Rapport svp regarder

Résolu
Bonjour,
Voila un rapport pouvez vous me dire si il y'la des virus:Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:42:35, on 09/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\LocalCooling\localcooling.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [LocalCooling] "C:\Program Files\LocalCooling\localcooling.exe" -s
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - AppInit_DLLs:
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 6350 bytes
Configuration: Windows XP
Firefox 2.0.0.11

18 réponses

Résumé de la discussion

Identification d'un éventuel virus à partir d'un log HijackThis et de la crainte d'infections sur Windows XP SP2 est discutée, le fichier listant de nombreuses entrées et programmes en fonctionnement. Plusieurs réponses suggèrent que les détections pourraient être des faux positifs et recommandent des scans en ligne avec des outils variés tels que Panda, Bitdefender ou Kaspersky pour confirmer l'absence d'infection. En parallèle, certains répondants évoquent des alertes similaires avec Avira ou d'autres suites et préconisent la comparaison des rapports afin d'éviter de tirer des conclusions hâtives. Une nuance utile est qu'aucun virus n'est effectivement confirmé dans le fil, et l'échange met surtout en évidence l'importance de croiser plusieurs analyses et de tenir compte des faux positifs.

Bobot (l’IA à votre service)
  1. Bonne année !

    Non, je ne crois pas qu'il y est des virus
    0
    1. Salut,

      Jette un oeil là-dessus : http://www.hijackthis.de/fr
      Tu devrais avoir quelques informations sur ton rapport HJT
      0
      1. Re,

        rien de suspect dans ton rapport.

        * Ouvre Hijackthis, choisis "do a scan only"

        Coche la case devant les lignes:
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O20 - AppInit_DLLs:
        

        Ferme toutes les autres fenêtres actives et clique sur "Fix checked"

        * Tu peux faire une analyse BitDefender: https://www.bitdefender.fr/

        (bouton "BitDefender scan online" en bas de la colonne gauche)

        et poster le rapport pour vérification.
        0
        1. Quand j'ai fais ce que tu ma dit mon pare-feu comodo c'est desactiver et j'ai perdu tout connection,en redemarant tout seula est revenu ,pour le rappoer enfiate j'ai eu des trjan a 13h aujord'hui mais merci pour tout
          0
          1. Avira ma detecter comme quoi j'ai un trojan venant de ton site
            0
            1. J'avais pas vu ça ... un trojan qui viens de Panda ? ah non surement pas!

              Mais bcp d'outils de sécu sont détectés comme faux-positifs, faut pas t'inquiéter pour ça ;o)
              0
          2. Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 20:23:05, on 09/01/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
            C:\windows\system\hpsysdrv.exe
            C:\WINDOWS\ALCXMNTR.EXE
            C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
            C:\Program Files\LocalCooling\localcooling.exe
            C:\HP\KBD\KBD.EXE
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\Comodo\Firewall\CPF.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\WINDOWS\system32\cisvc.exe
            C:\Program Files\Comodo\Firewall\cmdagent.exe
            C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
            C:\WINDOWS\system32\PnkBstrA.exe
            C:\WINDOWS\system32\PnkBstrB.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\WINDOWS\system32\cidaemon.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            c:\program files\avira\antivir personaledition classic\avscan.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
            O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
            O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
            O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
            O4 - HKLM\..\Run: [LocalCooling] "C:\Program Files\LocalCooling\localcooling.exe" -s
            O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
            O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
            O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
            O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
            O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
            0
            1. Fais un scan avec Antivir et poste le rapport stp.
              0
              1. Voila le rapport j'espere que tu poura m'aidé !! rapport Antivir:

                AntiVir PersonalEdition Classic
                Report file date: mercredi 9 janvier 2008 20:12

                Scanning for 1018140 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Username: HP_Propriétaire
                Computer name: NOM-EB85C523610

                Version information:
                BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 19:21:34
                ANTIVIR2.VDF : 7.0.1.205 620544 Bytes 08/01/2008 11:45:24
                ANTIVIR3.VDF : 7.0.1.211 23040 Bytes 09/01/2008 11:45:24
                AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 22/12/2007 12:01:32
                AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                AVPACK32.DLL : 7.6.0.2 360488 Bytes 22/12/2007 12:01:32
                AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                Configuration settings for the scan:
                Jobname..........................: Local Hard Disks
                Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: D:,
                Scan memory......................: on
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: All files
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
                Macro heuristic..................: on
                File heuristic...................: high
                Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

