TR/Crypt.XPACK.Gen

Résolu
Bonjour,

Je travaille sur deux ordinateurs PC, l'un d'entre eux est connecté à internet. J'ai l'impression que celui qui n'est pas connecté à internet (sur lequel je n'ai aucun antivirus d'installé) est infecté par TR/Crypt.XPACK.Gen et certainement par d'autres virus encore... Ce qui me fait penser cela c'est qu'à chaque fois que je branche une clé USB ou disque dur externe provenant du PC non connecté sur le PC connecté (et muni d'antivirus), ces dernier me signalent le Trojan Horse TR/Crypt.XPACK.Gen .
- Comment puis-je me débarrasser de ce/ces infections sur le PC non connecté ?
- Comment puis je être certaine que mon PC connecté n'est pas en fin de compte infecté également ?

Merci par avance pour votre aide, ci-dessous les rapports HijackThis de mes deux PC:

PC non connecté à internet :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:24:56, on 27/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
End of file - 4322 bytes


PC connecté à internet:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:29:14, on 27/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\PowerKey.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\acer\Empowering Technology\ePower\epm-dm.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Acer\Empowering Technology\admtray.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Softwin\BitDefender8\bdnagent.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
c:\program files\softwin\bitdefender8\bdmcon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O1 - Hosts: 199.238.134.93 escrow.com
O1 - Hosts: 199.238.134.93 www.escrow.com
O1 - Hosts: 199.238.134.93 imgs.escrow.com ar Microsoft TCP/IP
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [EPM-DM] c:\acer\Empowering Technology\ePower\epm-dm.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender8\bdmcon.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\Program Files\Softwin\BitDefender8\bdnagent.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [EPSON Stylus D78 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBGE.EXE /FU "C:\WINDOWS\TEMP\E_S89.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Sample Toolband Serach - res://C:\WINDOWS\system32\ToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) -
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 12882 bytesConfiguration: Windows XP
Internet Explorer 7.0
Configuration: Windows XP
Internet Explorer 7.0

40 réponses

Résumé de la discussion

Deux ordinateurs présentent des signes d'infection, le PC hors connexion, dépourvu d’antivirus, semble affecté par TR/Crypt.XPACK.Gen et l’insertion de périphériques externes déclenche des alertes sur le PC relié. Pour le PC hors connexion, il faut préparer une clé USB bootable avec un antivirus portable et lancer un balayage complet hors ligne afin d’éliminer les infections sans connexion réseau. Sur le PC connecté, actualiser et exécuter des analyses complètes avec des solutions reconnues (antivirus et anti-malware), examiner les éléments de démarrage et les composants inhabituels pour détecter d’éventuelles persistance. En cas de doute persistant, éviter de réutiliser les mêmes supports non nettoyés et envisager une réinstallation propre ou un formatage ciblé après sauvegarde des données essentielles.

Bobot (l’IA à votre service)
  1. Modérateur
    "...De toute façon, je ne publierai pas mes adresses eMail sur un forum "public"
    A demain // DSL => je vais dormir"
    ---> Je ne te demande pas de poster ton adresse mail ici, je te demande simplement de m'envoyer ton adresse mail sur (adresse mail supprimée) pour que je puisse t'envoyer un mail qui n'a rien à voir avec la personne que j'essaie d'aider entre tes messages. C'est pas vrai, ça...
    1. Et ben... pas toujours facile la communication virtuelle !!!
      Merci à tous les deux, ça fait du bien de voir qu'une certaine forme de solidarité peut encore se trouver.
      Euh, on n'en a finit avec mes méchants virus ?
  2. Modérateur
    De rien, ça m'a fait plaisir de t'aider :)

    Bonne journée !
    1. Voilà le rapport:

      [ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]

      -->- Recherche:

      C:\Combofix.txt: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
      C:\Documents and Settings\Szrajber\Bureau\HijackThis.lnk: trouvé !
      C:\Program Files\Trend Micro\HijackThis: trouvé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

      Restauration annulée !
      ---------------------------------
      -->- Suppression:
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
      C:\Documents and Settings\Szrajber\Bureau\HijackThis.lnk: supprimé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
      C:\Combofix.txt: supprimé !
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
      C:\Program Files\Trend Micro\HijackThis: supprimé !
      1. Modérateur
        Comme le PC n'est pas connecté à Internet, je ne pense pas que ça sert à grand chose que je te donne Internet Explorer 7.

        ---> Télécharge CCleaner (N'installe pas la Yahoo Toolbar) :
        https://www.ccleaner.com/ccleaner/download

        ---> Lance-le. Va dans "Options" puis "Avancé", tu décoches la case "Effacer uniquement les fichiers etc...". Tu vas dans "Nettoyeur", tu fais "Analyse". Une fois terminé, tu lances le nettoyage. Puis tu vas dans "Registre", tu fais "Chercher des erreurs". Une fois terminé, tu répares toutes les erreurs sans sauvegarder la base de registre.

