecte par system restore. j'ai lance prescan mais il a l'air bloque : ca fait 10 min que les fenetres noire s'ouvrent sans discontinuer mais que la petite fenetre d'avancement ne bouge plus. que dois je faire ?
ma config : pc sous windows xp a jour / ie 8
mon pc est infecte par system restore. j'ai lance prescan mais il a l'air bloque : ca fait 10 min que les fenetres noire s'ouvrent sans discontinuer mais que la petite fenetre d'avancement ne bouge plus. que dois je faire ?
ma config : pc sous windows xp a jour / ie 8
A voir également:
- Prescan a l'air bloque pendant desinfection
- Adobe air - Télécharger - Édition & Programmation
- Code puk bloqué - Guide
- Téléphone bloqué code verrouillage - Guide
- Pavé tactile bloqué - Guide
- Compte gmail bloqué - Guide
43 réponses
__________________________________________________
=>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
=>il est fort déconseillé de le transposer sur un autre ordinateur !<=
----------------------------------------------------------------------------
Toujours avec toutes les protections désactivées, fais ceci :
▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :
----------------------------------------------------------
KillAll::
Folder::
c:\documents and settings\All Users\Application Data\Ask
------------------------------------------------------------------
▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
▶ Quitte le Bloc Notes
▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix
▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt
Voilà (enfin) le rapport combofix. Merci !
ComboFix 11-11-23.03 - Marie-Lise 24/11/2011 7:44.3.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1518 [GMT 1:00]
Lancé depuis: c:\documents and settings\Marie-Lise\Bureau\desperateml.exe
Commutateurs utilisés :: c:\documents and settings\Marie-Lise\Bureau\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Free Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Ask
c:\windows\TEMP\logishrd\LVPrcInj01.dll
E:\Autorun.inf
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-10-24 au 2011-11-24 ))))))))))))))))))))))))))))))))))))
.
.
2011-11-23 13:15 . 2010-10-23 05:48 398704 ----a-w- c:\windows\system32\dsNcSmartCardProv.dll
2011-11-23 13:15 . 2010-10-23 05:48 345456 ----a-w- c:\windows\system32\dsNcCredProv.dll
2011-11-23 13:14 . 2011-11-23 13:15 -------- d-----w- c:\program files\Juniper Networks
2011-11-23 13:11 . 2011-11-23 13:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Juniper Networks
2011-11-23 13:11 . 2011-11-23 13:15 -------- d-----w- c:\documents and settings\Marie-Lise\Application Data\Juniper Networks
2011-11-15 22:16 . 2011-11-15 22:16 -------- d-----w- c:\documents and settings\Marie-Lise\Application Data\CheckPoint
2011-11-15 22:15 . 2011-11-15 22:15 -------- d-----w- c:\documents and settings\All Users\Application Data\CheckPoint
2011-11-15 22:15 . 2011-11-15 22:16 -------- d-----w- c:\program files\CheckPoint
2011-11-05 06:52 . 2011-11-05 06:52 -------- d-----r- c:\program files\Skype
2011-11-05 06:45 . 2011-10-03 04:06 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-02 13:05 . 2011-11-15 21:48 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-11-02 12:50 . 2011-11-15 21:39 -------- d-----w- C:\ZHP
2011-11-02 12:50 . 2011-11-15 21:47 -------- d-----w- c:\program files\ZHPDiag
2011-10-31 15:31 . 2011-11-15 22:01 -------- d-----w- c:\documents and settings\Marie-Lise\Application Data\QuickScan
2011-10-31 13:47 . 2011-11-15 20:31 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2011-10-31 13:12 . 2011-10-31 13:14 -------- d-----w- C:\Kill'em
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-24 18:57 . 2011-10-24 18:57 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:23 . 2006-03-31 11:22 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 01:37 . 2007-06-05 18:31 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2004-08-05 12:00 606208 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 17:59 614400 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2004-08-05 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2004-08-05 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-06 14:10 . 2004-08-05 12:00 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-08-30 21:05 . 2011-08-30 21:05 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-08-30 21:05 . 2011-08-30 21:05 73064 ----a-w- c:\windows\system32\dnssd.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-16_17.40.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-24 07:01 . 2011-11-24 07:01 16384 c:\windows\Temp\Perflib_Perfdata_540.dat
