Précédent
- 1
- 2
- 3
- 4
Suite des infos
Bon, alors voilà, analyse avec AntiVir.
Il y a 2 rapports, car la première analyse a été interrompue...
Premier rapport
AntiVir PersonalEdition Classic
Report file date: mercredi 6 février 2008 15:50
Scanning for 1094707 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Tata
Computer name: ACER-DC6C4D74B4
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 14:37:55
ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 25/01/2008 14:37:55
ANTIVIR3.VDF : 7.0.2.100 330752 Bytes 06/02/2008 14:37:55
AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 06/02/2008 14:37:56
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 06/02/2008 14:37:56
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: mercredi 6 février 2008 15:50
Starting search for hidden objects.
The driver could not be initialized.
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
11 processes with 11 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '42' files ).
Starting the file scan:
Begin scan in 'C:\' <ACER>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\upload_moi_ACER-DC6C4D74B4.tar.gz
[0] Archive type: GZ
--> upload_moi.tar
[1] Archive type: TAR (tape archiver)
--> qoobox/Quarantine/C/Documents and Settings/All Users/Application Data/zyhmrwfk.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.Gen
--> WINDOWS/System32/12520437l.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
--> WINDOWS/System32/acodep.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '4815c9e0.qua'!
C:\Documents and Settings\Toto\Bureau\catchme.zip
[0] Archive type: ZIP
--> symavc32.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> YIL48.sys
[DETECTION] Contains detection pattern of the worm WORM/Ntech.Z.4
--> fvelwow.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> jecsst.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> ztx86.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> astq.tga
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> srtwe.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '481dcba8.qua'!
End of the scan: mercredi 6 février 2008 16:12
Used time: 22:04 min
The scan has been canceled!
2072 Scanning directories
37747 Files were scanned
10 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
2 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
37737 Files not concerned
2623 Archives were scanned
1 Warnings
0 Notes
Deuxième rapport
AntiVir PersonalEdition Classic
Report file date: mercredi 6 février 2008 16:21
Scanning for 1094707 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Tata
Computer name: ACER-DC6C4D74B4
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 14:37:55
ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 25/01/2008 14:37:55
ANTIVIR3.VDF : 7.0.2.100 330752 Bytes 06/02/2008 14:37:55
AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 06/02/2008 14:37:56
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 06/02/2008 14:37:56
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Local Hard Disks
Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: mercredi 6 février 2008 16:21
Starting search for hidden objects.
The driver could not be initialized.
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avnotify.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
13 processes with 13 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '42' files ).
Starting the file scan:
Begin scan in 'C:\' <ACER>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Program Files\HijackThis1\backups\backup-20080130-221033-848.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '480cd719.qua'!
C:\Program Files\Panda Security\NanoScan\Engine\psnflg.dll
[DETECTION] Is the Trojan horse TR/Agent.bux.1
[INFO] The file was moved to '4817db4c.qua'!
C:\Program Files\Panda Security\TotalScan\pskavs.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '4814db50.qua'!
C:\QooBox\Quarantine\catchme2008-02-06_134341.23.zip
[0] Archive type: ZIP
--> ixyisxnz.dat
[DETECTION] Contains detection pattern of the rootkit RKIT/Agent.KA
--> unolaivy.dat
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '481ddbff.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Application Data\zyhmrwfk.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '4811dc17.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\hupqkh.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc14.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\iwmdlt.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4816dc16.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\ulyrqt.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4822dc0b.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\ziqpmm.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481adc08.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\zovsuz.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481fdc0f.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\aezlll.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4823dc05.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\catyrs.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481ddc01.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\ddpgki.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc04.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\elppep.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc0d.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\fzyeru.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4822dc1b.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\gchnly.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4811dc04.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\iinvip.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4817dc0a.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\lppdge.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc12.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\mfpfsw.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc08.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\naked0453.com.vir
[DETECTION] Is the Trojan horse TR/Agent.dwd.4
[INFO] The file was moved to '4814dc03.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\npxqif.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4821dc12.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\nygfyb.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4810dc1c.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\qguevw.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481edc0a.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\tugawl.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4810dc18.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\urufwd.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481edc15.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\ywsrlh.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481cdc1b.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\zltsym.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481ddc10.qua'!
C:\QooBox\Quarantine\C\WINDOWS\fmjqlgfe.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '4813dc11.qua'!
C:\QooBox\Quarantine\C\WINDOWS\gterupgp.dll.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '480edc19.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\12520437l.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '47dedbd7.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\acodep.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '4818dc08.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\lolol.hta.vir
[DETECTION] Contains suspicious code HEUR/Exploit.HTML
[INFO] The file was moved to '4815dc15.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\ixyisxnz.dat.vir
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '4822dc1e.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\unolaivy.dat.vir
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '4818dc14.qua'!
C:\SDFix\SDFix\backups\backups.zip
[0] Archive type: ZIP
--> backups/mrofinu1148.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
--> backups/Yil48.sys
[DETECTION] Contains detection pattern of the worm WORM/Ntech.Z.4
[INFO] The file was moved to '480cdc0c.qua'!
C:\System Volume Information\_restore{54887473-E0E8-4E40-8CB4-34743021C726}\RP2\A0000187.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '47d9dbea.qua'!
C:\System Volume Information\_restore{54887473-E0E8-4E40-8CB4-34743021C726}\RP2\A0000188.dll
[DETECTION] Is the Trojan horse TR/Agent.bux.1
[INFO] The file was moved to '46a7bd93.qua'!
C:\System Volume Information\_restore{54887473-E0E8-4E40-8CB4-34743021C726}\RP2\A0000189.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '47d9dbeb.qua'!
Begin scan in 'D:\' <ACERDATA>
End of the scan: mercredi 6 février 2008 17:35
Used time: 1:13:52 min
The scan has been done completely.
6873 Scanning directories
259299 Files were scanned
39 viruses and/or unwanted programs were found
1 Files were classified as suspicious:
0 files were deleted
0 files were repaired
38 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
259260 Files not concerned
8035 Archives were scanned
1 Warnings
0 Notes
Merci
Bon, alors voilà, analyse avec AntiVir.
Il y a 2 rapports, car la première analyse a été interrompue...
Premier rapport
AntiVir PersonalEdition Classic
Report file date: mercredi 6 février 2008 15:50
Scanning for 1094707 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Tata
Computer name: ACER-DC6C4D74B4
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 14:37:55
ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 25/01/2008 14:37:55
ANTIVIR3.VDF : 7.0.2.100 330752 Bytes 06/02/2008 14:37:55
AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 06/02/2008 14:37:56
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 06/02/2008 14:37:56
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: mercredi 6 février 2008 15:50
Starting search for hidden objects.
The driver could not be initialized.
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
11 processes with 11 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '42' files ).
Starting the file scan:
Begin scan in 'C:\' <ACER>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\upload_moi_ACER-DC6C4D74B4.tar.gz
[0] Archive type: GZ
--> upload_moi.tar
[1] Archive type: TAR (tape archiver)
--> qoobox/Quarantine/C/Documents and Settings/All Users/Application Data/zyhmrwfk.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.Gen
--> WINDOWS/System32/12520437l.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
--> WINDOWS/System32/acodep.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '4815c9e0.qua'!
C:\Documents and Settings\Toto\Bureau\catchme.zip
[0] Archive type: ZIP
--> symavc32.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> YIL48.sys
[DETECTION] Contains detection pattern of the worm WORM/Ntech.Z.4
--> fvelwow.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> jecsst.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> ztx86.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> astq.tga
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> srtwe.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '481dcba8.qua'!
End of the scan: mercredi 6 février 2008 16:12
Used time: 22:04 min
The scan has been canceled!
2072 Scanning directories
37747 Files were scanned
10 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
2 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
37737 Files not concerned
2623 Archives were scanned
1 Warnings
0 Notes
Deuxième rapport
AntiVir PersonalEdition Classic
Report file date: mercredi 6 février 2008 16:21
Scanning for 1094707 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Tata
Computer name: ACER-DC6C4D74B4
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 14:37:55
ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 25/01/2008 14:37:55
ANTIVIR3.VDF : 7.0.2.100 330752 Bytes 06/02/2008 14:37:55
AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 06/02/2008 14:37:56
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 06/02/2008 14:37:56
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Local Hard Disks
Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: mercredi 6 février 2008 16:21
Starting search for hidden objects.
The driver could not be initialized.
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avnotify.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
13 processes with 13 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '42' files ).
Starting the file scan:
Begin scan in 'C:\' <ACER>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Program Files\HijackThis1\backups\backup-20080130-221033-848.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '480cd719.qua'!
C:\Program Files\Panda Security\NanoScan\Engine\psnflg.dll
[DETECTION] Is the Trojan horse TR/Agent.bux.1
[INFO] The file was moved to '4817db4c.qua'!
C:\Program Files\Panda Security\TotalScan\pskavs.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '4814db50.qua'!