        ---> Télécharge Tools Cleaner sur ton bureau.
        http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
        Clique sur Recherche et laisse le scan agir.
        Clique sur Suppression pour finaliser.
        Tu peux, si tu le souhaites, te servir des Options facultatives.
        Clique sur Quitter pour obtenir le rapport.
        Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

        ---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
        http://www.infos-du-net.com/forum/272480-11-desactiver-activer-restauration-systeme

        ---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
        https://www.vulgarisation-informatique.com/creer-point-restauration.php
        1. Le nouveau rapport Hijackthis. Qu'en pensez vous docteur ?
          A priori je n'ai plus le pb que j'avais, c'est à dire que je peux passer mes disques externes d'un PC à l'autre sans que l'antivir ne me détecte des virus à chaque fois, et à chaque fois les même. Autrement, je n'avais pas réels soucis avec la machine infectées, rien qui m'empêchait de travailler en tous les cas (des messages d'erreurs parfois à l'allumage).

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 22:09:06, on 01/10/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\Tablet.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\WINDOWS\ALCWZRD.EXE
          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
          C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
          O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
          O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
          O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
          O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
          O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
          O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
          1. Modérateur
            Poste un nouveau rapport HijackThis et dis-moi si tu as encore des problèmes ou non.
            1. Modérateur
              Oui, bien sûr.
              1. Je me rends compte que j'ai trois rapports alors que je pensais n'avoir fait qu'un scan la première fois,...
                Bref, ci dessous et dans l'orde les 3 rapports:

                1-----------------------------

                Avira AntiVir Personal
                Report file date: mardi 30 septembre 2008 16:42

                Scanning for 1651060 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Boot mode: Save mode
                Username: Szrajber
                Computer name: SZRAJBER-EBD598

                Version information:
                BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 12:36:36
                ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:53:28
                ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 26/09/2008 13:56:58
                ANTIVIR3.VDF : 7.0.6.228 80896 Bytes 30/09/2008 09:10:40
                Engineversion : 8.1.1.35
                AEVDF.DLL : 8.1.0.5 102772 Bytes 02/04/2008 12:36:34
                AESCRIPT.DLL : 8.1.0.76 319867 Bytes 18/09/2008 12:03:16
                AESCN.DLL : 8.1.0.23 119156 Bytes 15/07/2008 13:58:46
                AERDL.DLL : 8.1.1.2 438644 Bytes 18/09/2008 12:03:16
                AEPACK.DLL : 8.1.2.3 364918 Bytes 24/09/2008 06:55:54
                AEOFFICE.DLL : 8.1.0.25 196986 Bytes 18/09/2008 12:03:16
                AEHEUR.DLL : 8.1.0.59 1438071 Bytes 18/09/2008 12:03:16
                AEHELP.DLL : 8.1.0.15 115063 Bytes 29/05/2008 12:08:42
                AEGEN.DLL : 8.1.0.36 315764 Bytes 18/08/2008 16:05:36
                AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 12:02:16
                AECORE.DLL : 8.1.1.11 172406 Bytes 03/09/2008 14:22:32
                AEBB.DLL : 8.1.0.1 53617 Bytes 18/07/2008 09:20:50
                AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                AVREP.DLL : 7.0.0.1 155688 Bytes 30/06/2008 14:35:20
                AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                Configuration settings for the scan:
                Jobname..........................: Complete system scan
                Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: C:, E:, H:, J:, K:,
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: All files
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium
                Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

                Start of the scan: mardi 30 septembre 2008 16:42

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                11 processes with 11 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [INFO] No virus was found!
                Boot sector 'E:\'
                [INFO] No virus was found!
                Boot sector 'H:\'
                [INFO] No virus was found!
                Boot sector 'J:\'
                [INFO] No virus was found!
                Boot sector 'K:\'
                [INFO] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '55' files ).

                Starting the file scan:

                Begin scan in 'C:\' <Windows>
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\WINDOWS\Nircmd.exe
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.2.B application
                [NOTE] The file was moved to '49544da4.qua'!
                Begin scan in 'E:\' <Audio-Vidéo>
                Begin scan in 'H:\' <My Passport>
                Begin scan in 'J:\' <Alekss>
                Begin scan in 'K:\' <ANYWAY>
                K:\System Volume Information\_restore{004AA4CB-CEFA-470B-84B6-7AE41AC1EA5D}\RP568\A0071409.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was moved to '491251fd.qua'!
                K:\System Volume Information\_restore{004AA4CB-CEFA-470B-84B6-7AE41AC1EA5D}\RP568\A0071410.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was moved to '49125203.qua'!

                End of the scan: mardi 30 septembre 2008 18:20
                Used time: 1:38:54 Hour(s)

                The scan has been done completely.

                4795 Scanning directories
                153965 Files were scanned
                3 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                3 files were moved to quarantine
                0 files were renamed
                1 Files cannot be scanned
                153961 Files not concerned
                611 Archives were scanned
                1 Warnings
                3 Notes

                2--------------------------------------------------------

                Avira AntiVir Personal
                Report file date: mardi 30 septembre 2008 18:29

                Scanning for 1651060 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Boot mode: Normally booted
                Username: SYSTEM
                Computer name: SZRAJBER-EBD598