+ 2011-06-11 00:58 . 2011-06-11 00:58 51024 c:\windows\system32\vcomp100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 51024 c:\windows\system32\vcomp100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 81744 c:\windows\system32\mfcm100u.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 81744 c:\windows\system32\mfcm100u.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 81744 c:\windows\system32\mfcm100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 81744 c:\windows\system32\mfcm100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 60752 c:\windows\system32\mfc100rus.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 60752 c:\windows\system32\mfc100rus.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 43344 c:\windows\system32\mfc100kor.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 43344 c:\windows\system32\mfc100kor.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 43856 c:\windows\system32\mfc100jpn.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 64336 c:\windows\system32\mfc100fra.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 64336 c:\windows\system32\mfc100fra.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 63824 c:\windows\system32\mfc100esn.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 63824 c:\windows\system32\mfc100esn.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 55120 c:\windows\system32\mfc100enu.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 55120 c:\windows\system32\mfc100enu.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 64336 c:\windows\system32\mfc100deu.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 64336 c:\windows\system32\mfc100deu.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 36176 c:\windows\system32\mfc100cht.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 36176 c:\windows\system32\mfc100cht.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 36176 c:\windows\system32\mfc100chs.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 36176 c:\windows\system32\mfc100chs.dll
+ 2010-10-23 05:24 . 2010-10-23 05:24 26624 c:\windows\system32\drivers\dsNcAdpt.sys
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ARPPRODUCTICON.exe
+ 2010-10-22 14:20 . 2010-10-22 14:20 42896 c:\windows\Downloaded Program Files\JuniperSetupClientCtrlUninstaller.exe
- 2011-02-18 23:40 . 2011-02-18 23:40 773968 c:\windows\system32\msvcr100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 773968 c:\windows\system32\msvcr100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 421200 c:\windows\system32\msvcp100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 421200 c:\windows\system32\msvcp100.dll
+ 2010-10-23 05:44 . 2010-10-23 05:44 225280 c:\windows\system32\dsGinaLoader.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 138056 c:\windows\system32\atl100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 138056 c:\windows\system32\atl100.dll
+ 2010-10-22 14:20 . 2010-10-22 14:20 402800 c:\windows\Downloaded Program Files\JuniperExt.exe
+ 2011-06-11 00:58 . 2011-06-11 00:58 4422992 c:\windows\system32\mfc100u.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 4422992 c:\windows\system32\mfc100u.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 4397384 c:\windows\system32\mfc100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 4397384 c:\windows\system32\mfc100.dll
+ 2011-11-19 06:47 . 2011-11-19 06:47 1435136 c:\windows\Installer\25139dd.msi
+ 2011-06-28 20:27 . 2011-06-28 20:27 4028928 c:\windows\Installer\1b8a3eb.msp
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 49152]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"SoundMan"="SOUNDMAN.EXE" [2005-10-04 90112]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-10-19 738944]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-10-26 73360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-4-5 434176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 16:00 449608 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\jeux\\BF2.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\jeux\\game.dat"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Call of Duty\\CoDMP.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Fichiers communs\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 eusk2par;Aladdin SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [03/08/2006 06:49 25680]
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [11/04/2006 07:52 120320]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [29/11/2009 08:12 136360]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [19/10/2011 11:18 27016]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [19/10/2011 11:18 497280]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/01/2010 06:54 135664]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [28/02/2011 16:52 366152]
S3 eusk3usb;SmartKey 3 USB;c:\windows\system32\drivers\eusk3usb.sys [03/08/2006 06:49 43968]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\drivers\fbxusb32.sys [20/10/2004 13:23 21344]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27/01/2010 06:54 135664]
S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys --> c:\windows\system32\drivers\mbam.sys [?]
S3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [31/10/2011 14:47 111872]
.
Contenu du dossier 'Tâches planifiées'
.
2011-11-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:57]
.
2011-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-27 05:54]
.
2011-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-27 05:54]
.
2011-11-23 c:\windows\Tasks\User_Feed_Synchronization-{F4E7C958-F5A4-41C8-84E5-B60E4F2540B7}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 212.27.40.241 212.27.40.240
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20100924015958
DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} - hxxps://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
DPF: {BF3CD111-6278-11D2-9EA3-00A0C9251384} - hxxp://www.o2c.de/download/O2CPlayer.CAB
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-24 09:40
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
.
c:\docume~1\MARIE-~1\LOCALS~1\Temp\EFValdation.INI
.
