AviraAntivir trouvé plusieurs instances du trojan Crypt.CFI.Gen dans mon ordinateur mais je n'ai trouvé aucun site internet parlant de ce virus.
J'ai fait des scans avec Spysweeper et Adaware mais ils n'ont rien trouvé.
Est-ce que vous pourriez me dire si j'ai bien réussi à enlever le virus ou s'il est encore quelque part dans mon ordinateur?
Configuration settings for the scan:
Jobname..........................: Manual Selection
Configuration file...............: C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic\PROFILES\folder.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: jeudi 8 mars 2007 17:39
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Modules have been scanned
Scan process 'avcenter.exe' - '1' Modules have been scanned
Scan process 'SSU.EXE' - '1' Modules have been scanned
Scan process 'wmplayer.exe' - '1' Modules have been scanned
Scan process 'avgnt.exe' - '1' Modules have been scanned
Scan process 'MSNMSGR.EXE' - '1' Modules have been scanned
Scan process 'emule.exe' - '1' Modules have been scanned
Scan process 'lxcccoms.exe' - '1' Modules have been scanned
Scan process 'Webshots.scr' - '1' Modules have been scanned
Scan process 'alg.exe' - '1' Modules have been scanned
Scan process 'ooneclockv65.exe' - '1' Modules have been scanned
Scan process 'ctfmon.exe' - '1' Modules have been scanned
Scan process 'Cld2000.exe' - '1' Modules have been scanned
Scan process 'SpySweeperUI.exe' - '1' Modules have been scanned
Scan process 'qttask.exe' - '1' Modules have been scanned
Scan process 'jusched.exe' - '1' Modules have been scanned
Scan process 'Monitor.exe' - '1' Modules have been scanned
Scan process 'LVCOMSX.EXE' - '1' Modules have been scanned
Scan process 'ATKOSD.exe' - '1' Modules have been scanned
Scan process 'SynTPEnh.exe' - '1' Modules have been scanned
Scan process 'wcourier.exe' - '1' Modules have been scanned
Scan process 'RTHDCPL.EXE' - '1' Modules have been scanned
Scan process 'SynTPLpr.exe' - '1' Modules have been scanned
Scan process 'lxccmon.exe' - '1' Modules have been scanned
Scan process 'HControl.exe' - '1' Modules have been scanned
Scan process 'iFrmewrk.exe' - '1' Modules have been scanned
Scan process 'EOUWiz.exe' - '1' Modules have been scanned
Scan process '1XConfig.exe' - '1' Modules have been scanned
Scan process 'SpySweeper.exe' - '1' Modules have been scanned
Scan process 'SVCHOST.EXE' - '1' Modules have been scanned
Scan process 'StarWindService.exe' - '1' Modules have been scanned
Scan process 'RegSrvc.exe' - '1' Modules have been scanned
Scan process 'OProtSvc.exe' - '1' Modules have been scanned
Scan process 'NVSVC32.EXE' - '1' Modules have been scanned
Scan process 'MSIEXEC.EXE' - '1' Modules have been scanned
Scan process 'LSSrvc.exe' - '1' Modules have been scanned
Scan process 'INSTAL~1.EXE' - '1' Modules have been scanned
Scan process 'AVGUARD.EXE' - '1' Modules have been scanned
Scan process 'SCHED.EXE' - '1' Modules have been scanned
Scan process 'SPOOLSV.EXE' - '1' Modules have been scanned
Scan process 'SVCHOST.EXE' - '1' Modules have been scanned
Scan process 'EXPLORER.EXE' - '1' Modules have been scanned
Scan process 'SVCHOST.EXE' - '1' Modules have been scanned
Scan process 'S24EvMon.exe' - '1' Modules have been scanned
Scan process 'ZCfgSvc.exe' - '1' Modules have been scanned
Scan process 'EvtEng.exe' - '1' Modules have been scanned
Scan process 'InCDsrv.exe' - '1' Modules have been scanned
Scan process 'SVCHOST.EXE' - '1' Modules have been scanned
Scan process 'SVCHOST.EXE' - '1' Modules have been scanned
Scan process 'SVCHOST.EXE' - '1' Modules have been scanned
Scan process 'LSASS.EXE' - '1' Modules have been scanned
Scan process 'SERVICES.EXE' - '1' Modules have been scanned
Scan process 'WINLOGON.EXE' - '1' Modules have been scanned
Scan process 'CSRSS.EXE' - '1' Modules have been scanned
Scan process 'SMSS.EXE' - '1' Modules have been scanned
55 processes with 55 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( 28 files ).
Starting the file scan:
Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd3693.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\vaxscsi.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP478\A0194804.exe
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[INFO] The file was moved to '4621b06f.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP478\A0194966.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b085.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP481\A0196470.EXE
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[INFO] The file was moved to '4621b153.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197301.exe
[DETECTION] Contains signature of the worm WORM/Bagle.HT
[INFO] The file was moved to '4621b191.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197303.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b198.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197304.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b19d.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197305.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b1a6.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197306.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b1aa.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197307.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b1ae.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197308.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b1b1.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197310.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b1b5.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197311.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b1b8.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP483\A0197312.exe
[DETECTION] Contains suspicious code HEUR/Crypted
[INFO] The file was moved to '4621b1bb.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP485\A0197400.exe
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[INFO] The file was moved to '4621b1c5.qua'!
C:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP487\A0197436.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '4621b1ca.qua'!
Begin scan in 'D:\'
D:\System Volume Information\_restore{B5FE3342-DE3A-4428-969D-7C390CE58E17}\RP487\A0197437.exe
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[INFO] The file was moved to '4621bb8c.qua'!
End of the scan: jeudi 8 mars 2007 19:46
Used time: 2:06:34 min
The scan has been done completely.
6094 Scanning directories
383260 Files were scanned
16 viruses and/or unwanted programs were found
0 files were deleted
0 files were repaired
16 files were moved to quarantine
0 files were renamed
5 Files cannot be scanned
383244 Files not concerned
7381 Archives were scanned
5 Warnings
0 Notes
Et voici un rapport de Hijackthis que j'ai lancé après avoir scanné avec Avira Antivir:
Logfile of HijackThis v1.99.1
Scan saved at 20:24:41, on 08/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Ton virus ets dans la restauration systeme suis ces procédures a la clé : http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/redemarrer-mode-echec-sujet_1526_1.htm
salut:
AviraAntivir trouvé plusieurs instances du trojan Crypt.CFI.Gen dans mon ordinateur mais je n'ai trouvé Est-ce que vous pourriez me dire si j'ai bien réussi à enlever le virus ou s'il est encore quelque part dans mon ordinateur?
Bonjour,
j'ai avira antivir comme anti virus il m'a detecté "trojan horse", j'ai beau mettre "move to quanrantine" ou "delete" rien a faire il revient toujours la charge.
Je ne comprend pas comment faire pour le detruire.
Depuis que j'ai ce virus mes programmes s'ouvre tout seule tel que msn ou certain de mes dossier sans meme que j'y touche. j'aimerai que vous m'aidiez ça serai sympatique..
Merciii.
scan kaspersky https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
Clic sur l'image Kaspersky Online Scanner
Clic sur J'accepte
Installes le ActiveX
Tu attends que la mise à jour se termine, une fois terminé,
clic sur Suivant
Clic sur Paramètres d'analyse
Coche la case Étendue >> Ok
Clic sur Poste de travail pour faire un scan complet
Une fois le scan fini à 100%, clic sur Enregistrer rapport
sous...
Enregistrer le rapport au format .txt (en nom tu mets rapport ou
ce que tu veux et en type tu choisis fichier texte (*.txt)
Tu ouvres le fichier que tu viens de sauvegarder, copie et colle
le rapport ici si tu es infecté
Statistiques de l'analyse:
Total d'objets analysés: 49989
Nombre de virus trouvés: 6
Nombre d'objets infectés: 10 / 0
Nombre d'objets suspects: 0
Durée de l'analyse: 01:06:13
Nom de l'objet infecté / Nom du virus / Dernière action
C:\Documents and Settings\Admin\Local Settings\Temp\NeroDemo12069\Toolbar.exe Infecté : not-a-virus:AdTool.Win32.MyWebSearch.bm ignoré
C:\Documents and Settings\Aktarus\Application Data\Microsoft\MSNLiveFav\LiveFavorites.xml L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\ie_update3r.exe L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\Local Settings\Historique\History.IE5\MSHist012007112120071122\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\Local Settings\Temp\~DF20A.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\Local Settings\Temporary Internet Files\Content.IE5\ONUTSVCH\mymsn[1] L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\ntuser.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\Aktarus\UserData\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService.AUTORITE NT\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService.AUTORITE NT\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService.AUTORITE NT\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService.AUTORITE NT\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService.AUTORITE NT\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\System Volume Information\_restore{4ABF4FD9-294E-4687-B317-62907B2A7856}\RP170\A0123626.exe Infecté : Trojan.Win32.DNSChanger.acs ignoré
C:\System Volume Information\_restore{4ABF4FD9-294E-4687-B317-62907B2A7856}\RP170\A0124649.exe Infecté : Trojan-Downloader.Win32.Small.grl ignoré
C:\System Volume Information\_restore{4ABF4FD9-294E-4687-B317-62907B2A7856}\RP170\A0124650.exe Infecté : Trojan-Downloader.Win32.Small.gro ignoré
C:\System Volume Information\_restore{4ABF4FD9-294E-4687-B317-62907B2A7856}\RP170\change.log L'objet est verrouillé ignoré
C:\upload_moi_AKTARUS.tar.gz/upload_moi.tar/WINDOWS/System32/_svchost.exe Infecté : Trojan-Downloader.Win32.Tiny.abk ignoré
C:\upload_moi_AKTARUS.tar.gz/upload_moi.tar/WINDOWS/System32/isdeidk.dll Infecté : Backdoor.Win32.Agent.adr ignoré
C:\upload_moi_AKTARUS.tar.gz/upload_moi.tar Infecté : Backdoor.Win32.Agent.adr ignoré
C:\upload_moi_AKTARUS.tar.gz GZIP: infecté - 3 ignoré
C:\WINDOWS\Debug\oakley.log L'objet est verrouillé ignoré
C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
C:\WINDOWS\system32\isdeidk.dll Infecté : Backdoor.Win32.Agent.adr ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
C:\WINDOWS\system32\_svchost.exe Infecté : Trojan-Downloader.Win32.Tiny.abk ignoré
C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
D:\System Volume Information\_restore{4ABF4FD9-294E-4687-B317-62907B2A7856}\RP170\change.log L'objet est verrouillé ignoré