                Version information:
                BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 12:36:36
                ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:53:28
                ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 26/09/2008 13:56:58
                ANTIVIR3.VDF : 7.0.6.228 80896 Bytes 30/09/2008 09:10:40
                Engineversion : 8.1.1.35
                AEVDF.DLL : 8.1.0.5 102772 Bytes 02/04/2008 12:36:34
                AESCRIPT.DLL : 8.1.0.76 319867 Bytes 18/09/2008 12:03:16
                AESCN.DLL : 8.1.0.23 119156 Bytes 15/07/2008 13:58:46
                AERDL.DLL : 8.1.1.2 438644 Bytes 18/09/2008 12:03:16
                AEPACK.DLL : 8.1.2.3 364918 Bytes 24/09/2008 06:55:54
                AEOFFICE.DLL : 8.1.0.25 196986 Bytes 18/09/2008 12:03:16
                AEHEUR.DLL : 8.1.0.59 1438071 Bytes 18/09/2008 12:03:16
                AEHELP.DLL : 8.1.0.15 115063 Bytes 29/05/2008 12:08:42
                AEGEN.DLL : 8.1.0.36 315764 Bytes 18/08/2008 16:05:36
                AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 12:02:16
                AECORE.DLL : 8.1.1.11 172406 Bytes 03/09/2008 14:22:32
                AEBB.DLL : 8.1.0.1 53617 Bytes 18/07/2008 09:20:50
                AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                AVREP.DLL : 7.0.0.1 155688 Bytes 30/06/2008 14:35:20
                AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                Configuration settings for the scan:
                Jobname..........................: Complete system scan
                Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: C:, E:, H:, J:, K:,
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: All files
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium
                Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

                Start of the scan: mardi 30 septembre 2008 18:29

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'Tablet.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                20 processes with 20 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [INFO] No virus was found!
                Boot sector 'E:\'
                [INFO] No virus was found!
                Boot sector 'H:\'
                [INFO] No virus was found!
                Boot sector 'J:\'
                [INFO] No virus was found!
                Boot sector 'K:\'
                [INFO] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '54' files ).

                Starting the file scan:

                Begin scan in 'C:\' <Windows>
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076814.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076815.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076844.dll
                [DETECTION] Is the TR/Vundo.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076849.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076850.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076903.dll
                [DETECTION] Is the TR/Vundo.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076908.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076909.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076917.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076918.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076926.dll
                [DETECTION] Is the TR/Vundo.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076938.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076939.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076957.dll
                [DETECTION] Is the TR/Vundo.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076963.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076964.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077011.dll
                [DETECTION] Is the TR/Vundo.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077016.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077017.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077064.dll
                [DETECTION] Is the TR/Vundo.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077069.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077070.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077076.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077077.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077087.dll
                [DETECTION] Is the TR/Vundo.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077092.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077093.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077101.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077102.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077110.exe
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077111.dll
                [DETECTION] Is the TR/Vundo.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077135.EXE
                [DETECTION] Contains recognition pattern of the APPL/PsExec.E application
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077150.exe
                [DETECTION] Contains recognition pattern of the SPR/Tool.Hide.A program
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077159.com
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.2.B application
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077177.exe
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.2.B application
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP269\A0077202.EXE
                [DETECTION] Contains recognition pattern of the APPL/PsExec.E application
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP269\A0077217.exe
                [DETECTION] Contains recognition pattern of the SPR/Tool.Hide.A program
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP269\A0077226.com
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.2.B application
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP269\A0077246.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP270\A0077281.exe
                [0] Archive type: RAR SFX (self extracting)
                --> 32788R22FWJFW\hidec.exe
                [DETECTION] Contains recognition pattern of the SPR/Tool.Hide.A program
                --> 32788R22FWJFW\NirCmd.cfexe
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.2.B application
                --> 32788R22FWJFW\nircmd.com
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.2.B application
                --> 32788R22FWJFW\NirCmdC.cfexe
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.1.B application
                --> 32788R22FWJFW\psexec.cfexe
                [1] Archive type: RSRC
                --> Object
                [DETECTION] Contains recognition pattern of the APPL/PsExec.E application
                [NOTE] The file was moved to '4912587e.qua'!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP271\A0077368.exe
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.2.B application
                [NOTE] The file was deleted!
                Begin scan in 'E:\' <Audio-Vidéo>
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076816.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076817.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076851.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076852.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076910.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076911.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076919.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076920.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076940.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076941.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076965.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0076966.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077018.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077019.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077071.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077072.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077078.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077079.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077094.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077095.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077103.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077104.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                E:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP269\A0077247.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                Begin scan in 'H:\' <My Passport>
                H:\System Volume Information\_restore{004AA4CB-CEFA-470B-84B6-7AE41AC1EA5D}\RP610\A0080875.exe
                [0] Archive type: RAR SFX (self extracting)
                --> 32788R22FWJFW\hidec.exe
                [DETECTION] Contains recognition pattern of the SPR/Tool.Hide.A program
                --> 32788R22FWJFW\NirCmd.cfexe
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.2.B application
                --> 32788R22FWJFW\nircmd.com
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.2.B application
                --> 32788R22FWJFW\NirCmdC.cfexe
                [DETECTION] Contains recognition pattern of the APPL/NirCmd.E.1.B application
                --> 32788R22FWJFW\psexec.cfexe
                [1] Archive type: RSRC
                --> Object
                [DETECTION] Contains recognition pattern of the APPL/PsExec.E application
                [NOTE] The file was moved to '49125ba2.qua'!
                Begin scan in 'J:\' <Alekss>
                J:\System Volume Information\_restore{004AA4CB-CEFA-470B-84B6-7AE41AC1EA5D}\RP564\A0070243.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{004AA4CB-CEFA-470B-84B6-7AE41AC1EA5D}\RP595\A0073100.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{004AA4CB-CEFA-470B-84B6-7AE41AC1EA5D}\RP595\A0073101.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076885.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076886.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077020.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP266\A0077021.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077097.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP267\A0077098.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077107.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP268\A0077108.inf
                [DETECTION] Contains recognition pattern of the WORM/Autorun.dtv worm
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP269\A0077249.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                J:\System Volume Information\_restore{B8A10E0C-7E71-439D-A903-AEC5A643C375}\RP402\A0096390.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                Begin scan in 'K:\' <ANYWAY>

                End of the scan: mardi 30 septembre 2008 19:03
                Used time: 33:54 Minute(s)

                The scan has been done completely.

