je dispause actuellement d'une machine avec Windows 2000,
j'ai Avast Anti Virus a jour ( aujourdui on es le 19 juillet 2005)
Avast me trouve un virus dans le fichier rdriv.sys dans c:\winnt\system32\rdriv.sys ( winnt etant mon repertoir root)
il le suprime mais quelques seconde seulement aprés il revien... j'ai pencer a une restoration du system automatique ( cf windows XP) mais je ne l'ais pas trouver sur windows 2000
j'ai parcourue le Web en me disant qu'une solution a surement dejas etait trouver, mais rien de trés concluents, j'ai entre autre lancer le petit utilitaire rdrivrem.bat il m'indique le log suivant en fin de traitement :
~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~ rdriv.sys PRESENT! ItunesMusic.exe NOT PRESENT! wkssvc.exe NOT PRESENT! ~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~ rdriv.sys PRESENT! ItunesMusic.exe NOT PRESENT! wkssvc.exe NOT PRESENT!
Si j'execute ce petit utilitaire en mode sans echeques voici ce que j'obtien :
~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~ rdriv.sys PRESENT! ItunesMusic.exe NOT PRESENT! wkssvc.exe NOT PRESENT! ~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~ rdriv.sys NOT PRESENT! ItunesMusic.exe NOT PRESENT! wkssvc.exe NOT PRESENT!
mais dés que je redémare normalement il revien comme si j'avais une restoration system - je vous rapelle que je suis sous Windows 2000...
voici un petit journal de avast :
19/07/2005 14:37:33 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 14:40:43 HONNFO 1428 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 15:12:33 HONNFO 1264 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 15:17:32 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 15:19:20 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\RECYCLER\S-1-5-21-1454471165-1708537768-1202660629-1000\Dc25.sys" file.
19/07/2005 15:19:39 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 15:19:49 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 15:20:02 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 15:20:29 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 15:22:56 HONNFO 584 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 15:23:09 HONNFO 1384 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 16:00:06 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 16:01:05 HONNFO 1316 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 16:04:25 HONNFO 1092 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 16:04:34 HONNFO 1340 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 16:04:43 HONNFO 1092 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 19:44:01 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 20:54:03 HONNFO 920 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 21:12:46 HONNFO 1224 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 21:21:23 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
19/07/2005 21:27:25 SYSTEM 472 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\WINNT\system32\rdriv.sys" file.
cela montre bien qu'il s'agit de ce fichier ( meme aprés des scann durant le démarage windows )
et voici un petit log hijackthis
