Vundo ou autre chose?
lachoukrate
-
Eliane -
Eliane -
Bonjour,
Depuis deux jours j'ai lu un paquet de postes, mais malgré les aides que ca m'a apporté, j'ai pas réussi à trouver mon probleme exact. J'ai installé spybot, ccleaner, hijackthis, avg spyware. Mais mon probleme vient d'un probleme de "crc check failed", mon antivir ne marche plus, soit une mauvaise manip de ma part, soit un virus... Lorsque j'essaie de l'enlever ou de le réinstaller, il veut pas!!! J'ai essayé d'installer avg antivirus, mais lors de l'installation il me dit une erreur est survenue, et s'arrete. En gros je n'ai plus d'antivirus opérationnel.
Tout a l'heure une page antivirus 2009 signé windows xp, s'est ouverte sans que je l'autorise et m'a fait un scan en me disant que j'avais : spyware.iemonster.b, zlob.pornadvertiser.xplisit (c'est sexuel??? :-)) et trojan.infostealer.banker.s. Je sens que mon ordi va me lacher :-( Je n'ai pas de disque d'install de windows (2000) et j'aimerai éviter le formatage.
Je suis pas douée en informatique, j'apprends sur le tas. Mais grace à toutes vos réponses je commence à etre callée en désinfection d'ordi, mais pas suffisamment hélas pour sauver le mien.
J'ai des logs de hijackthis et spybot.
Merci à celui qui pourra m'aider
et merci à tous pour votre aide si précieuse meme si c'est pas en direct, j'ai compris énormément de choses en lisant vos réponses...
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 16:41:23 05/01/2009
+ Résultat de l'analyse:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignoré.
HKU\S-1-5-21-57989841-602162358-682003330-1000\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@247realmedia[1].txt -> TrackingCookie.247realmedia : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@247realmedia[2].txt -> TrackingCookie.247realmedia : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@2o7[2].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@autoscout24.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@electronicarts.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@himedia.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@notrefamille.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@parship.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@veohnetwork.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adbrite[2].txt -> TrackingCookie.Adbrite : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@dynamic.media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@media.adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adtech[2].txt -> TrackingCookie.Adtech : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@adtech[1].txt -> TrackingCookie.Adtech : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@advertising[1].txt -> TrackingCookie.Advertising : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@advertising[2].txt -> TrackingCookie.Advertising : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@bluestreak[2].txt -> TrackingCookie.Bluestreak : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@casinotropez[1].txt -> TrackingCookie.Casinotropez : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@com[1].txt -> TrackingCookie.Com : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@estat[1].txt -> TrackingCookie.Estat : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@estat[1].txt -> TrackingCookie.Estat : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@www.etracker[1].txt -> TrackingCookie.Etracker : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@fastclick[2].txt -> TrackingCookie.Fastclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@hitbox[1].txt -> TrackingCookie.Hitbox : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ivwbox[2].txt -> TrackingCookie.Ivwbox : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@search.live[1].txt -> TrackingCookie.Live : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ie.search.msn[1].txt -> TrackingCookie.Msn : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@ie.search.msn[2].txt -> TrackingCookie.Msn : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@overture[1].txt -> TrackingCookie.Overture : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@smartadserver[2].txt -> TrackingCookie.Smartadserver : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@smartadserver[1].txt -> TrackingCookie.Smartadserver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@specificclick[2].txt -> TrackingCookie.Specificclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@statcounter[2].txt -> TrackingCookie.Statcounter : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@toplist[1].txt -> TrackingCookie.Toplist : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@cms.trafficmp[1].txt -> TrackingCookie.Trafficmp : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@aem.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@agircarrco.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@aimfar.solution.weborama[1].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@boursoramabanque.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@cetelem.solution.weborama[1].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@cnam.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@dolcegusto16avril11juin.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@francecredit2.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@interhome.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@intermarche.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@nespresso.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@samsung.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@sanofi.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@vivelledop.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@banquepopulaire.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@boursoramabanque.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@intermarche.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@content.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@zedo[1].txt -> TrackingCookie.Zedo : Ignoré.