                4864 Scanning directories
                155048 Files were scanned
                86 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                76 files were deleted
                0 files were repaired
                2 files were moved to quarantine
                0 files were renamed
                1 Files cannot be scanned
                154961 Files not concerned
                614 Archives were scanned
                1 Warnings
                78 Notes

                3------------------------------------------------------------------------------

                Avira AntiVir Personal
                Report file date: mardi 30 septembre 2008 18:29

                Scanning for 1651060 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Boot mode: Normally booted
                Username: SYSTEM
                Computer name: SZRAJBER-EBD598

                Version information:
                BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 12:36:36
                ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:53:28
                ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 26/09/2008 13:56:58
                ANTIVIR3.VDF : 7.0.6.228 80896 Bytes 30/09/2008 09:10:40
                Engineversion : 8.1.1.35
                AEVDF.DLL : 8.1.0.5 102772 Bytes 02/04/2008 12:36:34
                AESCRIPT.DLL : 8.1.0.76 319867 Bytes 18/09/2008 12:03:16
                AESCN.DLL : 8.1.0.23 119156 Bytes 15/07/2008 13:58:46
                AERDL.DLL : 8.1.1.2 438644 Bytes 18/09/2008 12:03:16
                AEPACK.DLL : 8.1.2.3 364918 Bytes 24/09/2008 06:55:54
                AEOFFICE.DLL : 8.1.0.25 196986 Bytes 18/09/2008 12:03:16
                AEHEUR.DLL : 8.1.0.59 1438071 Bytes 18/09/2008 12:03:16
                AEHELP.DLL : 8.1.0.15 115063 Bytes 29/05/2008 12:08:42
                AEGEN.DLL : 8.1.0.36 315764 Bytes 18/08/2008 16:05:36
                AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 12:02:16
                AECORE.DLL : 8.1.1.11 172406 Bytes 03/09/2008 14:22:32
                AEBB.DLL : 8.1.0.1 53617 Bytes 18/07/2008 09:20:50
                AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                AVREP.DLL : 7.0.0.1 155688 Bytes 30/06/2008 14:35:20
                AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                Configuration settings for the scan:
                Jobname..........................: Complete system scan
                Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: C:, E:, H:, J:, K:,
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: All files
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium
                Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

                Start of the scan: mardi 30 septembre 2008 18:29

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'Tablet.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                20 processes with 20 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [INFO] No virus was found!
                Boot sector 'E:\'
                [INFO] No virus was found!
                Boot sector 'H:\'
                [INFO] No virus was found!
                Boot sector 'J:\'
                [INFO] No virus was found!
                Boot sector 'K:\'
                [INFO] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '54' files ).

                Starting the file scan:

                Begin scan in 'C:\' <Windows>
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076814.com
                [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
                [NOTE] The file was deleted!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076844.dll
                [WARNING] The file could not be opened!
                C:\System Volume Information\_restore{8188D0DC-C06C-44BD-AD3E-5542C5E397A2}\RP265\A0076849.com
                [WARNING] The file could not be opened!
                Begin scan in 'E:\' <Audio-Vidéo>
                Begin scan in 'H:\' <My Passport>
                Begin scan in 'J:\' <Alekss>
                Begin scan in 'K:\' <ANYWAY>

                End of the scan: mardi 30 septembre 2008 19:12
                Used time: 43:12 Minute(s)

                The scan has been done completely.

                4864 Scanning directories
                154770 Files were scanned
                1 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                1 files were deleted
                0 files were repaired
                0 files were moved to quarantine
                0 files were renamed
                3 Files cannot be scanned
                154766 Files not concerned
                612 Archives were scanned
                3 Warnings
                1 Notes
            2. Mes confuses, je croyais l'avoir précisé dans un précédent message:
              Au premier scan avira a detecté un nombre important de fichiers infectés, que j'ai supprimé (fallait p'têtre pas...)
              J'ai refais ensuite un second et un troisième scan, et les rapports que je t'ai envoyé sont les derniers. Veux tu que j'envoie le premier rapport avec les infections ?
              1. Excuse-moi, je ne sais plus qui reçois mes réponses ou non.
                Ci-dessous:
                1- le rapport du scan avira que j'ai fais hier
                2- le dernier rapport du scan que j'ai refais aujourd'hui suites aux conseils de Le Sioux (modifs de configuration)

                1--------------------------------------------

                Avira AntiVir Personal
                Report file date: mardi 30 septembre 2008 19:20

                Scanning for 1651060 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Boot mode: Normally booted
                Username: SYSTEM
                Computer name: SZRAJBER-EBD598

