Infecté par un cheval de troie!!!!!

WAMBAROI -  
 WAMBAROI -
Bonjour,

J'ai recu un message instantané de Msn, venat d'un ami, et il s'avère que ce message, était infecté par un cheval de troie. Quand j'ai ouvert le fichier, il a infecté tous mes contacts. J'ai procédé à un scan avec avast, qui me dit qu'il y a un cheval de troie sur mon pc. Comment être bien sur que tout est retiré????

Merci à vous
Configuration: Windows XP
Internet Explorer 7.0

2 réponses

  1. chstdj
     
    Salut,

    alors premiere chose pour moi a faire:Virer Avast et installer antivir faire un scan en mode sans echec apres avoir fait la mise a jour..
    0
    1. WAMBAROI
       
      Salut,
      Justement , c'est ce que j'ai fais. j'ai installé antivir. Je vais essayer de faire un scan en mode sans échec.

      Je vous tiens au courant.
      Merci
      0
  2. WAMBAROI
     
    voici le rapport de avira :

    AntiVir PersonalEdition Classic
    Report file date: mardi 18 mars 2008 17:21

    Scanning for 1157590 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: GAELLE
    Computer name: RESEAUPC

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
    ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 14:13:48
    ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 14:13:48
    ANTIVIR3.VDF : 7.0.3.47 294400 Bytes 18/03/2008 14:13:48
    AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 18/03/2008 14:13:48
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVPACK32.DLL : 7.6.0.3 360488 Bytes 18/03/2008 14:13:48
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: i:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: I:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: mardi 18 mars 2008 17:21

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'aawservice.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    12 processes with 12 modules were scanned

    Start scanning boot sectors:
    Boot sector 'I:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '29' files ).

    Starting the file scan:

    Begin scan in 'I:\'
    I:\pagefile.sys
    [WARNING] The file could not be opened!
    I:\Documents and Settings\GAELLE\Bureau\catchme.zip
    [0] Archive type: ZIP
    --> qvoywo.exe
    [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
    --> qvoywo.exe.1
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    --> qvoywo.exe.3
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    [INFO] The file was deleted!
    I:\Documents and Settings\GAELLE\Bureau\MSNFix\17032008_19363354.zip
    [0] Archive type: ZIP
    --> backup/gcijvd.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] The file was deleted!

    End of the scan: mardi 18 mars 2008 19:04
    Used time: 1:43:33 min

    The scan has been done completely.

    8716 Scanning directories
    255937 Files were scanned
    4 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    2 files were deleted
    0 files were repaired
    0 files were moved to quarantine
    0 files were renamed
    1 Files cannot be scanned
    255933 Files not concerned
    1712 Archives were scanned
    1 Warnings
    49 Notes
    0