Avira détecte TR/agent.17920.DN, que faire ?

Résolu
pristi -  
 pristi -
Bonjour,

Tout d'abord merci d'avance à ceux qui pourront m'aider. Depuis hier Avira détecte un virus TR/Agent.17920.DN dans le système volume de mon ordinateur.
Voici la copie du message d'avira :

Virus or unwanted program 'TR/Agent.17920.DN [trojan]'
detected in file 'C:\System Volume Information\_restore{E21EED9E-FFD5-4507-A4B0-E7962CAE5F1D}\RP1280\A0849828.exe.
Action performed: Deny access

N'y connaissant vraiment pas grand chose, je ne sais pas quoi faire pour m'en débarrasser car il revient sans cesse. De plus mon ordi plante très très souvent (s'éteint seul, plus d'écran, fichiers .doc longs à ouvrir...) .

Merci beaucoup

7 réponses

  1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    slt
    désactive ta restauration puis redemarre ton pc puis réactive la

    car l'infection est dedans: voir ici: https://www.commentcamarche.net/faq/5097-virus-system-volume-information

    ensuite lance antivir et colle nous le rapport pour voir des infections persistent
    0
  2. pristi
     
    merci de votre aide, je m'en occupe de suite
    !
    0
  3. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok

    a plus
    0
  4. pristi
     
    en attendant le rapport, j'ai eu ça aussi récemment, si ça peut aider !
    The file 'C:\Program Files\MadOnion.com\3DMark2001\keygen.exe'
    contained a virus or unwanted program 'TR/Agent.17920.DN' [trojan]
    Action(s) taken:
    The file was moved to '4cebe081.qua'!
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. pristi
     
    Bonsoir, les plombs ont sauté ... au beau milieu du scan... Le voici enfin !
    Le scan ne détecte plus rien comme l'autre fois, j'espère que cette fois-ci le virus ne réapparaîtra pas !

    Avira AntiVir Personal
    Report file date: mercredi 25 août 2010 18:56

    Scanning for 2746072 virus strains and unwanted programs.

    Licensee : Avira AntiVir Personal - FREE Antivirus
    Serial number : 0000149996-ADJIE-0000001
    Platform : Windows XP
    Windows version : (Service Pack 2) [5.1.2600]
    Boot mode : Normally booted
    Username : SYSTEM
    Computer name : ISA

    Version information:
    BUILD.DAT : 9.0.0.422 21701 Bytes 09/03/2010 10:29:00
    AVSCAN.EXE : 9.0.3.10 466689 Bytes 13/10/2009 10:26:33
    AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 09:58:24
    LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:49
    LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 09:58:52
    VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 06:35:52
    VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 12:56:16
    VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 18:51:46
    VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 11:48:49
    VBASE004.VDF : 7.10.4.203 1579008 Bytes 05/03/2010 19:30:59
    VBASE005.VDF : 7.10.6.82 2494464 Bytes 15/04/2010 10:24:07
    VBASE006.VDF : 7.10.7.218 2294784 Bytes 02/06/2010 19:21:27
    VBASE007.VDF : 7.10.9.165 4840960 Bytes 23/07/2010 06:42:53
    VBASE008.VDF : 7.10.9.166 2048 Bytes 23/07/2010 06:42:53
    VBASE009.VDF : 7.10.9.167 2048 Bytes 23/07/2010 06:42:54
    VBASE010.VDF : 7.10.9.168 2048 Bytes 23/07/2010 06:42:54
    VBASE011.VDF : 7.10.9.169 2048 Bytes 23/07/2010 06:42:54
    VBASE012.VDF : 7.10.9.170 2048 Bytes 23/07/2010 06:42:54
    VBASE013.VDF : 7.10.9.198 157696 Bytes 26/07/2010 06:42:55
    VBASE014.VDF : 7.10.9.255 997888 Bytes 29/07/2010 06:44:45
    VBASE015.VDF : 7.10.10.28 139264 Bytes 02/08/2010 10:56:40
    VBASE016.VDF : 7.10.10.52 127488 Bytes 03/08/2010 10:56:43
    VBASE017.VDF : 7.10.10.84 137728 Bytes 06/08/2010 10:57:07
    VBASE018.VDF : 7.10.10.107 176640 Bytes 09/08/2010 20:12:15
    VBASE019.VDF : 7.10.10.130 132608 Bytes 10/08/2010 20:12:22
    VBASE020.VDF : 7.10.10.158 131072 Bytes 12/08/2010 09:16:33
    VBASE021.VDF : 7.10.10.190 136704 Bytes 16/08/2010 16:57:11
    VBASE022.VDF : 7.10.10.217 118272 Bytes 19/08/2010 18:01:11
    VBASE023.VDF : 7.10.10.246 130048 Bytes 23/08/2010 18:28:12
    VBASE024.VDF : 7.10.10.247 2048 Bytes 23/08/2010 18:28:13
    VBASE025.VDF : 7.10.10.248 2048 Bytes 23/08/2010 18:28:13
    VBASE026.VDF : 7.10.10.249 2048 Bytes 23/08/2010 18:28:15
    VBASE027.VDF : 7.10.10.250 2048 Bytes 23/08/2010 18:28:15
    VBASE028.VDF : 7.10.10.251 2048 Bytes 23/08/2010 18:28:16
    VBASE029.VDF : 7.10.10.252 2048 Bytes 23/08/2010 18:28:16
    VBASE030.VDF : 7.10.10.253 2048 Bytes 23/08/2010 18:28:16
    VBASE031.VDF : 7.10.11.9 121856 Bytes 25/08/2010 08:58:30
    Engineversion : 8.2.4.38
    AEVDF.DLL : 8.1.2.1 106868 Bytes 30/07/2010 06:45:15
    AESCRIPT.DLL : 8.1.3.42 1364347 Bytes 30/07/2010 06:45:14
    AESCN.DLL : 8.1.6.1 127347 Bytes 13/05/2010 17:51:35
    AESBX.DLL : 8.1.3.1 254324 Bytes 23/04/2010 18:18:05
    AERDL.DLL : 8.1.8.2 614772 Bytes 29/07/2010 06:43:10
    AEPACK.DLL : 8.2.3.5 471412 Bytes 07/08/2010 10:57:15
    AEOFFICE.DLL : 8.1.1.8 201081 Bytes 29/07/2010 06:43:07
    AEHEUR.DLL : 8.1.2.15 2859382 Bytes 18/08/2010 16:57:14
    AEHELP.DLL : 8.1.13.2 242039 Bytes 29/07/2010 06:43:00
    AEGEN.DLL : 8.1.3.19 393587 Bytes 07/08/2010 10:57:08
    AEEMU.DLL : 8.1.2.0 393588 Bytes 23/04/2010 18:18:01
    AECORE.DLL : 8.1.16.2 192887 Bytes 29/07/2010 06:42:58
    AEBB.DLL : 8.1.1.0 53618 Bytes 23/04/2010 18:18:00
    AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
    AVPREF.DLL : 9.0.3.0 44289 Bytes 26/08/2009 14:14:02
    AVREP.DLL : 8.0.0.7 159784 Bytes 17/02/2010 18:05:43
    AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 09:32:09
    AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:41
    AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:08
    SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
    SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:33
    NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 09:32:10
    RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/05/2009 14:39:58
    RCTEXT.DLL : 9.0.73.0 86785 Bytes 13/10/2009 11:25:47