                Version information:
                BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 12:36:36
                ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:53:28
                ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 26/09/2008 13:56:58
                ANTIVIR3.VDF : 7.0.6.228 80896 Bytes 30/09/2008 09:10:40
                Engineversion : 8.1.1.35
                AEVDF.DLL : 8.1.0.5 102772 Bytes 02/04/2008 12:36:34
                AESCRIPT.DLL : 8.1.0.76 319867 Bytes 18/09/2008 12:03:16
                AESCN.DLL : 8.1.0.23 119156 Bytes 15/07/2008 13:58:46
                AERDL.DLL : 8.1.1.2 438644 Bytes 18/09/2008 12:03:16
                AEPACK.DLL : 8.1.2.3 364918 Bytes 24/09/2008 06:55:54
                AEOFFICE.DLL : 8.1.0.25 196986 Bytes 18/09/2008 12:03:16
                AEHEUR.DLL : 8.1.0.59 1438071 Bytes 18/09/2008 12:03:16
                AEHELP.DLL : 8.1.0.15 115063 Bytes 29/05/2008 12:08:42
                AEGEN.DLL : 8.1.0.36 315764 Bytes 18/08/2008 16:05:36
                AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 12:02:16
                AECORE.DLL : 8.1.1.11 172406 Bytes 03/09/2008 14:22:32
                AEBB.DLL : 8.1.0.1 53617 Bytes 18/07/2008 09:20:50
                AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                AVREP.DLL : 7.0.0.1 155688 Bytes 30/06/2008 14:35:20
                AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                Configuration settings for the scan:
                Jobname..........................: Complete system scan
                Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                Logging..........................: low
                Primary action...................: quarantine
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: C:, E:, H:, J:, K:,
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: All files
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium
                Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

                Start of the scan: mardi 30 septembre 2008 19:20

                The scan of running processes will be started
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'acrotray.exe' - '1' Module(s) have been scanned
                Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
                Scan process 'iwctrl.exe' - '1' Module(s) have been scanned
                Scan process 'PCLETray.exe' - '1' Module(s) have been scanned
                Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'USBTip.exe' - '1' Module(s) have been scanned
                Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
                Scan process 'ALCWZRD.EXE' - '1' Module(s) have been scanned
                Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'Tablet.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                32 processes with 32 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [INFO] No virus was found!
                Boot sector 'E:\'
                [INFO] No virus was found!
                Boot sector 'H:\'
                [INFO] No virus was found!
                Boot sector 'J:\'
                [INFO] No virus was found!
                Boot sector 'K:\'
                [INFO] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '54' files ).

                Starting the file scan:

                Begin scan in 'C:\' <Windows>
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                Begin scan in 'E:\' <Audio-Vidéo>
                Begin scan in 'H:\' <My Passport>
                Begin scan in 'J:\' <Alekss>
                Begin scan in 'K:\' <ANYWAY>

                End of the scan: mardi 30 septembre 2008 19:40
                Used time: 20:08 Minute(s)

                The scan has been done completely.

                4863 Scanning directories
                154794 Files were scanned
                0 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                0 files were moved to quarantine
                0 files were renamed
                1 Files cannot be scanned
                154793 Files not concerned
                612 Archives were scanned
                1 Warnings
                0 Notes

                2------------------------------------------------------------

                Avira AntiVir Personal
                Report file date: mercredi 1 octobre 2008 20:37

                Scanning for 1651060 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Boot mode: Normally booted
                Username: Szrajber
                Computer name: SZRAJBER-EBD598

                Version information:
                BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 12:36:36
                ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:53:28
                ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 26/09/2008 13:56:58
                ANTIVIR3.VDF : 7.0.6.228 80896 Bytes 30/09/2008 09:10:40
                Engineversion : 8.1.1.35
                AEVDF.DLL : 8.1.0.5 102772 Bytes 02/04/2008 12:36:34
                AESCRIPT.DLL : 8.1.0.76 319867 Bytes 18/09/2008 12:03:16
                AESCN.DLL : 8.1.0.23 119156 Bytes 15/07/2008 13:58:46
                AERDL.DLL : 8.1.1.2 438644 Bytes 18/09/2008 12:03:16
                AEPACK.DLL : 8.1.2.3 364918 Bytes 24/09/2008 06:55:54
                AEOFFICE.DLL : 8.1.0.25 196986 Bytes 18/09/2008 12:03:16
                AEHEUR.DLL : 8.1.0.59 1438071 Bytes 18/09/2008 12:03:16
                AEHELP.DLL : 8.1.0.15 115063 Bytes 29/05/2008 12:08:42
                AEGEN.DLL : 8.1.0.36 315764 Bytes 18/08/2008 16:05:36
                AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 12:02:16
                AECORE.DLL : 8.1.1.11 172406 Bytes 03/09/2008 14:22:32
                AEBB.DLL : 8.1.0.1 53617 Bytes 18/07/2008 09:20:50
                AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                AVREP.DLL : 7.0.0.1 155688 Bytes 30/06/2008 14:35:20
                AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                Configuration settings for the scan:
                Jobname..........................: Manual Selection
                Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp
                Logging..........................: low
                Primary action...................: quarantine
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: A:, C:, D:, E:, F:, G:, H:, I:, J:, K:,
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: All files
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium
                Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

                Start of the scan: mercredi 1 octobre 2008 20:37

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'acrotray.exe' - '1' Module(s) have been scanned
                Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
                Scan process 'iwctrl.exe' - '1' Module(s) have been scanned
                Scan process 'PCLETray.exe' - '1' Module(s) have been scanned
                Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'USBTip.exe' - '1' Module(s) have been scanned
                Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
                Scan process 'ALCWZRD.EXE' - '1' Module(s) have been scanned
                Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
                Scan process 'Tablet.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                31 processes with 31 modules were scanned

                Start scanning boot sectors:
                Boot sector 'A:\'
                [INFO] In the drive 'A:\' no data medium is inserted!
                Boot sector 'C:\'
                [INFO] No virus was found!
                Boot sector 'E:\'
                [INFO] No virus was found!
                Boot sector 'H:\'
                [INFO] No virus was found!
                Boot sector 'I:\'
                [INFO] No virus was found!
                Boot sector 'J:\'
                [INFO] No virus was found!
                Boot sector 'K:\'
                [INFO] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '55' files ).