                Start of the scan: mercredi 9 janvier 2008 20:12

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
                Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
                Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                Scan process 'firefox.exe' - '1' Module(s) have been scanned
                Scan process 'cidaemon.exe' - '1' Module(s) have been scanned
                Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'PnkBstrB.exe' - '1' Module(s) have been scanned
                Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
                Scan process 'HPZIPM12.EXE' - '1' Module(s) have been scanned
                Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
                Scan process 'nTuneService.exe' - '1' Module(s) have been scanned
                Scan process 'cmdagent.exe' - '0' Module(s) have been scanned
                Scan process 'cisvc.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                Scan process 'cpf.exe' - '0' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                Scan process 'kbd.exe' - '1' Module(s) have been scanned
                Scan process 'localcooling.exe' - '1' Module(s) have been scanned
                Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                Scan process 'ALCXMNTR.EXE' - '1' Module(s) have been scanned
                Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
                Scan process 'jusched.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                40 processes with 40 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [NOTE] No virus was found!
                Boot sector 'D:\'
                [NOTE] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '29' files ).

                Starting the file scan:

                Begin scan in 'C:\' <HP_PAVILION>
                C:\hiberfil.sys
                [WARNING] The file could not be opened!
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\hp\bin\KillIt.exe
                [DETECTION] Contains detection pattern of the application APPL/KillApp.A
                [INFO] The file was moved to '47f11d73.qua'!
                C:\hp\bin\KillWind.exe
                [DETECTION] Contains detection pattern of the application APPL/KillApplicat.A
                [INFO] The file was moved to '468d51ac.qua'!
                C:\Program Files\Microsoft Works\WkMerge.dll
                [WARNING] The file could not be opened!
                Begin scan in 'D:\' <HP_RECOVERY>

                End of the scan: mercredi 9 janvier 2008 21:25
                Used time: 1:13:21 min

                The scan has been done completely.

                5451 Scanning directories
                418804 Files were scanned
                2 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                2 files were moved to quarantine
                0 files were renamed
                3 Files cannot be scanned
                418802 Files not concerned
                14873 Archives were scanned
                3 Warnings
                0 Notes

                Je reviens demain,rn esperant que ta une solution merci pour ton aide a demain :)
                0
                1. Salut !

                  Ton log HiJackThis est clean.

                  Quant à C:\hp\bin\KillIt.exe et C:\hp\bin\KillWind.exe, ils semblent être des faux-positifs.

                  As-tu encore des soucis ?
                  0
                  1. Slt Pi_Xi !!!!
                    Oui,mais c'est que c'est écrit que c'est un trojan,mon pc commence a ramé Je trouve.
                    0
                    1. et c'est quoi le trojan en question ?

                      Dans ton rapport Antivir, il n'y a pas de trojan !!

                      Fais le scan Panda nanoscan comme demandé plus haut si tu pense avoir un trojan !
                      0
                  2. Mais quand j'ai l'analyse il ma ecrit trojan:https://www.hiboox.com
                    Quans je faiseais delete il revenait tout le temp et puis mon logiciel CcLEANER a ete infecter ma ma mit ben le logiciel Ccleaner trojan Agent.... infecter j'ai fais surpimer le logiciel il ma mit recherche en cour
                    0
                  3. Ok ben pour le logiciel ccleanr pk sa fais sa ?
                    0
                    1. sans doute (une fois de plus!) car beaucoup d'outils de sécu sont détectés positifs par les AV !

                      J'attends le rapport ...
                      0
                  4. Je dois partir en cours a ce soir
                    0
                    1. Le scan n'a rien détecté donc je pence que c'est bon ofaite c'est quoi des faux positif?
                      0
                      1. Des faux-positifs, ce sont des fichiers qui sont détectés par les anti-virus comme vérolés alors qu'ils ne le sont pas.

                        C'est comme dans le cadre des contrôles anti-dopage, certains produits sont detectés positifs alors qu'ils ne le sont pas.

                        Ou encore, pour rester dans le domaine de l'informatique, dans le cadre de la lutte contre les spams, certains mails légitimes sont bloqués à tort.
                        0
                    2. Ok merci beaucoup ++ (dsl du retard)
                      0