27/08-2007 à 23:34Bonsoir,
J'ai via msn accepter un téléchargement envoyé par un de mes contacts, mal m'en a pris il s'agissait d'un
virus ou assimilé...
Ce qui est "fort" c'est que ce virus nous contacte via la messagerie donc en direct met une phrase du genre "voila mes derniéres photos" et dans un second temps nous envoie la piéce à télécharger...
Suite à ce chargement j'ai eu une alerte de mon antivirus :
Avira Antivir Personnel Edition j'ai mis le dossier en quarantaine...
Cependant au redémarrage de mon pc j'ai toujours deux alertes :
-
Heur Malware dans 2 dossiers : C:/documents and settings/.../backup [1].zip et l'autre C:/s4.exe
Ce que j'ai fais pour le moment sans résultats :
- Spybot (pas de mouchards

)
- Ad-aware
- Ccleaner (un prog qui nettoie la bdr, élimine les cookies et fichiers temp)
- Suppression des fichiers temporaires manuellement et via CleanMgr
Je vous mets à toute fin utile le rapport de mon antivirus :
ntiVir PersonalEdition Classic
Report file date: lundi 27 août 2007 22:27
Scanning for 1035335 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: laurent
Computer name: LAURENT-8OX0VBM
Version information:
BUILD.DAT : 247 14437 Bytes 10/05/2007 11:55:00
AVSCAN.EXE : 7.0.4.15 282664 Bytes 30/04/2007 05:42:37
AVSCAN.DLL : 7.0.4.4 33832 Bytes 30/04/2007 05:42:37
LUKE.DLL : 7.0.4.11 143400 Bytes 30/04/2007 05:42:38
LUKERES.DLL : 7.0.4.0 10280 Bytes 30/04/2007 05:42:38
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 03:29:07
ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 10/07/2007 13:10:00
ANTIVIR2.VDF : 6.39.1.43 1542656 Bytes 25/08/2007 22:30:53
ANTIVIR3.VDF : 6.39.1.45 13824 Bytes 26/08/2007 22:30:53
AVEWIN32.DLL : 7.4.1.63 2724352 Bytes 26/08/2007 22:30:53
AVWINLL.DLL : 1.0.0.7 14376 Bytes 30/04/2007 05:42:37
AVPREF.DLL : 7.0.2.1 24616 Bytes 30/04/2007 05:42:37
AVREP.DLL : 7.0.0.1 155688 Bytes 30/04/2007 05:42:39
AVPACK32.DLL : 7.3.0.15 360488 Bytes 08/08/2007 19:04:03
AVREG.DLL : 7.0.1.2 31784 Bytes 30/04/2007 05:42:37
AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 30/04/2007 05:42:36
AVARKT.DLL : 1.0.0.17 278568 Bytes 10/05/2007 11:25:19
NETNT.DLL : 7.0.0.0 7720 Bytes 30/04/2007 05:42:38
RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 30/04/2007 05:42:29
RCTEXT.DLL : 7.0.45.0 86056 Bytes 30/04/2007 05:42:29
Configuration settings for the scan:
Jobname..........................: Local Hard Disks
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldiscs.avp
Logging..........................: low
Primary action...................: delete
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: G:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: lundi 27 août 2007 22:27
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'SpybotSD.exe' - '1' Module(s) have been scanned
Scan process 'Ad-Aware2007.exe' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'SetPoint.exe' - '1' Module(s) have been scanned
Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
Scan process 'qttask.exe' - '1' Module(s) have been scanned
Scan process '9wifi.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
33 processes with 33 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Boot sector 'G:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '16' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\All Users\Application Data\Exetender\Setup.exe
[WARNING] The file could not be read!
C:\Program Files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
[WARNING] The file could not be read!
C:\Program Files\HP\Photosmart Essential\AdvertisedPlugins.dll
[WARNING] The file could not be read!
C:\Program Files\HP\Temp\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpcommunication.dll
[WARNING] The file could not be read!
C:\WINDOWS\system32\HPZipr12.dll
[WARNING] The file could not be read!
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcoi12.dll
[WARNING] The file could not be read!
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzime12.dll
[WARNING] The file could not be read!
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzlnt12.dll
[WARNING] The file could not be read!
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpcl12.dll
[WARNING] The file could not be read!
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzvip12.dll
[WARNING] The file could not be read!
Begin scan in 'D:\' <Disque local>
Begin scan in 'G:\' <DD 25 Go>
End of the scan: lundi 27 août 2007 23:10
Used time: 43:36 min
The scan has been done completely.
3933 Scanning directories
215322 Files were scanned
0 viruses and/or unwanted programs were found
0 classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
11 Files cannot be scanned
215322 Files not concerned
2140 Archives were scanned
11 Warnings
0 Notes
0 Hidden objects were found
Merci de votre aide (qui sera double car le pc d'une amie est lui aussi atteind des mêmes maux)