                Starting the file scan:

                Begin scan in 'A:\'
                Search path A:\ could not be opened!
                System error [21]: Le périphérique n'est pas prêt.
                Begin scan in 'C:\' <Windows>
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                Begin scan in 'D:\'
                Search path D:\ could not be opened!
                System error [21]: Le périphérique n'est pas prêt.
                Begin scan in 'E:\' <Audio-Vidéo>
                Begin scan in 'F:\'
                Search path F:\ could not be opened!
                System error [21]: Le périphérique n'est pas prêt.
                Begin scan in 'G:\'
                Search path G:\ could not be opened!
                System error [21]: Le périphérique n'est pas prêt.
                Begin scan in 'H:\' <My Passport>
                Begin scan in 'I:\' <ALEKS>
                Begin scan in 'J:\' <Alekss>
                Begin scan in 'K:\' <ANYWAY>

                End of the scan: mercredi 1 octobre 2008 20:57
                Used time: 20:05 Minute(s)

                The scan has been done completely.

                4842 Scanning directories
                154042 Files were scanned
                0 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                0 files were moved to quarantine
                0 files were renamed
                1 Files cannot be scanned
                154041 Files not concerned
                609 Archives were scanned
                1 Warnings
                0 Notes
                1. voilà,

                  J'ai tout fais comme tu me l'as dit, ci-dessous le rapport, merci :

                  Avira AntiVir Personal
                  Report file date: mercredi 1 octobre 2008 20:37

                  Scanning for 1651060 virus strains and unwanted programs.

                  Licensed to: Avira AntiVir PersonalEdition Classic
                  Serial number: 0000149996-ADJIE-0001
                  Platform: Windows XP
                  Windows version: (Service Pack 2) [5.1.2600]
                  Boot mode: Normally booted
                  Username: Szrajber
                  Computer name: SZRAJBER-EBD598

                  Version information:
                  BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                  AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                  AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                  LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                  LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                  ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 12:36:36
                  ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:53:28
                  ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 26/09/2008 13:56:58
                  ANTIVIR3.VDF : 7.0.6.228 80896 Bytes 30/09/2008 09:10:40
                  Engineversion : 8.1.1.35
                  AEVDF.DLL : 8.1.0.5 102772 Bytes 02/04/2008 12:36:34
                  AESCRIPT.DLL : 8.1.0.76 319867 Bytes 18/09/2008 12:03:16
                  AESCN.DLL : 8.1.0.23 119156 Bytes 15/07/2008 13:58:46
                  AERDL.DLL : 8.1.1.2 438644 Bytes 18/09/2008 12:03:16
                  AEPACK.DLL : 8.1.2.3 364918 Bytes 24/09/2008 06:55:54
                  AEOFFICE.DLL : 8.1.0.25 196986 Bytes 18/09/2008 12:03:16
                  AEHEUR.DLL : 8.1.0.59 1438071 Bytes 18/09/2008 12:03:16
                  AEHELP.DLL : 8.1.0.15 115063 Bytes 29/05/2008 12:08:42
                  AEGEN.DLL : 8.1.0.36 315764 Bytes 18/08/2008 16:05:36
                  AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 12:02:16
                  AECORE.DLL : 8.1.1.11 172406 Bytes 03/09/2008 14:22:32
                  AEBB.DLL : 8.1.0.1 53617 Bytes 18/07/2008 09:20:50
                  AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                  AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                  AVREP.DLL : 7.0.0.1 155688 Bytes 30/06/2008 14:35:20
                  AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                  AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                  AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                  SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                  SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                  NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                  RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                  RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                  Configuration settings for the scan:
                  Jobname..........................: Manual Selection
                  Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp
                  Logging..........................: low
                  Primary action...................: quarantine
                  Secondary action.................: ignore
                  Scan master boot sector..........: off
                  Scan boot sector.................: on
                  Boot sectors.....................: A:, C:, D:, E:, F:, G:, H:, I:, J:, K:,
                  Process scan.....................: on
                  Scan registry....................: on
                  Search for rootkits..............: off
                  Scan all files...................: All files
                  Scan archives....................: on
                  Recursion depth..................: 20
                  Smart extensions.................: on
                  Macro heuristic..................: on
                  File heuristic...................: medium
                  Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

                  Start of the scan: mercredi 1 octobre 2008 20:37

                  The scan of running processes will be started
                  Scan process 'avscan.exe' - '1' Module(s) have been scanned
                  Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                  Scan process 'alg.exe' - '1' Module(s) have been scanned
                  Scan process 'acrotray.exe' - '1' Module(s) have been scanned
                  Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
                  Scan process 'iwctrl.exe' - '1' Module(s) have been scanned
                  Scan process 'PCLETray.exe' - '1' Module(s) have been scanned
                  Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                  Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                  Scan process 'USBTip.exe' - '1' Module(s) have been scanned
                  Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
                  Scan process 'ALCWZRD.EXE' - '1' Module(s) have been scanned
                  Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
                  Scan process 'Tablet.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'avguard.exe' - '1' Module(s) have been scanned
                  Scan process 'explorer.exe' - '1' Module(s) have been scanned
                  Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'sched.exe' - '1' Module(s) have been scanned
                  Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'lsass.exe' - '1' Module(s) have been scanned
                  Scan process 'services.exe' - '1' Module(s) have been scanned
                  Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                  Scan process 'smss.exe' - '1' Module(s) have been scanned
                  31 processes with 31 modules were scanned

