[Trojandownloader.xs] Abebot - Page 2

Résolu
  1. Toujours pas de nouvelle? Je veux pas paraître opressant, juste un petit rappel au cas où :)
    0
    1. Contributeur
      Non, pas de nouvelles, tu as essayé Antivir?
      0
      1. Désolé pour mon message précédant, je n'avais pas vu le tien. Mon problème semble s'être résolu tout seul, en effet ce matin en arrivant sur mon pc, je voyais en bas à droite une petite bulle qui me disais que windows avait du télécharger une mise à jour importante qui avait nécessité un redémarrage automatique. Depuis lors je pense ne plus avoir ces alertes, j'ai néanmoins fait un scan avec l'antivirus conseillé qui m'a détecté certains trucs (genre crackmirc et smitfraudfix que je sais ne sont pas des virus) mais aussi d'autres qui semblaient intéressant! Voici le rapport.

        AntiVir PersonalEdition Classic
        Report file date: mercredi 9 avril 2008 13:25

        Scanning for 1188780 virus strains and unwanted programs.

        Licensed to: Avira AntiVir PersonalEdition Classic
        Serial number: 0000149996-ADJIE-0001
        Platform: Windows XP
        Windows version: (Service Pack 2) [5.1.2600]
        Username: SYSTEM
        Computer name: ANTECMAT

        Version information:
        BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
        AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
        AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
        LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
        LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
        ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
        ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 7/03/2008 11:24:49
        ANTIVIR2.VDF : 7.0.3.127 649216 Bytes 7/04/2008 11:24:49
        ANTIVIR3.VDF : 7.0.3.137 67072 Bytes 9/04/2008 11:24:49
        AVEWIN32.DLL : 7.6.0.81 3424768 Bytes 9/04/2008 11:24:49
        AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
        AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
        AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
        AVPACK32.DLL : 7.6.0.3 360488 Bytes 9/04/2008 11:24:50
        AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
        AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
        AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
        NETNT.DLL : 7.0.0.0 7720 Bytes 8/03/2007 10:09:42
        RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 7/08/2007 11:38:13
        RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
        SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

        Configuration settings for the scan:
        Jobname..........................: Complete system scan
        Configuration file...............: h:\program files\avira\antivir personaledition classic\sysscan.avp
        Logging..........................: low
        Primary action...................: interactive
        Secondary action.................: ignore
        Scan master boot sector..........: off
        Scan boot sector.................: on
        Boot sectors.....................: H:,
        Scan memory......................: on
        Process scan.....................: on
        Scan registry....................: on
        Search for rootkits..............: off
        Scan all files...................: Intelligent file selection
        Scan archives....................: on
        Recursion depth..................: 20
        Smart extensions.................: on
        Macro heuristic..................: on
        File heuristic...................: medium

        Start of the scan: mercredi 9 avril 2008 13:25

        The scan of running processes will be started
        Scan process 'avscan.exe' - '1' Module(s) have been scanned
        Scan process 'avcenter.exe' - '1' Module(s) have been scanned
        Scan process 'sched.exe' - '1' Module(s) have been scanned
        Scan process 'avgnt.exe' - '1' Module(s) have been scanned
        Scan process 'avguard.exe' - '1' Module(s) have been scanned
        Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
        Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
        Scan process 'firefox.exe' - '1' Module(s) have been scanned
        Scan process 'alg.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
        Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
        Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
        Scan process 'DUSuperControler.exe' - '1' Module(s) have been scanned
        Scan process 'RocketDock.exe' - '1' Module(s) have been scanned
        Scan process 'DUSuperControler.exe' - '1' Module(s) have been scanned
        Scan process 'VeohClient.exe' - '1' Module(s) have been scanned
        Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
        Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
        Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
        Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
        Scan process 'fdm.exe' - '1' Module(s) have been scanned
        Scan process 'googletalk.exe' - '1' Module(s) have been scanned
        Scan process 'QTTask.exe' - '1' Module(s) have been scanned
        Scan process 'realsched.exe' - '1' Module(s) have been scanned
        Scan process 'jusched.exe' - '1' Module(s) have been scanned
        Scan process 'ashDisp.exe' - '1' Module(s) have been scanned
        Scan process 'type32.exe' - '1' Module(s) have been scanned
        Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
        Scan process 'G-vga.exe' - '1' Module(s) have been scanned
        Scan process 'rundll32.exe' - '1' Module(s) have been scanned
        Scan process 'rundll32.exe' - '1' Module(s) have been scanned
        Scan process 'explorer.exe' - '1' Module(s) have been scanned
        Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
        Scan process 'ashServ.exe' - '1' Module(s) have been scanned
        Scan process 'aswUpdSv.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'lsass.exe' - '1' Module(s) have been scanned
        Scan process 'services.exe' - '1' Module(s) have been scanned
        Scan process 'winlogon.exe' - '1' Module(s) have been scanned
        Scan process 'csrss.exe' - '1' Module(s) have been scanned
        Scan process 'smss.exe' - '1' Module(s) have been scanned
        46 processes with 46 modules were scanned

        Start scanning boot sectors:
        Boot sector 'C:\'
        [NOTE] No virus was found!
        Boot sector 'F:\'
        [NOTE] No virus was found!
        Boot sector 'H:\'
        [NOTE] No virus was found!

        Starting to scan the registry.
        The registry was scanned ( '32' files ).

        Starting the file scan:

        Begin scan in 'C:\' <HHD120>
        Begin scan in 'F:\' <HHD2>
        F:\Download\crack-mirc_v6.03.zip
        [0] Archive type: ZIP
        --> crack-mirc_v6.03/mIRC v6.03 Keygen.exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [INFO] The file was deleted!
        F:\Download\SmitfraudFix.exe
        [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.75
        [INFO] The file was deleted!
        F:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP346\A0037752.exe
        [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.75
        [INFO] The file was deleted!
        Begin scan in 'H:\' <WINDOWS>
        H:\pagefile.sys
        [WARNING] The file could not be opened!
        H:\Documents and Settings\All Users\Application Data\rwnapmng\vspsxipe.exe
        [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
        [INFO] The file was deleted!
        H:\Documents and Settings\Mat\Local Settings\Application Data\Microsoft\Messenger\insisni@gmail.com\Sharing Folders\david.grosjean@gmail.com\lentraineur20012002Francais.exe
        [0] Archive type: ACE SFX (self extracting)
        --> History\1.FC K”ln.his
        [WARNING] Error creating the file
        --> History\AC Milan.his
        [WARNING] No further files can be extracted from this archive. The archive will be closed
        [WARNING] No further files can be extracted from this archive. The archive will be closed
        H:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP257\A0023167.exe
        [0] Archive type: ACE SFX (self extracting)
        --> History\1.FC K”ln.his
        [WARNING] Error creating the file
        --> History\AC Milan.his
        [WARNING] No further files can be extracted from this archive. The archive will be closed
        [WARNING] No further files can be extracted from this archive. The archive will be closed
        H:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP257\A0023168.exe
        [0] Archive type: ACE SFX (self extracting)
        --> History\1.FC K”ln.his
        [WARNING] Error creating the file
        --> History\AC Milan.his
        [WARNING] No further files can be extracted from this archive. The archive will be closed
        [WARNING] No further files can be extracted from this archive. The archive will be closed
        H:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP331\A0033439.exe
        [0] Archive type: ACE SFX (self extracting)
        --> History\1.FC K”ln.his
        [WARNING] Error creating the file
        --> History\AC Milan.his
        [WARNING] No further files can be extracted from this archive. The archive will be closed
        [WARNING] No further files can be extracted from this archive. The archive will be closed
        H:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP331\A0033510.dll
        [DETECTION] Is the Trojan horse TR/Dldr.Agen.253952
        [INFO] The file was deleted!
        H:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP331\A0033518.dll
        [DETECTION] Is the Trojan horse TR/Dldr.Agen.253952
        [INFO] The file was deleted!
        H:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP338\A0034445.exe
        [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.75
        [INFO] The file was deleted!
        H:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP345\A0037546.exe
        [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
        [INFO] The file was deleted!
        H:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP345\A0037547.exe
        [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
        [INFO] The file was deleted!
        H:\System Volume Information\_restore{B509A2F1-F7D4-47D4-A469-5CF6D57CAB0E}\RP346\A0037755.exe
        [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
        [INFO] The file was deleted!
        H:\WINDOWS\system32\drivers\sptd.sys
        [WARNING] The file could not be opened!

        End of the scan: mercredi 9 avril 2008 14:16
        Used time: 50:55 min

        The scan has been done completely.

        7919 Scanning directories
        300721 Files were scanned
        10 viruses and/or unwanted programs were found
        0 Files were classified as suspicious:
        10 files were deleted
        0 files were repaired
        0 files were moved to quarantine
        0 files were renamed
        2 Files cannot be scanned
        300711 Files not concerned
        2002 Archives were scanned
        14 Warnings
        5 Notes
        0
        1. Contributeur
          10 virus trouvés! Chapeau Antivir. Bien content pour toi
          0
          1. Merci beaucoup de ton aide! Mon problème est résolu! ;)
            0
            Précédent
            • 1
            • 2