Fin du rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:40:18, on 05/01/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\WINNT\system\msddll.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ScsiAccess.EXE
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\Program Files\QuickTime\qttask.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINNT\system32\sysmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINNT\system32\sistray.exe
C:\Program Files\MultiRes\MultiRes.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINNT\system32\NOTEPAD.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jeuxvideo-flash.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww17.ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\Mctray.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINNT\system32\sysmgr.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: MultiRes.lnk = C:\Program Files\MultiRes\MultiRes.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINNT\system32\sistray.exe
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Events Log (Event) - Unknown owner - C:\WINNT\system32\drivers\csrss.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: m43158.exe - Unknown owner - \\82.253.79.183\Admin$\m75034.exe (file missing)
O23 - Service: m46247.exe - Unknown owner - \\82.253.79.183\Admin$\m53463.exe (file missing)
O23 - Service: McAfee Security Agent Taskbar Extension. - Unknown owner - C:\WINNT\Mctray.exe (file missing)
O23 - Service: msddll - Unknown owner - C:\WINNT\system\msddll.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: ptssvc - Unknown owner - D:\Kodak EasyShare software\bin\ptssvc.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\system32\ScsiAccess.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VMwareService - Unknown owner - C:\WINNT\system\VMwareService.exe
O23 - Service: Windows Spool Services (WinSpoolSvc) - Unknown owner - C:\WINNT\system32\csrsc.exe (file missing)
Depuis deux jours j'ai lu un paquet de postes, mais malgré les aides que ca m'a apporté, j'ai pas réussi à trouver mon probleme exact. J'ai installé spybot, ccleaner, hijackthis, avg spyware. Mais mon probleme vient d'un probleme de "crc check failed", mon antivir ne marche plus, soit une mauvaise manip de ma part, soit un virus... Lorsque j'essaie de l'enlever ou de le réinstaller, il veut pas!!! J'ai essayé d'installer avg antivirus, mais lors de l'installation il me dit une erreur est survenue, et s'arrete. En gros je n'ai plus d'antivirus opérationnel.
Tout a l'heure une page antivirus 2009 signé windows xp, s'est ouverte sans que je l'autorise et m'a fait un scan en me disant que j'avais : spyware.iemonster.b, zlob.pornadvertiser.xplisit (c'est sexuel??? :-)) et trojan.infostealer.banker.s. Je sens que mon ordi va me lacher :-( Je n'ai pas de disque d'install de windows (2000) et j'aimerai éviter le formatage.
Je suis pas douée en informatique, j'apprends sur le tas. Mais grace à toutes vos réponses je commence à etre callée en désinfection d'ordi, mais pas suffisamment hélas pour sauver le mien.
J'ai des logs de hijackthis et spybot.
Merci à celui qui pourra m'aider
et merci à tous pour votre aide si précieuse meme si c'est pas en direct, j'ai compris énormément de choses en lisant vos réponses...
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 16:41:23 05/01/2009
+ Résultat de l'analyse:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignoré.
HKU\S-1-5-21-57989841-602162358-682003330-1000\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@247realmedia[1].txt -> TrackingCookie.247realmedia : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@247realmedia[2].txt -> TrackingCookie.247realmedia : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@2o7[2].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@autoscout24.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@electronicarts.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@himedia.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@notrefamille.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@parship.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@veohnetwork.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adbrite[2].txt -> TrackingCookie.Adbrite : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@dynamic.media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@media.adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adtech[2].txt -> TrackingCookie.Adtech : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@adtech[1].txt -> TrackingCookie.Adtech : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@advertising[1].txt -> TrackingCookie.Advertising : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@advertising[2].txt -> TrackingCookie.Advertising : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@bluestreak[2].txt -> TrackingCookie.Bluestreak : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@casinotropez[1].txt -> TrackingCookie.Casinotropez : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@com[1].txt -> TrackingCookie.Com : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@estat[1].txt -> TrackingCookie.Estat : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@estat[1].txt -> TrackingCookie.Estat : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@www.etracker[1].txt -> TrackingCookie.Etracker : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@fastclick[2].txt -> TrackingCookie.Fastclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@hitbox[1].txt -> TrackingCookie.Hitbox : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ivwbox[2].txt -> TrackingCookie.Ivwbox : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@search.live[1].txt -> TrackingCookie.Live : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ie.search.msn[1].txt -> TrackingCookie.Msn : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@ie.search.msn[2].txt -> TrackingCookie.Msn : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@overture[1].txt -> TrackingCookie.Overture : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@smartadserver[2].txt -> TrackingCookie.Smartadserver : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@smartadserver[1].txt -> TrackingCookie.Smartadserver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@specificclick[2].txt -> TrackingCookie.Specificclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@statcounter[2].txt -> TrackingCookie.Statcounter : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@toplist[1].txt -> TrackingCookie.Toplist : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@cms.trafficmp[1].txt -> TrackingCookie.Trafficmp : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@aem.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@agircarrco.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@aimfar.solution.weborama[1].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@boursoramabanque.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@cetelem.solution.weborama[1].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@cnam.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@dolcegusto16avril11juin.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@francecredit2.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@interhome.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@intermarche.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@nespresso.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@samsung.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@sanofi.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@vivelledop.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@banquepopulaire.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@boursoramabanque.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@intermarche.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@content.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@zedo[1].txt -> TrackingCookie.Zedo : Ignoré.
Fin du rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:40:18, on 05/01/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\WINNT\system\msddll.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ScsiAccess.EXE
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\Program Files\QuickTime\qttask.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINNT\system32\sysmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINNT\system32\sistray.exe
C:\Program Files\MultiRes\MultiRes.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINNT\system32\NOTEPAD.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jeuxvideo-flash.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww17.ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\Mctray.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINNT\system32\sysmgr.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: MultiRes.lnk = C:\Program Files\MultiRes\MultiRes.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINNT\system32\sistray.exe
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Events Log (Event) - Unknown owner - C:\WINNT\system32\drivers\csrss.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: m43158.exe - Unknown owner - \\82.253.79.183\Admin$\m75034.exe (file missing)
O23 - Service: m46247.exe - Unknown owner - \\82.253.79.183\Admin$\m53463.exe (file missing)
O23 - Service: McAfee Security Agent Taskbar Extension. - Unknown owner - C:\WINNT\Mctray.exe (file missing)
O23 - Service: msddll - Unknown owner - C:\WINNT\system\msddll.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: ptssvc - Unknown owner - D:\Kodak EasyShare software\bin\ptssvc.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\system32\ScsiAccess.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VMwareService - Unknown owner - C:\WINNT\system\VMwareService.exe
O23 - Service: Windows Spool Services (WinSpoolSvc) - Unknown owner - C:\WINNT\system32\csrsc.exe (file missing)
A voir également:
- Vundo ou autre chose?
- Flouter quelque chose sur une photo - Guide
- Image ours polaire sur une plage qui cache quelque chose - Forum Graphisme
- Quelque chose de tres lent - Guide
- Retrouver l'image originale après avoir fait des modifications ? ✓ - Forum Windows
- Sur la plage... - Forum Loisirs / Divertissements
282 réponses
bonsoir,
j'ai bien fait combofix /killal, mais j'ai oublié de redémarrer l'ordi pour lancer avg tool, c'est grave docteur? lol
le scan avg me trouve quand meme un paquet de virut.q. Vu l'heure tardive à laquelle ca va se terminer je vais aller me coucher, et j'entamerai la desinfection des fichiers dès le réveil, et tu me diras ce que je devrai faire. Je vais installer la version gratuite de kaspersky (durée d'un mois) au lieu d'antivir, qui ne veut toujours pas s'installer (enfin j'ai pas réessayé encore, mais vu que la somme CRC de ... ne lui convient pas je vais en tester un autre) Une fois que ce sera remis en état, je reviendrai à antivir.
bonne nuit :-)
j'ai bien fait combofix /killal, mais j'ai oublié de redémarrer l'ordi pour lancer avg tool, c'est grave docteur? lol
le scan avg me trouve quand meme un paquet de virut.q. Vu l'heure tardive à laquelle ca va se terminer je vais aller me coucher, et j'entamerai la desinfection des fichiers dès le réveil, et tu me diras ce que je devrai faire. Je vais installer la version gratuite de kaspersky (durée d'un mois) au lieu d'antivir, qui ne veut toujours pas s'installer (enfin j'ai pas réessayé encore, mais vu que la somme CRC de ... ne lui convient pas je vais en tester un autre) Une fois que ce sera remis en état, je reviendrai à antivir.
bonne nuit :-)
Bonjour,
tu postes le rapport et je suggère de recommencer tout de suite un scan AVP Tool.
