Ordinateur instable

sunshine -  
moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour,

Mon ordi est instable, antivir est toujours en alerte, internet rame, j'ai fais un scan hijackthis, le rapport est le suivant:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:45:04, on 25/09/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\WINDOW~4\MESSEN~1\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\PROGRA~1\WINDOW~4\MESSEN~1\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 5763 bytes

En vous remerciant d'avance. ;)

24 réponses

  • 1
  • 2
  1. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    bonjour

    et que te dit-il antivir ,

    as tu un rapport stp

    de plus

    Télécharge ZHPDiag ( de Nicolas coolman ).
    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

    Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

    Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin ( vista )

    Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

    Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

    ensuite

    Rend toi sur Cjoint : http://www.cijoint.fr/

    Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

    Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

    Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

    pour t'aider sur ci joijnt : https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
    0
  2. sunshine
     
    Merci je vais executer les ordres et voici le rapport avast de ses alertes depuis une semaine:

    Evénements exportés :

    25/09/2010 18:08 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    24/09/2010 20:03 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 19:08 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 19:08 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 19:08 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 19:08 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 19:08 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 19:08 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 19:08 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 18:46 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\Documents and Settings\Compaq_Propriétaire\Mes
    documents\Mes
    logiciels\Windows.Genuine.Advantage.Validation.v1.8.32.0.CRACKED.JiNo22\WgaTray.
    exe'
    un virus ou un programme indésirable 'TR/Patched.IV.66' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 18:46 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\Documents and Settings\Compaq_Propriétaire\Mes
    documents\Mes
    logiciels\Windows.Genuine.Advantage.Validation.v1.8.32.0.CRACKED.JiNo22\WgaTray.
    exe'
    un virus ou un programme indésirable 'TR/Patched.IV.66' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 18:38 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\Documents and Settings\Compaq_Propriétaire\Bureau\Dossier
    AK\Windows.Genuine.Advantage.Validation.v1.8.32.0.CRACKED.JiNo22\WgaTray.exe'
    un virus ou un programme indésirable 'TR/Patched.IV.66' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 18:37 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\Documents and Settings\Compaq_Propriétaire\Bureau\Dossier
    AK\Windows.Genuine.Advantage.Validation.v1.8.32.0.CRACKED.JiNo22\WgaTray.exe'
    un virus ou un programme indésirable 'TR/Patched.IV.66' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 18:17 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\Documents and Settings\Compaq_Propriétaire\Application
    Data\Thinstall\Photodex Presenter\1000000b00002i\rundll32.exe'
    un virus ou un programme indésirable 'TR/Horse.JEO' [trojan] a été détecté.
    Action exécutée : Autoriser l'accès

    22/09/2010 18:17 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    22/09/2010 17:51 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    20/09/2010 19:38 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    19/09/2010 21:01 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    19/09/2010 20:20 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    19/09/2010 17:33 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    18/09/2010 20:09 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès
    0
  3. sunshine
     
    Evénements exportés :

    16/09/2010 21:28 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    16/09/2010 20:29 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    16/09/2010 19:42 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    16/09/2010 18:28 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    16/09/2010 18:20 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    16/09/2010 09:12 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    16/09/2010 08:54 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    15/09/2010 18:50 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    15/09/2010 17:50 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    15/09/2010 17:16 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    14/09/2010 21:44 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    14/09/2010 20:43 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    14/09/2010 19:48 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    13/09/2010 22:39 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    13/09/2010 19:59 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    13/09/2010 13:21 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    13/09/2010 13:09 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    13/09/2010 11:38 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    13/09/2010 10:04 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    12/09/2010 20:11 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    12/09/2010 18:44 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    12/09/2010 18:04 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    12/09/2010 15:12 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    12/09/2010 13:17 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    11/09/2010 20:19 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    11/09/2010 19:41 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    11/09/2010 18:30 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    11/09/2010 13:08 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    11/09/2010 11:50 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    11/09/2010 09:45 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    10/09/2010 20:29 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    10/09/2010 20:02 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    09/09/2010 20:54 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\System Volume
    Information\_restore{88F0EC16-5093-454D-BD2D-4DD02919E000}\RP252\A0029151.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    08/09/2010 20:28 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\Documents and Settings\Compaq_Propriétaire\Application
    Data\Thinstall\Photodex Presenter\1000000b00002i\rundll32.exe'
    un virus ou un programme indésirable 'TR/Horse.JEO' [trojan] a été détecté.
    Action exécutée : Refuser l'accès

    08/09/2010 20:28 [Guard] Logiciel malveillant détecté
    Dans le fichier 'C:\Documents and Settings\Compaq_Propriétaire\Application
    Data\Thinstall\Photodex Presenter\1000000500002i\hh.exe'
    un virus ou un programme indésirable 'TR/Horse.IGM' [trojan] a été détecté.
    Action exécutée : Supprimer le fichier
    0
  4. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    ok

    vu

    jusque là c'est facile

    ce n'est que la restauration systeme qui est infectée et la présence de tes cracks !!!