C:\QooBox\Quarantine\catchme2008-02-06_134341.23.zip
[0] Archive type: ZIP
--> ixyisxnz.dat
[DETECTION] Contains detection pattern of the rootkit RKIT/Agent.KA
--> unolaivy.dat
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '481ddbff.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Application Data\zyhmrwfk.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '4811dc17.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\hupqkh.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc14.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\iwmdlt.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4816dc16.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\ulyrqt.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4822dc0b.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\ziqpmm.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481adc08.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Toto\zovsuz.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481fdc0f.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\aezlll.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4823dc05.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\catyrs.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481ddc01.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\ddpgki.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc04.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\elppep.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc0d.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\fzyeru.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4822dc1b.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\gchnly.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4811dc04.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\iinvip.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4817dc0a.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\lppdge.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc12.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\mfpfsw.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4819dc08.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\naked0453.com.vir
[DETECTION] Is the Trojan horse TR/Agent.dwd.4
[INFO] The file was moved to '4814dc03.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\npxqif.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4821dc12.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\nygfyb.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4810dc1c.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\qguevw.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481edc0a.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\tugawl.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4810dc18.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\urufwd.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481edc15.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\ywsrlh.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481cdc1b.qua'!
C:\QooBox\Quarantine\C\Documents and Settings\Tata\Mes documents\PToto\zltsym.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '481ddc10.qua'!
C:\QooBox\Quarantine\C\WINDOWS\fmjqlgfe.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '4813dc11.qua'!
C:\QooBox\Quarantine\C\WINDOWS\gterupgp.dll.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '480edc19.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\12520437l.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '47dedbd7.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\acodep.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '4818dc08.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\lolol.hta.vir
[DETECTION] Contains suspicious code HEUR/Exploit.HTML
[INFO] The file was moved to '4815dc15.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\ixyisxnz.dat.vir
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '4822dc1e.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\unolaivy.dat.vir
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '4818dc14.qua'!
C:\SDFix\SDFix\backups\backups.zip
[0] Archive type: ZIP
--> backups/mrofinu1148.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
--> backups/Yil48.sys
[DETECTION] Contains detection pattern of the worm WORM/Ntech.Z.4
[INFO] The file was moved to '480cdc0c.qua'!
C:\System Volume Information\_restore{54887473-E0E8-4E40-8CB4-34743021C726}\RP2\A0000187.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '47d9dbea.qua'!
C:\System Volume Information\_restore{54887473-E0E8-4E40-8CB4-34743021C726}\RP2\A0000188.dll
[DETECTION] Is the Trojan horse TR/Agent.bux.1
[INFO] The file was moved to '46a7bd93.qua'!
C:\System Volume Information\_restore{54887473-E0E8-4E40-8CB4-34743021C726}\RP2\A0000189.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '47d9dbeb.qua'!
Begin scan in 'D:\' <ACERDATA>
End of the scan: mercredi 6 février 2008 17:35
Used time: 1:13:52 min
The scan has been done completely.
6873 Scanning directories
259299 Files were scanned
39 viruses and/or unwanted programs were found
1 Files were classified as suspicious:
0 files were deleted
0 files were repaired
38 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
259260 Files not concerned
8035 Archives were scanned
1 Warnings
0 Notes
Merci
Re,
Bien, il y avait des sauvegardes relatives aux outils utilisés.
1°- C'est surprenant de lire que Antivir trouve des infections dans PANDA ==> PANDA les gardait en mémoire, mais je ne trouve pas trace de sa poubelle/backup :
C:\Program Files\Panda Security\NanoScan\Engine\psnflg.dll
[DETECTION] Is the Trojan horse TR/Agent.bux.1
[INFO] The file was moved to '4817db4c.qua'!
C:\Program Files\Panda Security\TotalScan\pskavs.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '4814db50.qua'!
2°- Celles-ci, tu les reconnais :
C:\upload_moi_ACER-DC6C4D74B4.tar.gz
C:\Program Files\HijackThis1\backups
C:\QooBox\Quarantine
C:\SDFix\SDFix\backups
3°- Celles-ci montrent que l'infection a atteint "Restauration système" :
C:\System Volume Information\_restore
CONCLUSION:
A)•- OK, vide la QUARANTINE de ANTIVIR en faisant : "clic-droit sur antivir" > "start antivir" > "quarantine" > selectionne ce qui s'y trouve via clic-droit > puis "delete" (ce pour chacun).
B)•- Ensuite renouveler la restauration comme ceci (on en profite pour supprimer les outils utilisés):
•- Clique sur "Démarrer" - Clic droit sur le "Poste de Travail" > dans "Propriétés" > onglet "Restauration du système" - Cocher la case "Désactiver la restauration du système" et cliquer sur "Appliquer".
•- Télécharger _OTMoveIt sur ton bureau > < http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe >
•- Lance OTMoveIt.exe par double-clic
[*]Clique sur CleanUp! (le programme va télécharger un fichier texte qui servira à nettoyer les programmes que l'on a téléchargés).
NOTE : Normalement, ton Firewall (parefeu) devrait te demander si _OTMoveIt peut accéder à Internet. Autorise-le.
[*]Une liste apparaît dans la partie gauche d' _OTMoveIt.
[*]Un message apparaît pour confirmer le nettoyage. Confirme
Ce programme supprime les outils utilisés ainsi que les quarantaines éventuelles.
