J'ai formaté car l'ordinateur ne se rallumait plus, même en mode sans échec.
J'ai installé Avira Antivir et il m'a détecté des trojan, des malware, zango B Virus, bref plein de truc ds le fichier c: system volume restoration. Ils sont en quarantaine.
Pour l'instant, le Pc marche bien. Je te remercie pour ton aide, et si tu pouvais me décrypter le rapport et me dire que faire pour être définitivement débarrassé de ces méchantes bébêtes, je t'en serais gré.
Avira AntiVir Personal
Report file date: samedi 31 mai 2008 00:21
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
ANTIVIR2.VDF : 7.0.4.53 1848832 Bytes 17/05/2008 22:17:46
ANTIVIR3.VDF : 7.0.4.118 376832 Bytes 30/05/2008 22:17:56
Engineversion : 8.1.0.51
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.37 270715 Bytes 30/05/2008 22:18:33
AESCN.DLL : 8.1.0.20 119157 Bytes 30/05/2008 22:18:31
AERDL.DLL : 8.1.0.20 418165 Bytes 30/05/2008 22:18:29
AEPACK.DLL : 8.1.1.5 364918 Bytes 30/05/2008 22:18:23
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 30/05/2008 22:18:19
AEHEUR.DLL : 8.1.0.29 1253750 Bytes 30/05/2008 22:18:16
AEHELP.DLL : 8.1.0.15 115063 Bytes 30/05/2008 22:18:08
AEGEN.DLL : 8.1.0.25 307573 Bytes 30/05/2008 22:18:06
AEEMU.DLL : 8.1.0.6 430451 Bytes 30/05/2008 22:18:01
AECORE.DLL : 8.1.0.30 168311 Bytes 30/05/2008 22:17:58
AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 31 mai 2008 00:21
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'zaSetup_fr.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'Watch.exe' - '1' Module(s) have been scanned
Scan process 'ComComp.exe' - '1' Module(s) have been scanned
Scan process 'EspaceWanadoo.exe' - '1' Module(s) have been scanned
Scan process 'CnxMon.exe' - '1' Module(s) have been scanned
Scan process 'dslmon.exe' - '1' Module(s) have been scanned
Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'nvraidservice.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
31 processes with 31 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '32' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\User\Mes documents\alain\FileFormatConverters.exe
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\System Volume Information\_restore{4813E5C4-1699-4622-BD61-DBCF4F218DDE}\RP135\A0050496.sys
[DETECTION] Contains detection pattern of the rootkit RKIT/Agent.aol
[NOTE] The file was moved to '487086cd.qua'!
C:\System Volume Information\_restore{4813E5C4-1699-4622-BD61-DBCF4F218DDE}\RP135\A0050617.dll
[DETECTION] Is the Trojan horse TR/Agent.45056.138
[NOTE] The file was moved to '487086d7.qua'!
C:\System Volume Information\_restore{4813E5C4-1699-4622-BD61-DBCF4F218DDE}\RP135\A0050863.sys
[DETECTION] Contains detection pattern of the rootkit RKIT/Agent.aol
[NOTE] The file was moved to '487086e0.qua'!
C:\System Volume Information\_restore{4813E5C4-1699-4622-BD61-DBCF4F218DDE}\RP137\A0051013.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[NOTE] The file was moved to '487086e8.qua'!
C:\System Volume Information\_restore{B662776E-7328-4F6C-91ED-F78986AFF29B}\RP8\A0002965.dll
[DETECTION] Is the Trojan horse TR/Agent.30208
[NOTE] The file was moved to '4870888f.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP35\A0010919.dll
[DETECTION] Contains detection pattern of the ASDPY/Zango.B virus
[NOTE] The file was moved to '487088ec.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP35\A0010923.dll
[DETECTION] Is the Trojan horse TR/BHO.Zango.A
[NOTE] The file was moved to '491667c5.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP37\A0012228.dll
[DETECTION] Contains detection pattern of the ASDPY/Zango.B virus
[NOTE] The file was moved to '487088f4.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP37\A0012239.dll
[DETECTION] Is the Trojan horse TR/BHO.Zango.A
[NOTE] The file was moved to '491667dd.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP43\A0013512.dll
[DETECTION] Contains detection pattern of the ASDPY/Zango.B virus
[NOTE] The file was moved to '487088ff.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP43\A0013516.dll
[DETECTION] Is the Trojan horse TR/BHO.Zango.A
[NOTE] The file was moved to '49166628.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP43\A0013596.dll
[DETECTION] Contains detection pattern of the ASDPY/Zango.B virus
[NOTE] The file was moved to '48708901.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP43\A0013607.dll
[DETECTION] Is the Trojan horse TR/BHO.Zango.A
[NOTE] The file was moved to '4916662a.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP45\A0013980.dll
[DETECTION] Contains detection pattern of the ASDPY/Zango.B virus
[NOTE] The file was moved to '48708906.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP45\A0013984.dll
[DETECTION] Is the Trojan horse TR/BHO.Zango.A
[NOTE] The file was moved to '48708907.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP45\A0014065.dll
[DETECTION] Contains detection pattern of the ASDPY/Zango.B virus
[NOTE] The file was moved to '48708908.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP45\A0014076.dll
[DETECTION] Is the Trojan horse TR/BHO.Zango.A
[NOTE] The file was moved to '49166621.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP47\A0014329.dll
[DETECTION] Contains detection pattern of the ASDPY/Zango.B virus
[NOTE] The file was moved to '4870890c.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP47\A0014333.dll
[DETECTION] Is the Trojan horse TR/BHO.Zango.A
[NOTE] The file was moved to '4870890d.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP47\A0014413.dll
[DETECTION] Contains detection pattern of the ASDPY/Zango.B virus
[NOTE] The file was moved to '4870890e.qua'!
C:\System Volume Information\_restore{BE888896-C5BF-4E86-814C-ADC719F30E10}\RP47\A0014424.dll
[DETECTION] Is the Trojan horse TR/BHO.Zango.A
[NOTE] The file was moved to '49166627.qua'!
End of the scan: samedi 31 mai 2008 01:42
Used time: 1:20:50 min
The scan has been canceled!
7487 Scanning directories
188122 Files were scanned
21 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
21 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
188101 Files not concerned
625 Archives were scanned
2 Warnings
21 Notes