Faux positif ou pas ??

Bonjour,voila je vien de faire un scan avec mon anti-virus et mes 2 anti-spyware et a-squared Anti-Malware
a detecté un malware que j'ai mi en quarentaine .Mais que ni mon anti-virus (norton) ni mon deuxieme anti-spyware (super anti spyware) n'on detecter ?je pense qu'il s'agit d'un faux postif mais je voudrais etre sur avant de relacher se soi disant virus dans mon pc .

AIDEZ MOI SVP

je poste ci dessous le rapport a-squared
Version - a-squared Anti-Malware 4.5
Dernière mise à jour : 24/06/2009 15:25:03

Paramètres des balayages :

Type de numérisation : Scan Détail
Éléments : Mémoire, Traces, Cookies, C:\, E:\
Balaye dans les archives : Marche
Analyse heuristique : Arrêt
Balaye dans les ADS : Marche

Début du balayage : 24/06/2009 15:47:55

C:\Utilisateurs\enfant\AppData\Local\Mozilla\Firefox\Profiles\p9fjv3as.default\Cache\E92913C6d01 Objets détectés : SWF.Downloader!IK

Analysé

Fichiers : 324824
Traces : 565034
Cookies : 3
Processus : 56

Objets trouvés

Fichiers : 1
Traces : 0
Cookies : 0
Processus : 0
Clés de Registre : 0

Fin du balayage : 24/06/2009 21:12:13
Temps du balayage : 5:24:18

--
avast ? mieux vaut pas connaitre
Configuration: Windows Vista Internet Explorer 7.0

6 réponses

  1. y a quelqun pour m'aidez ??
    0
    1. télécharge hijackthis http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
      >> enregistre la cible sous .... "le bureau" renomme HJTInstall.exe en par exemple HJT.exe

      >> Fais un double-clic sur "HJT.exe" afin de lancer l'installation

      >> Clique sur Install ensuite sur "I Accept"

      >> Clique sur" Do a scan system and save log file"

      >> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse

      http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
      0
      1. merci de m'aider voila le rapport

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 17:48:40, on 25/06/2009
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
        Boot mode: Normal

        Running processes:
        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        E:\Program Files\a-squared Anti-Malware\a2service.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
        C:\Windows\system32\TODDSrv.exe
        C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
        C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
        C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\DRIVERS\xaudio.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\System32\igfxpers.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Windows\RtHDVCpl.exe
        C:\Windows\System32\wpcumi.exe
        E:\Program Files\Spamihilator\spamihilator.exe
        C:\Program Files\QuickTime\QTTask.exe
        E:\Program Files\Unlocker\UnlockerAssistant.exe
        E:\Program Files\a-squared Anti-Malware\a2guard.exe
        C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
        C:\Program Files\RocketDock\RocketDock.exe
        C:\Windows\ehome\ehtray.exe
        E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\Mozilla Firefox 3.5 Beta 4\firefox.exe
        C:\Windows\system32\igfxext.exe
        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
        C:\Program Files\MSN Messenger\usnsvc.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.0.0.134\coIEPlg.dll
        O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.0.0.134\IPSBHO.DLL
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.134\coIEPlg.dll
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
        O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
        O4 - HKLM\..\Run: [Spamihilator] "E:\Program Files\Spamihilator\spamihilator.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [UnlockerAssistant] "E:\Program Files\Unlocker\UnlockerAssistant.exe"
        O4 - HKLM\..\Run: [a-squared] "E:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2guard.exe" /d=60
        O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
        O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [SUPERAntiSpyware] E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - Global Startup: Redémarrer les cartes Flash.lnk = C:\Program Files\TOSHIBA\FlashCards\TfcRst.exe
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
        O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
        O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.0.0.134\coIEPlg.dll
        O20 - Winlogon Notify: !SASWinLogon - E:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - E:\Program Files\a-squared Anti-Malware\a2service.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
        O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
        O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
        O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
        O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
        0
        1. Alors, personne ?
          0
          1. je ne vois rien
            de toute facon ca n'a pas l'air bien grave
            c'est dans le cache de firefox
            donc tu peu toujours supprimer
            mais ce n'est pas un faux positif
            0