A chaque fois tu postes le rapport que je vois comment ça évolue.
tu postes le rapport et je suggère de recommencer tout de suite un scan AVP Tool.
A chaque fois tu postes le rapport que je vois comment ça évolue.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
bonjour a vous deux :-)
Voici le scan fait hier soir
Je n'arrive toujours pas a installer antivir, il repete inlassablement que la somme CRC a été modifié, ca peut etre du à un virus.....
Scan
----
Scanned: 230161
Detected: 898
Untreated: 3
Start time: 2009-01-26 00:18
Duration: 01:37:39
Finish time: 2009-01-26 01:56
Detected
--------
Status Object
------ ------
disinfected: virus Virus.Win32.Virut.q File: D:\RECYCLER\S-1-5-21-57989841-602162358-682003330-1000\Dd1\hpwuSchd2.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Product Assistant\bin\hprbUpdate.exe
not found: virus Virus.Win32.Virut.q File: D:\HP Software Update\hpwuSchd2.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\util\common\hpzghl12.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzmsi01.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\common\drivers\com_os\hpztbx12.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\common\drivers\com_os\hpzeng12.exe
disinfected: virus Virus.Win32.Virut.q File: d:\digital imaging\unload\hpqpsmon.exe
disinfected: virus Virus.Win32.Virut.q File: d:\digital imaging\unload\hpqphunl.exe
disinfected: virus Virus.Win32.Virut.q File: d:\digital imaging\unload\hpqapkil.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpqtra08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpqpprop.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpqEmlsz.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hposvc08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpostl08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpospd08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hposid01.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hposfx08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpofxs08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpofxm08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpoews01.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpfccopy.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\DestTest.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\PASnap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\Monitor.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\KillTray.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\DeINF.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\CleanDev.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\AMCap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sisagp\SiS7012\Uninst\uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\WinXP_2K\InstFunc.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\WinXP64\InstFunc.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\utilDLL\LCDMode.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\setupDLL\waitwnd.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\setupDLL\Progress.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\setupDLL\IsUninst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\USB\Win9x\SiSFiles\Mp_s3.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\USB\Win2K_XP\WinXPUSB\SiSUSBrg.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\SISfiles\waitwnd.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\SISfiles\ata133ap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\SISfiles\AMDInst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\sl119\sl119\WINXP2K\uninst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\sl119\sl119\SRV2003\uninst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\waitwnd.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\SisFilter.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\infinstall.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\HDinfo.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\DMA98.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\ata133ap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\IDE\IdeUtil\SISIDE.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\IDE\IdeUtil\PropInstall.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\USB\Win9x\SiSFiles\Mp_s3.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\USB\Win2K_XP\WinXPUSB\SiSUSBrg.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\SISfiles\waitwnd.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\SISfiles\ata133ap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\SISfiles\AMDInst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\WS03XP64\Uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\WinXP\Uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\win95_98\SiSsynth.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\Win2000\Uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\WAITWND.EXE
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\srv2003\Uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\NT40\SISUIAUD.EXE
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\AudiRack\unAuRack.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\AudiRack\AudiRack.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\App\unDrvApp.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\App\SoundMan.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\App\SiSaudUt.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\App\SiSAudHk.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\SiS7012\Uninst\uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\zip.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\winrep.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\winhlp32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\welcome.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\VFIND.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\upwizun.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\unvise32qt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\twunk_32.exe
deleted: virus Email-Worm.Win32.Iksmas.de File: C:\WINNT\temp\TMP5.tmp
deleted: virus Email-Worm.Win32.Iksmas.de File: C:\WINNT\temp\TMP1E.tm_
deleted: virus Email-Worm.Win32.Iksmas.de File: C:\WINNT\temp\TMP10.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BNF.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BN24.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BN20.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BN12.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BN10.tmp
deleted: Trojan program Trojan-Dropper.Win32.Small.azk File: C:\WINNT\temp\0.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\TASKMAN.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system\SmWizard.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Écran de veille des chaînes.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\xcopy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wzcsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wupdmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\write.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\wpnpinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winver.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winmsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winmine.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\winhlp32.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\windres.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\windres.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Windows Media\Server\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wextract.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\System32\WBEM\WinMgmt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\wbemtest.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\unsecapp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\scrcons.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\mofcomp.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\vmware-ufad.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\vmware-ufad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\verifier.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\utilman.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\userinit.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ups.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\updcrl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\unlodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tracert.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\tlntsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tlntsess.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tlntadmn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\themes.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\telnet.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tcpsvcs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tcmsetup.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\taskmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\taskman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\systray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sysocmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\syskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\syncapp.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\svchost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\subst.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\stisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\stimon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sstext3d.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssstars.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sspipes.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmyst.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmaze.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmarque.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssflwbox.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssbezier.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ss3dfo.scr
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\spoolsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\spiisupd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sp4iis.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sort.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sol.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\smlogsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\skeys.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\sistray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sigverif.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\shrpubw.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\shmgrate.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sfc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\setup\wmpocm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\setreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sethc.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\secedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\scrnsave.scr
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\scardsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\savedump.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\runonce.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rundll32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\runas.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rsvp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\routemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\route.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\replace.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\regwiz.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\regwiz.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\regsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\regedt32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\reg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\recover.exe
