Antivir

Résolu
fosta Messages postés 72 Date d'inscription   Statut Membre Dernière intervention   -  
JADIDKHA Messages postés 2059 Statut Membre -
Bonjour,
on m' a conseiller de installer antivir et je l'ai installer...
j'ai lancer un scan complet...
je veux savoir si il m'a debarasser se toute les virus... il a detecter 22!
le rapport:

Avira AntiVir Personal
Report file date: lundi 14 avril 2008 16:55

Scanning for 1200839 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: FAMILIAL-3CE5D5

Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 14/04/2008 16:39:12
AVSCAN.DLL : 8.1.1.0 53505 Bytes 14/04/2008 16:39:12
LUKE.DLL : 8.1.2.9 151809 Bytes 14/04/2008 16:39:15
LUKERES.DLL : 8.1.2.1 12033 Bytes 14/04/2008 16:39:15
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 15:27:15
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 16:39:18
ANTIVIR2.VDF : 7.0.3.156 795136 Bytes 11/04/2008 16:39:18
ANTIVIR3.VDF : 7.0.3.163 92160 Bytes 14/04/2008 16:39:18
Engineversion : 8.1.0.30
AEVDF.DLL : 8.1.0.5 102772 Bytes 14/04/2008 16:39:21
AESCRIPT.DLL : 8.1.0.23 233851 Bytes 14/04/2008 16:39:21
AESCN.DLL : 8.1.0.13 115061 Bytes 14/04/2008 16:39:21
AERDL.DLL : 8.1.0.19 418164 Bytes 14/04/2008 16:39:20
AEPACK.DLL : 8.1.1.1 364918 Bytes 14/04/2008 16:39:20
AEOFFICE.DLL : 8.1.0.17 192891 Bytes 14/04/2008 16:39:20
AEHEUR.DLL : 8.1.0.18 1167735 Bytes 14/04/2008 16:39:19
AEHELP.DLL : 8.1.0.12 115063 Bytes 14/04/2008 16:39:19
AEGEN.DLL : 8.1.0.15 299379 Bytes 14/04/2008 16:39:19
AEEMU.DLL : 8.1.0.5 430450 Bytes 14/04/2008 16:39:19
AECORE.DLL : 8.1.0.26 168311 Bytes 14/04/2008 16:39:18
AVWINLL.DLL : 1.0.0.7 14593 Bytes 14/04/2008 16:39:12
AVPREF.DLL : 8.0.0.1 25857 Bytes 14/04/2008 16:39:12
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 14:16:24
AVREG.DLL : 8.0.0.0 30977 Bytes 14/04/2008 16:39:12
AVARKT.DLL : 1.0.0.23 307457 Bytes 14/04/2008 16:39:11
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 14/04/2008 16:39:11
SQLITE3.DLL : 3.3.17.1 339968 Bytes 14/04/2008 16:39:16
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 14/04/2008 16:39:15
NETNT.DLL : 8.0.0.1 7937 Bytes 14/04/2008 16:39:15
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 14/04/2008 16:38:54
RCTEXT.DLL : 8.0.32.0 86273 Bytes 14/04/2008 16:38:54

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: lundi 14 avril 2008 16:55

The scan of running processes will be started
Scan process 'taskmgr.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'IEMonitor.exe' - '1' Module(s) have been scanned
Scan process 'dslmon.exe' - '1' Module(s) have been scanned
Scan process 'IDMan.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Scan process 'GrooveMonitor.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'igfxtray.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
27 processes with 27 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '20' files ).

Starting the file scan:

Begin scan in 'C:\' <System>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\ayman\Local Settings\Temporary Internet Files\Content.IE5\11KN5JWM\Enterprise[1].exe
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\Documents and Settings\ayman\Local Settings\Temporary Internet Files\Content.IE5\1PFLRZHI\Enterprise[1].exe
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\Documents and Settings\ayman\Local Settings\Temporary Internet Files\Content.IE5\5W23Y9YO\tv[1].htm
[DETECTION] Contains suspicious code HEUR/HTML.Malware
[NOTE] The fund was classified as suspicious.
[NOTE] The file was moved to '485e92fc.qua'!
C:\Documents and Settings\ayman\Local Settings\Temporary Internet Files\Content.IE5\HTX7J3UW\eicarcom2[1].zip
[0] Archive type: ZIP
--> eicar_com.zip
[1] Archive type: ZIP
--> eicar.com
[DETECTION] Contains code of the Eicar-Test-Signature virus
[NOTE] The file was deleted!
C:\Documents and Settings\ayman_2\Application Data\Creative Amok Bind\Dvdstyleplatform.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\ayman_2\Application Data\Creative Amok Bind\IntraFlawHelpMpeg.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\ayman_2\Application Data\Creative Amok Bind\jtjiyalq.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\ayman_2\Application Data\Creative Amok Bind\uqvjsydy.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\ayman_2\Application Data\Creative Amok Bind\yhvcqnqr.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\ayman_2\Local Settings\Temp\bis1.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\ayman_2\Local Settings\Temp\bisC.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\ayman_2\Local Settings\Temp\sta1.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\ayman_2\Local Settings\Temp\sta3.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{34D853B8-8770-43F8-AFE2-A1F695A05E0B}\RP553\A0125318.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4834a099.qua'!
C:\System Volume Information\_restore{34D853B8-8770-43F8-AFE2-A1F695A05E0B}\RP553\A0125320.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4834a0a0.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP26\A0005643.exe
[DETECTION] Is the Trojan horse TR/Gendal.551137
[NOTE] The file was moved to '4833a17f.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP50\A0010698.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4833a1d6.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP50\A0010699.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4833a1d9.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP50\A0010700.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4833a1dd.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP50\A0010701.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4833a1e1.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP50\A0010702.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4833a1e7.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP50\A0010703.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4833a1eb.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP50\A0010704.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4833a1ee.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP50\A0010705.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4833a1f1.qua'!
C:\System Volume Information\_restore{88149DA2-56E4-467F-BB8A-D8D6ED4CE0C9}\RP50\A0010706.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '4833a1f5.qua'!
Begin scan in 'D:\'

End of the scan: lundi 14 avril 2008 18:36
Used time: 1:44:28 min
A voir également:

9 réponses

DeNisCoOl Messages postés 2871 Statut Membre 224
 
salut fosta,

Tu avais plusieurs l'infection Trojan horse TR/Dldr.Swizzor.Gen dans plusieurs fichiers.
La plupart ont été effacé mais les autres sont dans les fichiers restauration mais bloqué en quarantaine.

Désactiver la restauration système attendre qu'il travail puis l’activer de nouveau
Pour cela suivre les instructions du lien ICI

Ensuite tu pourras retourner dans Antivir pour surpprimer les fichiers qui ont été mis en quarantaine (.qua)

Pour compléter le réglage de Antivir:
Une fois Antivir ouvert clic sur configuration et coche la case "expert mode" puis sur l´onglet scanner dans la fenêtre du dessous tu va voir : rootkit search clic sur le petit + pour déployer et coche la case a coté de ton disk dur
puis click sur configuration en haut a droite; dans la nouvelle fenêtre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
Coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le désires.
Puis sur la droite coche les case suivantes :
Scan boot sectors of selected drives
Scan master boot sectors
Scan memory
Search for rootkit before scan
Decoche : ignore off line files
Toujours à gauche > scan > déploie > heuristique > macro virus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

Si tu utilises LIVE Messenger, alors clic sur Outils / Options / Transfert de fichiers / ‘’C:\Program Files\AVPersonal\AVGUARD.EXE‘’%1 <====== rajouter %1
Chaque fichier échangé avec MSN sera scanné.

A+

Denis
0
fosta Messages postés 72 Date d'inscription   Statut Membre Dernière intervention   5
 
j' ai peur que les fichier dans la quarantaine soivent des fichier system infecter.
0
fosta Messages postés 72 Date d'inscription   Statut Membre Dernière intervention   5
 
j' ai peur que les fichier dans la quarantaine soivent des fichier system infecter.
0
DeNisCoOl Messages postés 2871 Statut Membre 224
 
Re fosta,

Ensuite tu pourras retourner dans Antivir pour surpprimer les fichiers qui ont été mis en quarantaine (.qua)
Oui c'est ce que je disais tu peux les effacer maintenant.

Bye bye

Denis
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
JADIDKHA Messages postés 2059 Statut Membre 196
 
Et n'oublie pas de créer un nouveau point de restauration car tu n'en as plus maintenant.
0
DeNisCoOl Messages postés 2871 Statut Membre 224
 
salut fosta,

Merci JADIDKHA, mais comme j'avais indiqué ;-)
Désactiver la restauration système attendre qu'il travail puis l’activer de nouveau

A+
0
JADIDKHA Messages postés 2059 Statut Membre 196
 
oui je suis bien d'accord décocher puis recocher la case, mais prendre la précaution de créer un point de restauration en cas de plantage. Sans vouloir t'offenser, avec toutes mes excuses si je l'ai fait. OK A+
0
DeNisCoOl Messages postés 2871 Statut Membre 224
 
Salut,

Non non pas de problème ;-)

Quand on le réactive il crée un point de restauration assez rapidement voir immédiatement.

A+
0
JADIDKHA Messages postés 2059 Statut Membre 196
 
Merci. Trop cool !
0