La manoeuvre nécessitera un reboot (=redémarrage) initié par le programme. (sinon, le redémarrer toi-même)
•- Clique sur "Démarrer" - Clic droit sur le "Poste de Travail" > dans "Propriétés" > onglet "Restauration du système" - Décocher la case "Désactiver la restauration du système" et cliquer sur "Appliquer".
Bonne soirée
Al.
Bien, il y avait des sauvegardes relatives aux outils utilisés.
1°- C'est surprenant de lire que Antivir trouve des infections dans PANDA ==> PANDA les gardait en mémoire, mais je ne trouve pas trace de sa poubelle/backup :
C:\Program Files\Panda Security\NanoScan\Engine\psnflg.dll
[DETECTION] Is the Trojan horse TR/Agent.bux.1
[INFO] The file was moved to '4817db4c.qua'!
C:\Program Files\Panda Security\TotalScan\pskavs.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '4814db50.qua'!
2°- Celles-ci, tu les reconnais :
C:\upload_moi_ACER-DC6C4D74B4.tar.gz
C:\Program Files\HijackThis1\backups
C:\QooBox\Quarantine
C:\SDFix\SDFix\backups
3°- Celles-ci montrent que l'infection a atteint "Restauration système" :
C:\System Volume Information\_restore
CONCLUSION:
A)•- OK, vide la QUARANTINE de ANTIVIR en faisant : "clic-droit sur antivir" > "start antivir" > "quarantine" > selectionne ce qui s'y trouve via clic-droit > puis "delete" (ce pour chacun).
B)•- Ensuite renouveler la restauration comme ceci (on en profite pour supprimer les outils utilisés):
•- Clique sur "Démarrer" - Clic droit sur le "Poste de Travail" > dans "Propriétés" > onglet "Restauration du système" - Cocher la case "Désactiver la restauration du système" et cliquer sur "Appliquer".
•- Télécharger _OTMoveIt sur ton bureau > < http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe >
•- Lance OTMoveIt.exe par double-clic
[*]Clique sur CleanUp! (le programme va télécharger un fichier texte qui servira à nettoyer les programmes que l'on a téléchargés).
NOTE : Normalement, ton Firewall (parefeu) devrait te demander si _OTMoveIt peut accéder à Internet. Autorise-le.
[*]Une liste apparaît dans la partie gauche d' _OTMoveIt.
[*]Un message apparaît pour confirmer le nettoyage. Confirme
Ce programme supprime les outils utilisés ainsi que les quarantaines éventuelles.
La manoeuvre nécessitera un reboot (=redémarrage) initié par le programme. (sinon, le redémarrer toi-même)
•- Clique sur "Démarrer" - Clic droit sur le "Poste de Travail" > dans "Propriétés" > onglet "Restauration du système" - Décocher la case "Désactiver la restauration du système" et cliquer sur "Appliquer".
Bonne soirée
Al.
Merci encore pour l'efficacité et aussi (surtout ?) les explications données.
Tout semble correct.
Puis-je me permettre une question ? Faut-il passer à IE7 ? Dans ton profil, il est indiqué IE6...
Alain
Tout semble correct.
Puis-je me permettre une question ? Faut-il passer à IE7 ? Dans ton profil, il est indiqué IE6...
Alain
Re,
Bonne question.
Je ne vois absolument pas l'intérêt de passer à IE7 quand IE6 me comble de bonheur.
Je ne me laisse pas non plus tenter par la "promotion" de Microsoft de permettre l'installation de IE7 sur des Windows "de vendeurs peu scrupuleux qui font payer aux clients des copies de copies au prix fort".
Tout cela, n'est destiné (principalement) qu'à autoriser Microsoft de visiter régulièrement tes activités.
Et quand tout le monde aura cédé à la tentation IE7, ils commenceront à avoir des surprises désagréables.
Il faut bien donner du travail aux "dépanneurs" professionnels !
Bonne nuit
Reviens quand tu veux si problème nouveau il y a .
Merci pour ta patience
Al.
Bonne question.
Je ne vois absolument pas l'intérêt de passer à IE7 quand IE6 me comble de bonheur.
Je ne me laisse pas non plus tenter par la "promotion" de Microsoft de permettre l'installation de IE7 sur des Windows "de vendeurs peu scrupuleux qui font payer aux clients des copies de copies au prix fort".
Tout cela, n'est destiné (principalement) qu'à autoriser Microsoft de visiter régulièrement tes activités.
Et quand tout le monde aura cédé à la tentation IE7, ils commenceront à avoir des surprises désagréables.
Il faut bien donner du travail aux "dépanneurs" professionnels !
Bonne nuit
Reviens quand tu veux si problème nouveau il y a .
Merci pour ta patience
Al.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Précédent
- 1
- 2
- 3
- 4