                  Start scanning boot sectors:
                  Boot sector 'A:\'
                  [INFO] In the drive 'A:\' no data medium is inserted!
                  Boot sector 'C:\'
                  [INFO] No virus was found!
                  Boot sector 'E:\'
                  [INFO] No virus was found!
                  Boot sector 'H:\'
                  [INFO] No virus was found!
                  Boot sector 'I:\'
                  [INFO] No virus was found!
                  Boot sector 'J:\'
                  [INFO] No virus was found!
                  Boot sector 'K:\'
                  [INFO] No virus was found!

                  Starting to scan the registry.
                  The registry was scanned ( '55' files ).

                  Starting the file scan:

                  Begin scan in 'A:\'
                  Search path A:\ could not be opened!
                  System error [21]: Le périphérique n'est pas prêt.
                  Begin scan in 'C:\' <Windows>
                  C:\pagefile.sys
                  [WARNING] The file could not be opened!
                  Begin scan in 'D:\'
                  Search path D:\ could not be opened!
                  System error [21]: Le périphérique n'est pas prêt.
                  Begin scan in 'E:\' <Audio-Vidéo>
                  Begin scan in 'F:\'
                  Search path F:\ could not be opened!
                  System error [21]: Le périphérique n'est pas prêt.
                  Begin scan in 'G:\'
                  Search path G:\ could not be opened!
                  System error [21]: Le périphérique n'est pas prêt.
                  Begin scan in 'H:\' <My Passport>
                  Begin scan in 'I:\' <ALEKS>
                  Begin scan in 'J:\' <Alekss>
                  Begin scan in 'K:\' <ANYWAY>

                  End of the scan: mercredi 1 octobre 2008 20:57
                  Used time: 20:05 Minute(s)

                  The scan has been done completely.

                  4842 Scanning directories
                  154042 Files were scanned
                  0 viruses and/or unwanted programs were found
                  0 Files were classified as suspicious:
                  0 files were deleted
                  0 files were repaired
                  0 files were moved to quarantine
                  0 files were renamed
                  1 Files cannot be scanned
                  154041 Files not concerned
                  609 Archives were scanned
                  1 Warnings
                  0 Notes
                  1. Contributeur sécurité
                    Salut schilmacks

                    Bien joué, par contre deux réglages à revoir :

                    Scan master boot sector..........: off
                    ...
                    Search for rootkits..............: off

                    Lance Avira antivir en faisant un double-clic sur le raccourci d’Antivir sur ton Bureau (ou via Démarrer /Tous les programmes /Antivir Personnal Edition Classique / Start Antivir Personnal Edition Classique ou via clic droit sur icone dans barre des tâches) puis «Start Antivir »
                    Clique sur Local protection (colonne à gauche) puis sur « Scanner » puis vérifie à RootKit search et Manuelle détection (en développant avec la petite croix devant chacun d'eux) que tous tes disques durs soient bien cochés, puis clique sur la loupe (en dessous de statut)
                    ...

                    Salut.
                    1. Et si, les machines pensent pour nous. Le rapport du tout dernier scan Avira:

                      Avira AntiVir Personal
                      Report file date: mardi 30 septembre 2008 19:20

                      Scanning for 1651060 virus strains and unwanted programs.

                      Licensed to: Avira AntiVir PersonalEdition Classic
                      Serial number: 0000149996-ADJIE-0001
                      Platform: Windows XP
                      Windows version: (Service Pack 2) [5.1.2600]
                      Boot mode: Normally booted
                      Username: SYSTEM
                      Computer name: SZRAJBER-EBD598

                      Version information:
                      BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                      AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                      AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                      LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                      LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 12:36:36
                      ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:53:28
                      ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 26/09/2008 13:56:58
                      ANTIVIR3.VDF : 7.0.6.228 80896 Bytes 30/09/2008 09:10:40
                      Engineversion : 8.1.1.35
                      AEVDF.DLL : 8.1.0.5 102772 Bytes 02/04/2008 12:36:34
                      AESCRIPT.DLL : 8.1.0.76 319867 Bytes 18/09/2008 12:03:16
                      AESCN.DLL : 8.1.0.23 119156 Bytes 15/07/2008 13:58:46
                      AERDL.DLL : 8.1.1.2 438644 Bytes 18/09/2008 12:03:16
                      AEPACK.DLL : 8.1.2.3 364918 Bytes 24/09/2008 06:55:54
                      AEOFFICE.DLL : 8.1.0.25 196986 Bytes 18/09/2008 12:03:16
                      AEHEUR.DLL : 8.1.0.59 1438071 Bytes 18/09/2008 12:03:16
                      AEHELP.DLL : 8.1.0.15 115063 Bytes 29/05/2008 12:08:42
                      AEGEN.DLL : 8.1.0.36 315764 Bytes 18/08/2008 16:05:36
                      AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 12:02:16
                      AECORE.DLL : 8.1.1.11 172406 Bytes 03/09/2008 14:22:32
                      AEBB.DLL : 8.1.0.1 53617 Bytes 18/07/2008 09:20:50
                      AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                      AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                      AVREP.DLL : 7.0.0.1 155688 Bytes 30/06/2008 14:35:20
                      AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                      AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                      SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                      RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                      RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                      Configuration settings for the scan:
                      Jobname..........................: Complete system scan
                      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                      Logging..........................: low
                      Primary action...................: quarantine
                      Secondary action.................: ignore
                      Scan master boot sector..........: off
                      Scan boot sector.................: on
                      Boot sectors.....................: C:, E:, H:, J:, K:,
                      Process scan.....................: on
                      Scan registry....................: on
                      Search for rootkits..............: off
                      Scan all files...................: All files
                      Scan archives....................: on
                      Recursion depth..................: 20
                      Smart extensions.................: on
                      Macro heuristic..................: on
                      File heuristic...................: medium
                      Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

