bichoo
Messages postés244Date d'inscriptionjeudi 26 avril 2007StatutMembreDernière intervention15 janvier 2014
-
21 nov. 2009 à 18:11
Utilisateur anonyme -
29 nov. 2009 à 14:38
Bonjour,
Voilà dès que je vais sur internet Avira (mon antirirus) m'affiche des alertes d'un virus. Soit c'est DR/Delphi.gen, ADWARE/Adware.gen, EXP/ASF.GetCodec.gen mais le plus souvent c'est HTML/Infected.WebPage.gen.
Comment faire pour se débarrasser de ça?
J'ai visité des forums et j'ai vu que fallait télécharger Hijackthis.Donc je l'ai fais.donc la je vous donne le rapport de Avira après un scan et le rapport de hijackthis.
Pouvez vous m'aidez?
Rapport de Avira:
Avira AntiVir Personal
Report file date: samedi 21 novembre 2009 12:45
Scanning for 1916411 virus strains and unwanted programs.
Licensed to: Avira AntiVir Personal - FREE Antivirus
Serial number: 0000149996-ADJIE-0000001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: ACTARUS
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 21 novembre 2009 12:45
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'jucheck.exe' - '1' Module(s) have been scanned
Scan process 'skypePM.exe' - '1' Module(s) have been scanned
Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
Scan process 'soffice.bin' - '1' Module(s) have been scanned
Scan process 'soffice.exe' - '1' Module(s) have been scanned
Scan process 'SPUVolumeWatcher.exe' - '1' Module(s) have been scanned
Scan process 'WZQKPICK.EXE' - '1' Module(s) have been scanned
Scan process 'fuljb.exe' - '1' Module(s) have been scanned
Scan process 'Skype.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'SearchSettings.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'QTTask.exe' - '1' Module(s) have been scanned
Scan process 'SFAgent.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
Scan process 'ezSP_Px.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sfus.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'IoctlSvc.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'NBService.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
53 processes with 53 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '62' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Françoise\Local Settings\Application Data\Mozilla\Firefox\Profiles\9fiwemf9.default\Cache\23D61869d01
[DETECTION] Contains recognition pattern of the HTML/Infected.WebPage.Gen HTML script virus
[WARNING] An error has occurred and the file was not deleted. ErrorID: 26004
[WARNING] The source file could not be found.
[NOTE] Attempting to perform action using the ARK lib.
[WARNING] Error in ARK lib
[NOTE] The file is scheduled for deleting after reboot.
C:\Documents and Settings\Françoise\Local Settings\Temporary Internet Files\Content.IE5\V1B21X9W\PLAY_MP3[1].exe
[WARNING] The file could not be opened!
C:\Documents and Settings\Françoise\Local Settings\Temporary Internet Files\Content.IE5\XVSZZF2Z\installer.70159[1].exe
[WARNING] The file could not be opened!
C:\Documents and Settings\Françoise\Mes documents\LimeWire\Incomplete\Preview-T-5174365-loverboy les visiteurs new cover version.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '4b6cdb39.qua'!
C:\System Volume Information\_restore{03A8A5C4-E6A8-4B42-8440-68557157B69C}\RP774\A0087993.exe
[DETECTION] Contains recognition pattern of the ADWARE/Adware.Gen virus
[NOTE] The file was moved to '4b37e17d.qua'!
C:\System Volume Information\_restore{03A8A5C4-E6A8-4B42-8440-68557157B69C}\RP777\A0088090.exe
[DETECTION] Contains recognition pattern of the ADWARE/Adware.Gen virus
[NOTE] The file was moved to '4b37e183.qua'!
C:\WINDOWS\system32\SysWoW32\mi175473509v0
[0] Archive type: ZIP
--> setup.exe
[DETECTION] Contains recognition pattern of the DR/Delphi.Gen dropper
[NOTE] The file was moved to '4b38e6ea.qua'!
C:\WINDOWS\system32\SysWoW32\mi175473509v1
[0] Archive type: ZIP
--> setup.exe
[DETECTION] Contains recognition pattern of the DR/Delphi.Gen dropper
[NOTE] The file was moved to '4a126c8b.qua'!
C:\WINDOWS\system32\SysWoW32\mi175473509v2
[0] Archive type: ZIP
--> patch.by.REVENGE.exe
[DETECTION] Is the TR/Spy.399360.9 Trojan
--> setup.exe
[DETECTION] Contains recognition pattern of the DR/Delphi.Gen dropper
[NOTE] The file was moved to '4b38e6eb.qua'!
C:\WINDOWS\system32\SysWoW32\mi175473509v3
[0] Archive type: ZIP
--> setup.exe
[DETECTION] Contains recognition pattern of the DR/Delphi.Gen dropper
[NOTE] The file was moved to '4b38e6ec.qua'!
Begin scan in 'D:\'
End of the scan: samedi 21 novembre 2009 14:13
Used time: 1:28:06 Hour(s)
The scan has been done completely.
8869 Scanning directories
397133 Files were scanned
9 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
7 files were moved to quarantine
0 files were renamed
4 Files cannot be scanned
397120 Files not concerned
3258 Archives were scanned
5 Warnings
8 Notes
Rapport de Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:58, on 21/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal