Besoin d'aide Virus Win32

Bonjour,
Mon ordi est victime d'un virus : win32 small JMH.
Comment m'en débarasser ?
Merci pour votre aide
Configuration: Windows XP
Opera 9.25

9 réponses

  1. c'est pas un virus mais un trojan sur msn dénommé win32:Small-JMH.

    va sur ce site : http://bibou0007.com/scans-en-ligne-f75/tutorial-bitdefender-online-t390.htm

    l
    0
    1. Merci mais apparemment je ne peux pas télécharger. Voila ce qui est mis :

      Impossible de charger le scanner en ligne. Le Service Pack 2 a été détecté sur cet ordinateur. Cliquez sur la barre d'information et sélectionner 'Installer Contrôle ActiveX...'.Cliquez ici pour d'autres solutions possibles.
      --------------------------------------------------------------------------------
      0
    2. @papouC'est bon
      J'ai installé activeX et l'analyse a commencé.
      0
  2. tu as koi comme anti virus? il est a jours
    0
    1. C'est avast et il est a jour
      0
  3. oui je te conseil de le desinstaler et de mettre antivir
    0
    1. Voici le resultat de l'anlyse avec antivir :
      A virus or unwanted program was found
      C:System Volume Information\...\A0005711.com
      Is the trojan horse TR/Crypt.XPACK.Gen

      Choix proposés:
      move to quarantine
      delete
      rename
      access deny
      ignore
      0
      1. move to quarantine
        0
        1. ok mais c'est ce que j'avais deja fait avec avast et le virus etait toujours là
          Voila le scan complet par antivir :

          AntiVir PersonalEdition Classic
          Report file date: dimanche 13 avril 2008 13:39

          Scanning for 835736 virus strains and unwanted programs.

          Licensed to: Avira AntiVir PersonalEdition Classic
          Serial number: 0000149996-ADJIE-0001
          Platform: Windows XP
          Windows version: (Service Pack 2) [5.1.2600]
          Username: Eric BELIARD
          Computer name: PC-BUREAU

          Version information:
          BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
          AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
          AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
          LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
          LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
          ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 13:26:55
          ANTIVIR2.VDF : 7.0.0.1 2048 Bytes 13/09/2007 13:27:04
          ANTIVIR3.VDF : 7.0.0.2 2048 Bytes 13/09/2007 13:27:13
          AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 17/09/2007 16:43:56
          AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
          AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
          AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
          AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 07:46:00
          AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
          AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
          AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
          NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
          RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
          RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
          SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

          Configuration settings for the scan:
          Jobname..........................: Windows System Directory
          Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\setupprf.dat
          Logging..........................: low
          Primary action...................: interactive
          Secondary action.................: ignore
          Scan master boot sector..........: off
          Scan boot sector.................: on
          Boot sectors.....................: C:,
          Scan memory......................: on
          Process scan.....................: on
          Scan registry....................: on
          Search for rootkits..............: off
          Scan all files...................: Intelligent file selection
          Scan archives....................: on
          Recursion depth..................: 20
          Smart extensions.................: on
          Macro heuristic..................: on
          File heuristic...................: medium

          Start of the scan: dimanche 13 avril 2008 13:39

          The scan of running processes will be started
          Scan process 'avscan.exe' - '1' Module(s) have been scanned
          Scan process 'avgnt.exe' - '1' Module(s) have been scanned
          Scan process 'avguard.exe' - '1' Module(s) have been scanned
          Scan process 'sched.exe' - '1' Module(s) have been scanned
          Scan process 'rundll32.exe' - '1' Module(s) have been scanned
          Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
          Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
          Scan process 'Opera.exe' - '1' Module(s) have been scanned
          Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
          Scan process 'CLI.exe' - '1' Module(s) have been scanned
          Scan process 'CLI.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'skypePM.exe' - '1' Module(s) have been scanned
          Scan process 'alg.exe' - '1' Module(s) have been scanned
          Scan process 'ashWebSv.exe' - '1' Module(s) have been scanned
          Scan process 'ashMaiSv.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'slmdmsr.exe' - '1' Module(s) have been scanned
          Scan process 'soffice.bin' - '1' Module(s) have been scanned
          Scan process 'soffice.exe' - '1' Module(s) have been scanned
          Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
          Scan process 'Skype.exe' - '1' Module(s) have been scanned
          Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
          Scan process 'jusched.exe' - '1' Module(s) have been scanned
          Scan process 'CLI.exe' - '1' Module(s) have been scanned
          Scan process 'rundll32.exe' - '1' Module(s) have been scanned
          Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
          Scan process 'ashDisp.exe' - '1' Module(s) have been scanned
          Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
          Scan process 'explorer.exe' - '1' Module(s) have been scanned
          Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
          Scan process 'ashServ.exe' - '1' Module(s) have been scanned
          Scan process 'aswUpdSv.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
          Scan process 'lsass.exe' - '1' Module(s) have been scanned
          Scan process 'services.exe' - '1' Module(s) have been scanned
          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
          Scan process 'csrss.exe' - '1' Module(s) have been scanned
          Scan process 'smss.exe' - '1' Module(s) have been scanned
          44 processes with 44 modules were scanned

