Keylogger

Résolu
hunterbullet -  
 hunterbullet -
Bonjour,
comment savoir si il y a un keylogger sur son pc? Car je joue beaucoup aux jeux en ligne et je viens
de me rendre compte que j'ai visité beaucoup de site suspect.

Merci
A voir également:

104 réponses

hunterbullet
 
Le rapport c'est bien l'endroit ou est le virus le nom et le reste ?
0
Utilisateur anonyme
 
Il est dans le dossier d'Avira, le rapport.
0
hunterbullet
 
Sinon je peux aller dans reports ?
0
Utilisateur anonyme
 
Oui, t'as raison, ils sont là.
Poste le plus récent.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
hunterbullet
 
Puis je fais reports files
0
Utilisateur anonyme
 
Je sais pas, moi j'ai une nouvelle version et l'interface a changé...
0
hunterbullet
 
Avira AntiVir Personal
Report file date: jeudi 24 avril 2008 20:46

Scanning for 1236769 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows Vista
Windows version: (plain) [6.0.6000]
Boot mode: Normally booted
Username: SYSTEM
Computer name: PC-DE-MORGAN

Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 24/04/2008 18:45:26
AVSCAN.DLL : 8.1.1.0 53505 Bytes 24/04/2008 18:45:26
LUKE.DLL : 8.1.2.9 151809 Bytes 24/04/2008 18:45:26
LUKERES.DLL : 8.1.2.1 12033 Bytes 24/04/2008 18:45:26
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 18:45:26
ANTIVIR2.VDF : 7.0.3.197 1260032 Bytes 22/04/2008 18:45:27
ANTIVIR3.VDF : 7.0.3.209 113664 Bytes 24/04/2008 18:45:27
Engineversion : 8.1.0.32
AEVDF.DLL : 8.1.0.5 102772 Bytes 24/04/2008 18:45:27
AESCRIPT.DLL : 8.1.0.26 233850 Bytes 24/04/2008 18:45:27
AESCN.DLL : 8.1.0.14 119156 Bytes 24/04/2008 18:45:27
AERDL.DLL : 8.1.0.19 418164 Bytes 24/04/2008 18:45:27
AEPACK.DLL : 8.1.1.2 364917 Bytes 24/04/2008 18:45:27
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 24/04/2008 18:45:27
AEHEUR.DLL : 8.1.0.18 1167735 Bytes 24/04/2008 18:45:27
AEHELP.DLL : 8.1.0.14 115063 Bytes 24/04/2008 18:45:27
AEGEN.DLL : 8.1.0.17 299380 Bytes 24/04/2008 18:45:27
AEEMU.DLL : 8.1.0.5 430450 Bytes 24/04/2008 18:45:27
AECORE.DLL : 8.1.0.27 168310 Bytes 24/04/2008 18:45:27
AVWINLL.DLL : 1.0.0.7 14593 Bytes 24/04/2008 18:45:26
AVPREF.DLL : 8.0.0.1 25857 Bytes 24/04/2008 18:45:25
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVREG.DLL : 8.0.0.0 30977 Bytes 24/04/2008 18:45:25
AVARKT.DLL : 1.0.0.23 307457 Bytes 24/04/2008 18:45:24
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 24/04/2008 18:45:25
SQLITE3.DLL : 3.3.17.1 339968 Bytes 24/04/2008 18:45:26
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 24/04/2008 18:45:26
NETNT.DLL : 8.0.0.1 7937 Bytes 24/04/2008 18:45:26
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 24/04/2008 18:45:19
RCTEXT.DLL : 8.0.32.0 86273 Bytes 24/04/2008 18:45:19

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: jeudi 24 avril 2008 20:46

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'MpCmdRun.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'TrustedInstaller.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
Scan process 'razerofa.exe' - '1' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
Scan process 'iczuwtftn.exe' - '1' Module(s) have been scanned
Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
Scan process 'LightScribeControlPanel.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'sidebar.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'ashDisp.exe' - '1' Module(s) have been scanned
Scan process 'razerhid.exe' - '1' Module(s) have been scanned
Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'dwm.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
Scan process 'ashMaiSv.exe' - '1' Module(s) have been scanned
Scan process 'ashWebSv.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'SDWinSec.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ashServ.exe' - '1' Module(s) have been scanned
Scan process 'aswUpdSv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
67 processes with 67 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '12' files ).

Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Users\Morgan\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0cb63dd0\Report.cab
[0] Archive type: CAB (Microsoft)
--> ssunaxjlf.exe.xor
[1] Archive type: HIDDEN
--> MEM\AV00012b3d.AV$
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[NOTE] The file was moved to '4880d7eb.qua'!

End of the scan: jeudi 24 avril 2008 21:11
Used time: 24:30 min

The scan has been done completely.

11648 Scanning directories
217134 Files were scanned
1 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
1 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
217133 Files not concerned
1144 Archives were scanned
2 Warnings
1 Notes
0
hunterbullet
 
C'est ca?
0
Utilisateur anonyme
 
Oui, c'est bien ça, et apparemment c'est un virus qui a été mis en quarantaine par Windows Defender.
Et Antivir a détecté ce fichier mais ce fichier était inoffensif car quarantainé.

Et les deux WARNING c'est que antivir n'a pas pu scanner certains fichiers (mais ces fichiers sont sains)

Apparemment t'as pas de keyloggers, c'est clean! :)
0
hunterbullet
 
T'es sur par windows defender? parceque j'ai cliqué sur mettre en quarantaine a partir de antivir
0
hunterbullet
 
Ah ok windows defender m'avait pas avertis maintenant qu'il est en quarantaine je le suprime?
0
Utilisateur anonyme
 
Je suis sûr: Windows Defender a détecté le virus, l'a mis en quarantaine en changeant l'extension du fichier afin que personne ne l'exécute, et après Antivir a détecté le fichier de la quarantaine de Windows Defender et l'a mis dans la sienne.

C'est compliqué mais c'est ce qui s'est passé!
0
Utilisateur anonyme
 
Oui
0
hunterbullet
 
s'était bien un cheval de troie non?
0
Utilisateur anonyme
 
Plus précisément un Dropper.
Un dropper, c'est un virus qui "droppe" des virus sur ton PC.
En fait, il "largue" d'autres virus.
0
hunterbullet
 
Cool j'espère qu'il en a pas largué xD . Tu me conseil de changer tout les mots de passe de mes jeux?
0
Utilisateur anonyme
 
lol, il a pas eu le temps! ;-P

Non, c'est pas très utile de changer tout tes mots de passe de jeu.
0
hunterbullet
 
Et dit moi comment on nettoie un peu l'antivir?
0
hunterbullet
 
je veux dire après un scan ya rien a supprimer
0
Utilisateur anonyme
 
Si t'as mis des fichiers en quarantaine, efface-les.
C'est tout.
0