    à voir avec zhp s'il traine autre chose
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. sunshine
     
    Le ZHP beug, car il bloque à 80 pourcent et plus precisement au moment de la recherche master boot record infection. :/ Comment se fait il?
    0
    1. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
       
      attendre un peu...
      0
  7. sunshine
     
    Ca va faire une bonne dizaine de minute qu'il reste à 80.
    0
  8. sunshine
     
    Re, meme en mode sans echec il s'arrete à 80 pourcent à mbr check, je sais pas ce qu'il ya :/.
    0
  9. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    Attention, avant de commencer, lit attentivement la procédure, et imprime la

    Aide à l'utilisation
    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

    Télécharge ComboFix de sUBs que tu renommes SUN.exe avant de l'enregistrer sur ton Bureau :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    /!\ Déconnecte-toi du net et <gras>DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\ </gras>

    ---> Double-clique sur ComboFix.exe
    Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

    SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
    (si il te propose de l'installer remets internet)

    ---> Mets-le en langue française F
    Tape sur la touche 1 (Yes) pour démarrer le scan.

    Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

    Note : Le rapport se trouve également là : C:\ComboFix.txt

    0
  10. sunshine
     
    Bonjour merci pour ton aide ;) voici le rapport:

    http://www.cijoint.fr/cjlink.php?file=cj201009/cijJXl88IW.txt

    :)
    0
  11. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    bonjour

    rien avec combo

    retente zhp et s'il coince encore

    * Télécharge Random's System Information Tool (RSIT) de Random/Random.

    (outil de diagnostic)

    http://images.malwareremoval.com/random/RSIT.exe

    * Enregistre le sur ton Bureau.

    * Double clique sur RSIT.exe pour lancer l'outil.

    * Clique sur "Continue" à l'écran Disclaimer.

    * Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    * Une fois le scan terminé, deux rapports vont apparaître

    Rend toi sur Cjoint : http://www.cijoint.fr/

    Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

    Sélectionne chaque rapport

    Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

    Les rapports se trouvent à cet endroit:
    C:\rsit\info.txt
    C:\rsit\log.txt
    0
  12. sunshine
     
    Merci, voici les rapports:

    http://www.cijoint.fr/cjlink.php?file=cj201009/cijCyRUwZy.txt

    http://www.cijoint.fr/cjlink.php?file=cj201009/cijfeSfHXD.txt

    j'ai toujours le meme soucis avec zhp. :/
    0
  13. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    bizarre, rien par là non plus

    DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)

    Télécharge List_Kill'em et enregistre le sur ton bureau

    http://sd-4.archive-host.com/membres/up/829108531491024/Mes_Tools/List_Killem_Install.exe

    double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

    Laisse coché :

    Executer List_Kill'em"


    une fois terminée , clic sur "terminer" et le programme se lancera seul

    choisis l'option Search

    laisse travailler l'outil

    à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

    Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

    Rend toi sur Cjoint : http://www.cijoint.fr/

    Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

    Sélectionne le rapport C:\List'em.txt

    Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

    Même opération pour le rapport more.txt qui se trouve sur ton bureau

    si soucis avec ci joint. fr

    => utiliser https://www.cjoint.com/
    => utiliser http://ww38.toofiles.com/fr/oip/documents/txt/av.html

    0
  14. sunshine
     
    C'est combien pour la durée, car je vois checking MBR et ca m'a l'air bloqué depuis 30 minutes., c'est toujours un probleme avec MBR?
    0
  15. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    la version viens d'être modifiée

    desinstalle killem

    et retélécharge le

    puis même procédure
    0
  16. sunshine
     
    Merci, j'ai retenté et ca marche cette fois ci:

    http://www.cijoint.fr/cjlink.php?file=cj201009/cije6aYIOS.txt
    0
  17. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    toujours pas grand chose

    1)

    Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
    mais cette fois-ci :

    choisis l'option CLEAN
    ton PC va redemarrer,

    laisse travailler l'outil.

    en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

    colle le contenu dans ta reponse

    .....................

    2)

    fais un scan en ligne ici

    copie colle le rapport final

    http://www.kaspersky.com/kos/eng/partner/default/pages/default/check.html?n=1263916919335

    tuto pout t'aider

    https://www.commentcamarche.net/faq/17751-scanner-en-ligne-avec-kaspersky#analyse-de-l-ordinateur

    0
  18. sunshine
     
    J'ai fais l'option clean ca veut pas marcher, quand j'appuie on voit une fenetre noir qui apparait et qui disparait en meme pas une seconde.
    0
  19. sunshine
     
    Oui il ya effectivement un probleme il ne trouve pas le fichier listem bat.
    0
    1. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
       
      fais le scan en ligne
      0
  • 1
  • 2