          Start scanning boot sectors:
          Boot sector 'C:\'
          [NOTE] No virus was found!

          Starting to scan the registry.
          C:\WINDOWS\system32\%%%.exe
          [WARNING] The file could not be opened!
          The registry was scanned ( '33' files ).

          Starting the file scan:

          Begin scan in 'C:\WINDOWS\system32'
          C:\WINDOWS\system32\%%%.exe
          [WARNING] The file could not be opened!

          End of the scan: dimanche 13 avril 2008 13:47
          Used time: 07:33 min

          The scan has been done completely.

          159 Scanning directories
          6307 Files were scanned
          0 viruses and/or unwanted programs were found
          0 Files were classified as suspicious:
          0 files were deleted
          0 files were repaired
          0 files were moved to quarantine
          0 files were renamed
          2 Files cannot be scanned
          6307 Files not concerned
          5 Archives were scanned
          2 Warnings
          0 Notes
          0
      2. Nettoyage avec CCleaner
        0
        1. Comment dois je faire ?
          0
      3. 0
        1. J'ai téléchargé et j'ai lancé le netoyage avec ccleaner.
          L'analyse avec bitdefender est en cours.
          Merci pour votre aide.
          Je terminerai plus tard je dois m'absenter
          0
        2. @papouBitDefender Online Scanner

          Rapport d'analyse généré à: Sun, Apr 13, 2008 - 14:11:34

          Voie d'analyse: A:\;C:\;D:\;

          Statistiques

          Temps
          00:57:30

          Fichiers
          128865

          Directoires
          4358

          Secteurs de boot
          2

          Archives
          711

          Paquets programmes
          9815

          Résultats

          Virus identifiés
          1

          Fichiers infectés
          1

          Fichiers suspects
          0

          Avertissements
          0

          Désinfectés
          0

          Fichiers effacés
          1

          Info sur les moteurs

          Définition virus
          1142347

          Version des moteurs
          AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

          Analyse des plugins
          16

          Archive des plugins
          41

          Unpack des plugins
          7

          E-mail plugins
          6

          Système plugins
          5

          Paramètres d'analyse

          Première action
          Désinfecté

          Seconde Action
          Supprimé

          Heuristique
          Oui

          Acceptez les avertissements
          Oui

          Extensions analysées
          exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

          Excludez les extensions

          Analyse d'emails
          Oui

          Analyse des Archives
          Oui

          Analyser paquets programmes
          Oui

          Analyse des fichiers
          Oui

          Analyse de boot
          Oui

          Fichier analysé
          Statut

          C:\Documents and Settings\Eric BELIARD\Local Settings\Temporary Internet Files\Content.IE5\UH8HG5Y3\wv[2].exe
          Infecté par: Trojan.Retapu.D

          C:\Documents and Settings\Eric BELIARD\Local Settings\Temporary Internet Files\Content.IE5\UH8HG5Y3\wv[2].exe
          Echec de la désinfection

          C:\Documents and Settings\Eric BELIARD\Local Settings\Temporary Internet Files\Content.IE5\UH8HG5Y3\wv[2].exe
          Supprimé
          0
      4. que dois- je faire mtn ?
        0
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 12:38:11, on 14/04/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\WINDOWS\system32\RunDll32.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\WINDOWS\system32\slmdmsr.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Skype\Plugin Manager\skypePM.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Opera\Opera.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\%%%.exe
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%.exe
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slmdmsr.exe
          0
        2. @papouComment faire pour régler le pb ?
          apres un nettoyage avec Ccleaner, j'ai toujours ce cheval de troie sur mon ordi. Cf rapport hijackthis ci dessus.
          Merci d'avance pour votre aide
          0