                      Start of the scan: mardi 30 septembre 2008 19:20

                      The scan of running processes will be started
                      Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                      Scan process 'alg.exe' - '1' Module(s) have been scanned
                      Scan process 'acrotray.exe' - '1' Module(s) have been scanned
                      Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
                      Scan process 'iwctrl.exe' - '1' Module(s) have been scanned
                      Scan process 'PCLETray.exe' - '1' Module(s) have been scanned
                      Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                      Scan process 'USBTip.exe' - '1' Module(s) have been scanned
                      Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
                      Scan process 'ALCWZRD.EXE' - '1' Module(s) have been scanned
                      Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
                      Scan process 'explorer.exe' - '1' Module(s) have been scanned
                      Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                      Scan process 'Tablet.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'avguard.exe' - '1' Module(s) have been scanned
                      Scan process 'sched.exe' - '1' Module(s) have been scanned
                      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                      Scan process 'lsass.exe' - '1' Module(s) have been scanned
                      Scan process 'services.exe' - '1' Module(s) have been scanned
                      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                      Scan process 'csrss.exe' - '1' Module(s) have been scanned
                      Scan process 'smss.exe' - '1' Module(s) have been scanned
                      32 processes with 32 modules were scanned

                      Start scanning boot sectors:
                      Boot sector 'C:\'
                      [INFO] No virus was found!
                      Boot sector 'E:\'
                      [INFO] No virus was found!
                      Boot sector 'H:\'
                      [INFO] No virus was found!
                      Boot sector 'J:\'
                      [INFO] No virus was found!
                      Boot sector 'K:\'
                      [INFO] No virus was found!

                      Starting to scan the registry.
                      The registry was scanned ( '54' files ).

                      Starting the file scan:

                      Begin scan in 'C:\' <Windows>
                      C:\pagefile.sys
                      [WARNING] The file could not be opened!
                      Begin scan in 'E:\' <Audio-Vidéo>
                      Begin scan in 'H:\' <My Passport>
                      Begin scan in 'J:\' <Alekss>
                      Begin scan in 'K:\' <ANYWAY>

                      End of the scan: mardi 30 septembre 2008 19:40
                      Used time: 20:08 Minute(s)

                      The scan has been done completely.

                      4863 Scanning directories
                      154794 Files were scanned
                      0 viruses and/or unwanted programs were found
                      0 Files were classified as suspicious:
                      0 files were deleted
                      0 files were repaired
                      0 files were moved to quarantine
                      0 files were renamed
                      1 Files cannot be scanned
                      154793 Files not concerned
                      612 Archives were scanned
                      1 Warnings
                      0 Notes
                      1. ...j'imagine que le rapport ne s'enregistre pas automatiquement comme par magie dans un dossier ?...
                        Dans ce cas je ne l'ai pas, mais je peux refaire un scan et enregistrer le rapport cette fois ci
                        1. Contributeur sécurité
                          Bonjour

                          Tu télécharges le set up d antivir sur ta clef https://www.avira.com/en/downloads

                          ainsi que la dernière mise à jour ici https://www.avira.com/en/support-vdf-update-info

                          Puis une fois Antivir installé, clique droit sur celui-ci dans la barre des taches puis Start Antivir puis clique sur "Update" puis choisi "Manuel update" va "chercher" le zip ivdf_fusebundle_nt_en des mises à jour, clique sur OK et laisse faire ;) puis ferme Antivir quand ce sera terminé.

                          A refaire régulièrement pour qu'antivir soit à jour ;)

                          Rappel :

                          Paramètre le comme indiqué ici</gras> :
                          http://speedweb1.free.fr/frames2.php?page=tuto5
                          ou la : https://www.malekal.com/avira-free-security-antivirus-gratuit/

                          Salut.
                          1. Merci bôcoup !
                        2. Modérateur
                          ---> Désinstalle Norton avec ceci :
                          ftp://ftp.symantec.com/public/francais/removal_tools/Norton_Removal_Tool.exe

                          ---> Installe Antivir :
                          http://www.commentcamarche.net/telecharger/telecharger 55 antivir personal

                          Si tu veux la préversion française, elle est disponible ici :
                          https://www.mediafire.com/?sharekey=1ab12433e284b403d2db6fb9a8902bda
                          1. Ok, mais comment est ce que je peux le faire puisque ce PC n'est pas connecté à internet (je voulais justement le protéger de toute attaque) ? Si je charge le logiciel et le transfère par clé USB (comme combofix), je n'aurais pas la mise à jour, non ?
                        • 1
                        • 2