Volledige versie bekijken : Bitdefender slaat alarm



fryum
6 December 2006, 09:40
bij mijn laatste scan met bitdefender 9 kreeg ik volgend rapport :

//-----------------------------------------------------------------
//
// Product: BitDefender 9 Professional Plus
// Version: 9.5
//
// Created on: 05/12/2006 16:36:36
//
//-----------------------------------------------------------------


Statistics

Scan path : C:\
Folders : 9427
Files : 527528
Archives : 2100
Packed files : 45818
Identified viruses : 4
Infected files : 4
Warnings : 0
Suspect files : 4
Disinfected files : 0
Deleted files : 0
Copied files : 2
Moved files : 1
Renamed files : 0
I/O errors : 47
Scan time : 01:29:03
Scan speed (files/sec) : 98

Spyware Statistics

Memory processes scanned : 33
Memory processes infected : 0
Registry keys scanned : 1840
Registry keys infected : 0
Cookies scanned : 35
Cookies infected : 0
Spyware files infected : 0
Spyware threats detected : 0


Virus definitions : 351458
Scan plugins : 16
Archive plugins : 41
Unpack plugins : 6
Mail plugins : 6
System plugins : 5

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Second action
[ ] Ignore
[ ] Delete
[ ] Copy to quarantine
[X] Move to quarantine
[ ] Rename
[ ] Prompt user

Scan options
[X] Enable warnings
[X] Enable heuristics
[ ] Show all files in log
[X] Report file: C:\Program Files\Softwin\BitDefender9\Logs\vscan_1165332996.l og

Spyware scan options

[X] Memory Processes
[X] Registry keys
[X] Cookies


Summary:

C:\Documents and Settings\Fryum\Local Settings\Application Data\Identities\{6D79718C-1BF2-416D-BB87-61B8145F775B}\Microsoft\Outlook Express\alt.crack.nl.dbx=>(message 1)=>[Subject: Pr0n!][Date: 6 Apr 2006 18:00:59 -0500]=>(MIME part)=>(MIME part)=>(message body) Suspect: Exploit.Iframe.Vulnerability
C:\Documents and Settings\Fryum\Local Settings\Application Data\Identities\{6D79718C-1BF2-416D-BB87-61B8145F775B}\Microsoft\Outlook Express\alt.crack.nl.dbx=>(message 1)=>[Subject: Pr0n!][Date: 6 Apr 2006 18:00:59 -0500]=>(MIME part)=>(MIME part)=>(message body) Copy failed
C:\Documents and Settings\Fryum\Local Settings\Application Data\Identities\{6D79718C-1BF2-416D-BB87-61B8145F775B}\Microsoft\Outlook Express\alt.crack.nl.dbx=>(message 1)=>[Subject: Pr0n!][Date: 6 Apr 2006 18:00:59 -0500]=>(MIME part)=>message.zip=>message.htm Infected: Generic.XPL.CodeBase.C376BAA7
C:\Documents and Settings\Fryum\Local Settings\Application Data\Identities\{6D79718C-1BF2-416D-BB87-61B8145F775B}\Microsoft\Outlook Express\alt.crack.nl.dbx=>(message 1)=>[Subject: Pr0n!][Date: 6 Apr 2006 18:00:59 -0500]=>(MIME part)=>message.zip=>message.htm Disinfection failed
C:\Documents and Settings\Fryum\Local Settings\Application Data\Identities\{6D79718C-1BF2-416D-BB87-61B8145F775B}\Microsoft\Outlook Express\alt.crack.nl.dbx=>(message 1)=>[Subject: Pr0n!][Date: 6 Apr 2006 18:00:59 -0500]=>(MIME part)=>message.zip=>message.htm=>(JAVASCRIPT 1) Infected: Generic.XPL.CodeBase.C97245DD
C:\Documents and Settings\Fryum\Local Settings\Application Data\Identities\{6D79718C-1BF2-416D-BB87-61B8145F775B}\Microsoft\Outlook Express\alt.crack.nl.dbx=>(message 1)=>[Subject: Pr0n!][Date: 6 Apr 2006 18:00:59 -0500]=>(MIME part)=>message.zip=>message.htm=>(unknown) Infected: Win32.Torvil.D@mm
C:\Documents and Settings\Fryum\Local Settings\Application Data\Identities\{6D79718C-1BF2-416D-BB87-61B8145F775B}\Microsoft\Outlook Express\alt.crack.nl.dbx=>(message 1)=>[Subject: Pr0n!][Date: 6 Apr 2006 18:00:59 -0500]=>(MIME part)=>message.zip=>message.htm=>(unknown) Disinfection failed
C:\Documents and Settings\Fryum\Local Settings\Application Data\Identities\{6D79718C-1BF2-416D-BB87-61B8145F775B}\Microsoft\Outlook Express\alt.crack.nl.dbx=>(message 1)=>[Subject: Pr0n!][Date: 6 Apr 2006 18:00:59 -0500]=>(MIME part)=>message.zip=>message.htm=>(unknown) Move failed
C:\Documents and Settings\Fryum\Local Settings\Temporary Internet Files\Content.IE5\1PO48FGQ\d[2].htm Infected: JS.Trojan.Downloader.IstBar.A
C:\Documents and Settings\Fryum\Local Settings\Temporary Internet Files\Content.IE5\1PO48FGQ\d[2].htm Disinfection failed
C:\Documents and Settings\Fryum\Local Settings\Temporary Internet Files\Content.IE5\1PO48FGQ\d[2].htm Moved
C:\Documents and Settings\Fryum\Local Settings\Temporary Internet Files\Content.IE5\N5LDCU23\wbk2E.tmp Suspect: Exploit.Iframe.Vulnerability
C:\Documents and Settings\Fryum\Local Settings\Temporary Internet Files\Content.IE5\N5LDCU23\wbk2E.tmp Copied
C:\Documents and Settings\Fryum\Local Settings\Temporary Internet Files\Content.IE5\N5LDCU23\wbk2E.tmp=>(IFRAME) Suspect: Exploit.Iframe.Vulnerability
C:\Documents and Settings\Fryum\Local Settings\Temporary Internet Files\Content.IE5\N5LDCU23\wbk2E.tmp=>(IFRAME) Copy failed
C:\Documents and Settings\Fryum\Wahr Suspect: JS.Trojan.Downloader.IstBar.M
C:\Documents and Settings\Fryum\Wahr Copied

moet ik nog iets doen, of is alles 'veilig' ?

nojs
6 December 2006, 11:30
Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Je hebt dus aangevraagd om hem te de-infecteren. Zelf kruis ik altijd verwijderen aan omdat je dan zeker bent dat het weg is. Maar dat is een persoonlijke keuze. Als je niet zeker bent: laat hem nog eens draaien in veilige modus en doe er dan AVG anti-spyware ook maarbij, in veilige modus.

berger
6 December 2006, 13:13
Persoonlijk zou ik ook nog de tijdelijke internetbestanden wegdoen, bvb met ATF Cleaner :

http://www.atribune.org/ccount/click.php?id=1

Dubbelklik ATF-Cleaner.exe om het te starten.
Onder Main kies je: Select All
Klik de Empty Selected knop.
Indien je Firefox gebruikt
Klik Firefox bovenaan in het menu en vink aan: Select All
Klik de Empty Selected knop.
NOTA: Indien je je wachtwoorden wilt behouden, klik No bij de melding wat betreft passwords.