    Configuration settings for the scan:
    Jobname.............................: Complete system scan
    Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
    Logging.............................: low
    Primary action......................: interactive
    Secondary action....................: ignore
    Scan master boot sector.............: on
    Scan boot sector....................: on
    Boot sectors........................: C:,
    Process scan........................: on
    Scan registry.......................: on
    Search for rootkits.................: on
    Integrity checking of system files..: off
    Scan all files......................: All files
    Scan archives.......................: on
    Recursion depth.....................: 20
    Smart extensions....................: on
    Macro heuristic.....................: on
    File heuristic......................: medium

    Start of the scan: mercredi 25 août 2010 18:56

    Starting search for hidden objects.
    '101585' objects were checked, '0' hidden objects were found.

    The scan of running processes will be started
    Scan process 'wltuser.exe' - '1' Module(s) have been scanned
    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
    Scan process 'plugin-container.exe' - '1' Module(s) have been scanned
    Scan process 'firefox.exe' - '1' Module(s) have been scanned
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'hprblog.exe' - '1' Module(s) have been scanned
    Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'soffice.bin' - '1' Module(s) have been scanned
    Scan process 'soffice.exe' - '1' Module(s) have been scanned
    Scan process 'SSScheduler.exe' - '1' Module(s) have been scanned
    Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
    Scan process 'AcroTray.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
    Scan process 'jusched.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
    Scan process 'realsched.exe' - '1' Module(s) have been scanned
    Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
    Scan process 'qttask.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
    Scan process 'jqs.exe' - '1' Module(s) have been scanned
    Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    42 processes with 42 modules were scanned

    Starting master boot sector scan:
    Master boot sector HD0
    [INFO] No virus was found!

    Start scanning boot sectors:
    Boot sector 'C:\'
    [INFO] No virus was found!

    Starting to scan executable files (registry).
    The registry was scanned ( '56' files ).

    Starting the file scan:

    Begin scan in 'C:\'
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    [NOTE] This file is a Windows system file.
    [NOTE] This file cannot be opened for scanning.

    End of the scan: mercredi 25 août 2010 21:25
    Used time: 2:28:50 Hour(s)

    The scan has been done completely.

    10827 Scanned directories
    537023 Files were scanned
    0 Viruses and/or unwanted programs were found
    0 Files were classified as suspicious
    0 files were deleted
    0 Viruses and unwanted programs were repaired
    0 Files were moved to quarantine
    0 Files were renamed
    1 Files cannot be scanned
    537022 Files not concerned
    4266 Archives were scanned
    1 Warnings
    1 Notes
    101585 Objects were scanned with rootkit scan
    0 Hidden objects were found

    Merci !
    0
  7. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok parfait!

    tu diras si cela revient

    bonne suite
    0