Scan terminé avec succès
Fichiers cachés: 1
.
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø*€|ÿÿÿÿ*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(944)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(1000)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'explorer.exe'(7880)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\SOUNDMAN.EXE
c:\program files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
c:\program files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Heure de fin: 2011-11-24 09:48:47 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-11-24 08:48
ComboFix2.txt 2011-11-16 17:46
.
Avant-CF: 53 510 635 520 octets libres
Après-CF: 53 602 742 272 octets libres
.
- - End Of File - - 7E4C4241877D8BF951B1CB3D5E44F3FF
ComboFix 11-11-23.03 - Marie-Lise 24/11/2011 7:44.3.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1518 [GMT 1:00]
Lancé depuis: c:\documents and settings\Marie-Lise\Bureau\desperateml.exe
Commutateurs utilisés :: c:\documents and settings\Marie-Lise\Bureau\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Free Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Ask
c:\windows\TEMP\logishrd\LVPrcInj01.dll
E:\Autorun.inf
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-10-24 au 2011-11-24 ))))))))))))))))))))))))))))))))))))
.
.
2011-11-23 13:15 . 2010-10-23 05:48 398704 ----a-w- c:\windows\system32\dsNcSmartCardProv.dll
2011-11-23 13:15 . 2010-10-23 05:48 345456 ----a-w- c:\windows\system32\dsNcCredProv.dll
2011-11-23 13:14 . 2011-11-23 13:15 -------- d-----w- c:\program files\Juniper Networks
2011-11-23 13:11 . 2011-11-23 13:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Juniper Networks
2011-11-23 13:11 . 2011-11-23 13:15 -------- d-----w- c:\documents and settings\Marie-Lise\Application Data\Juniper Networks
2011-11-15 22:16 . 2011-11-15 22:16 -------- d-----w- c:\documents and settings\Marie-Lise\Application Data\CheckPoint
2011-11-15 22:15 . 2011-11-15 22:15 -------- d-----w- c:\documents and settings\All Users\Application Data\CheckPoint
2011-11-15 22:15 . 2011-11-15 22:16 -------- d-----w- c:\program files\CheckPoint
2011-11-05 06:52 . 2011-11-05 06:52 -------- d-----r- c:\program files\Skype
2011-11-05 06:45 . 2011-10-03 04:06 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-02 13:05 . 2011-11-15 21:48 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-11-02 12:50 . 2011-11-15 21:39 -------- d-----w- C:\ZHP
2011-11-02 12:50 . 2011-11-15 21:47 -------- d-----w- c:\program files\ZHPDiag
2011-10-31 15:31 . 2011-11-15 22:01 -------- d-----w- c:\documents and settings\Marie-Lise\Application Data\QuickScan
2011-10-31 13:47 . 2011-11-15 20:31 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2011-10-31 13:12 . 2011-10-31 13:14 -------- d-----w- C:\Kill'em
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-24 18:57 . 2011-10-24 18:57 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:23 . 2006-03-31 11:22 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 01:37 . 2007-06-05 18:31 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2004-08-05 12:00 606208 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 17:59 614400 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2004-08-05 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2004-08-05 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-06 14:10 . 2004-08-05 12:00 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-08-30 21:05 . 2011-08-30 21:05 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-08-30 21:05 . 2011-08-30 21:05 73064 ----a-w- c:\windows\system32\dnssd.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-16_17.40.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-24 07:01 . 2011-11-24 07:01 16384 c:\windows\Temp\Perflib_Perfdata_540.dat
+ 2011-06-11 00:58 . 2011-06-11 00:58 51024 c:\windows\system32\vcomp100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 51024 c:\windows\system32\vcomp100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 81744 c:\windows\system32\mfcm100u.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 81744 c:\windows\system32\mfcm100u.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 81744 c:\windows\system32\mfcm100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 81744 c:\windows\system32\mfcm100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 60752 c:\windows\system32\mfc100rus.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 60752 c:\windows\system32\mfc100rus.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 43344 c:\windows\system32\mfc100kor.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 43344 c:\windows\system32\mfc100kor.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 43856 c:\windows\system32\mfc100jpn.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 64336 c:\windows\system32\mfc100fra.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 64336 c:\windows\system32\mfc100fra.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 63824 c:\windows\system32\mfc100esn.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 63824 c:\windows\system32\mfc100esn.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 55120 c:\windows\system32\mfc100enu.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 55120 c:\windows\system32\mfc100enu.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 64336 c:\windows\system32\mfc100deu.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 64336 c:\windows\system32\mfc100deu.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 36176 c:\windows\system32\mfc100cht.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 36176 c:\windows\system32\mfc100cht.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 36176 c:\windows\system32\mfc100chs.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 36176 c:\windows\system32\mfc100chs.dll
+ 2010-10-23 05:24 . 2010-10-23 05:24 26624 c:\windows\system32\drivers\dsNcAdpt.sys
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-11-19 06:47 . 2011-11-19 06:47 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ARPPRODUCTICON.exe
+ 2010-10-22 14:20 . 2010-10-22 14:20 42896 c:\windows\Downloaded Program Files\JuniperSetupClientCtrlUninstaller.exe
- 2011-02-18 23:40 . 2011-02-18 23:40 773968 c:\windows\system32\msvcr100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 773968 c:\windows\system32\msvcr100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 421200 c:\windows\system32\msvcp100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 421200 c:\windows\system32\msvcp100.dll
+ 2010-10-23 05:44 . 2010-10-23 05:44 225280 c:\windows\system32\dsGinaLoader.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 138056 c:\windows\system32\atl100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 138056 c:\windows\system32\atl100.dll
+ 2010-10-22 14:20 . 2010-10-22 14:20 402800 c:\windows\Downloaded Program Files\JuniperExt.exe
+ 2011-06-11 00:58 . 2011-06-11 00:58 4422992 c:\windows\system32\mfc100u.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 4422992 c:\windows\system32\mfc100u.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 4397384 c:\windows\system32\mfc100.dll
- 2011-02-19 22:03 . 2011-02-19 22:03 4397384 c:\windows\system32\mfc100.dll
+ 2011-11-19 06:47 . 2011-11-19 06:47 1435136 c:\windows\Installer\25139dd.msi
+ 2011-06-28 20:27 . 2011-06-28 20:27 4028928 c:\windows\Installer\1b8a3eb.msp
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 49152]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"SoundMan"="SOUNDMAN.EXE" [2005-10-04 90112]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-10-19 738944]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-10-26 73360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-4-5 434176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 16:00 449608 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\jeux\\BF2.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\jeux\\game.dat"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Call of Duty\\CoDMP.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Fichiers communs\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 eusk2par;Aladdin SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [03/08/2006 06:49 25680]
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [11/04/2006 07:52 120320]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [29/11/2009 08:12 136360]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [19/10/2011 11:18 27016]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [19/10/2011 11:18 497280]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/01/2010 06:54 135664]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [28/02/2011 16:52 366152]
S3 eusk3usb;SmartKey 3 USB;c:\windows\system32\drivers\eusk3usb.sys [03/08/2006 06:49 43968]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\drivers\fbxusb32.sys [20/10/2004 13:23 21344]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27/01/2010 06:54 135664]
S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys --> c:\windows\system32\drivers\mbam.sys [?]
S3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [31/10/2011 14:47 111872]
.
Contenu du dossier 'Tâches planifiées'
.
2011-11-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:57]
.
2011-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-27 05:54]
.
2011-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-27 05:54]
.
2011-11-23 c:\windows\Tasks\User_Feed_Synchronization-{F4E7C958-F5A4-41C8-84E5-B60E4F2540B7}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 212.27.40.241 212.27.40.240
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20100924015958
DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} - hxxps://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
DPF: {BF3CD111-6278-11D2-9EA3-00A0C9251384} - hxxp://www.o2c.de/download/O2CPlayer.CAB
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-24 09:40
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
.
c:\docume~1\MARIE-~1\LOCALS~1\Temp\EFValdation.INI
.
Scan terminé avec succès
Fichiers cachés: 1
.
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø*€|ÿÿÿÿ*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(944)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(1000)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'explorer.exe'(7880)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\SOUNDMAN.EXE
c:\program files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
c:\program files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Heure de fin: 2011-11-24 09:48:47 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-11-24 08:48
ComboFix2.txt 2011-11-16 17:46
.
Avant-CF: 53 510 635 520 octets libres
Après-CF: 53 602 742 272 octets libres
.
- - End Of File - - 7E4C4241877D8BF951B1CB3D5E44F3FF