detected: Trojan program Backdoor.Win32.Small.hik File: C:\WINNT\System32\reader_s.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rcp.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rasphone.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasdial.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasautou.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\QuickTime\QuickTimeUpdateHelper.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\QuickTime\QTPluginInstaller.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\PROXYCFG.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\proquota.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\progman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\print.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\posix.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ping.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\perfmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pentnt.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\pdbcopy.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\pdbcopy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pax.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pathping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\packager.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\osk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\os2srv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\os2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\odbcconf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\odbcad32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nwscript.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ntsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ntdsutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nslookup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\npp\nppagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\netstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\netsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nddeapir.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nbtstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\narrator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mstinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\msswchx.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mspmspsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\msiregmv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\msdtc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mrinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mpnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mplay32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mountvol.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mobsync.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mnmsrvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\migpwd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\makecab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\magnify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lpr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lpq.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\logon.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lodctr.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\locator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lnkstub.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lights.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\javaws.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\javaw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\java.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\irftp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipxroute.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\iexpress.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ieshwiz.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ie4uinit.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\i386kd.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\i386kd.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\hpzipm12.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\HPZinw12.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\hostname.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\hhupd.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\hhupd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\help.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\GRPCONV.EXE
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\gcc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\freecell.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\forcedos.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\fixmapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\finger.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\findstr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\find.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\fc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\faxsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxsend.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxqueue.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxcover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\extrac32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\export\encinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\expand.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\eudcedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\esentutl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dxdllreg.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\drwtsn32.exe
deleted: Trojan program Rootkit.Win32.Agent.jj File: c:\winnt\system32\drivers\protect.sys
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\drivers\kodakccs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dpvsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dpnsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\doskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dmremote.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\dmadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllhst3g.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllhost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\xcopy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wzcsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wupdmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\write.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wpnpinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wordpad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winver.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wins.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winrep.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winmsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winmine.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winmgmt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\WINLOGON.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winhstb.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winhlp32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wextract.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\welcome.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wbemtest.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wbemperm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wb32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wangimg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\WABMIG.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\WAB.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\w32tm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\verifier.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\vcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\utilman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\userinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\upwizun.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ups.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\unsecapp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\unregmp2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\unlodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\twunk_32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tracert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tlntsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tlntsess.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tlntadmn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\themes.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\telnet.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tcptest.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tcpsvcs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tcmsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\taskmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\taskman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\systray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sysocmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\syskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\syncapp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\svchost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\subst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\stisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\stimon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\spoolsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sort.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\snmptrap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\snmp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sndvol32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sndrec32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\smtp_regtrace.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\smlogsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\skeys.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sigverif.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\shtml.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\shrpubw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\shmgrate.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sfc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\setup50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\setreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sethc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\secedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\scrcons.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\scardsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\savedump.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\runonce.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rundll32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\runas.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsvp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\routemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\route.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\replace.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regsvr32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regedt32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\recover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rcp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasphone.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasdial.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasautou.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\qtest32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pwstray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pws.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\proquota.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\progman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\print.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pinball.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\perfmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pentnt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pax.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pathping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\packager.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\osk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\os2srv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\os2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\OEMIG50.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcconf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcad32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nwscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntdsutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntbackup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nslookup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nppagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\notepad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\net1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nddeapir.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nbtstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\narrator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwssw32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwremind.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwmdmsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcsw32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcpyrt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcloadw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcload.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mtstocom.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msswchx.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mspaint.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msinfo32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\MSIMN.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mshta.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msdtc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mrinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqexchng.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqbkup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mq1sync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mpnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplayer2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplay32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mountvol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mofcomp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mobsync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mnmsrvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migregdb.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migpwd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migisol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\makecab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\magnify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpq.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\locator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lnkstub.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\LLSSRV.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lights.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\label.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakprv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakimg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\isignup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\irftp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipxroute.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\internat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpuex.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imagemap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iissync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisrstas.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisreset.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexpress.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexplore.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ieshwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ie4uinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwtutor.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwrmind.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\htimage.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hostname.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\help.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\gameenum.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\freecell.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpremadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpcount.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpadmcgi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fp98swin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fp98sadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fortutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\forcedos.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fltmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fixmapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\finger.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\findstr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\find.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxsend.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxqueue.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxcover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\extrac32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\explorer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\expand.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\evntwin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\evntcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\eventvwr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\eudcedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\esentutl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\encinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\drwtsn32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\doskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dmremote.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dmadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dllhst3g.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dllhost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\diskperf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\discover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\diantz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dialer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dfrgntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dfrgfat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\delttsul.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ddmprxy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ddeshare.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dcomcnfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cplexe.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\convlog.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\convert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\control.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\conime.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\conf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comrereg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comrepl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\compact.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comclust.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmstp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmmon32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmmgr32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmdl32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\CMD.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cluster.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clussvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ClusCfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clipsrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clipbrd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cleanmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ckcnv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cipher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cidaemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\chkntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\charmap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cfgwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cdplayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cb32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\calc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cacls.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\bootvrfy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\bootok.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\author.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\attrib.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\atmadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\at.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\arp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\admin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\actmovie.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\accwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\diskperf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\diantz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dfrgntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dfrgfat.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\deviceemulator.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\deviceemulator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ddmprxy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ddeshare.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dcomcnfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\convert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\control.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\conime.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\compact.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\comp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\comclust.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Com\comrereg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Com\comrepl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmstp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmmon32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\cmmgr32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmirmdrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmdl32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmd.execf
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CMD.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cluster.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\clipsrv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\clipbrd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cliconfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cleanmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ckcnv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\cisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cipher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cidaemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\chkntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CHKDSK.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\charmap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CF11233.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CF10965.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cdplayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\calc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cacls.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\bootvrfy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\bootok.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\attrib.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\atmadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\at.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\arp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\actmovie.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\actcontroller.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\actcontroller.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\accwiz.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\7z.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\7z.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWXCACLS.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWSC.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWREG.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Speech\vcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\fa4b0db30b43f91158e7521435d65d29\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\f8be264a53925fc5b1c9668562b23365\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm9l\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm9\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm71\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\b5cae5c643ad60578df1bfab32fbcb38\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\ad9c4c2a779933f83b51a49a2c88838d\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\7e2a6ab8c08390d6ca0624962723abb4\wm41\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\6bd7eb68d000be3199ca46f3c39521ac\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wordpad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wms\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wins.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\winlogon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\w32tm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\netmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\llssrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\fltmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\cmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\clussvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\cluscfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\254ef2369b4f2311a1e81cf87ee93d47\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SiS\900\uninst.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\services.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\services.ex_
disinfected:
Voici le scan fait hier soir
Je n'arrive toujours pas a installer antivir, il repete inlassablement que la somme CRC a été modifié, ca peut etre du à un virus.....
Scan
----
Scanned: 230161
Detected: 898
Untreated: 3
Start time: 2009-01-26 00:18
Duration: 01:37:39
Finish time: 2009-01-26 01:56
Detected
--------
Status Object
------ ------
disinfected: virus Virus.Win32.Virut.q File: D:\RECYCLER\S-1-5-21-57989841-602162358-682003330-1000\Dd1\hpwuSchd2.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Product Assistant\bin\hprbUpdate.exe
not found: virus Virus.Win32.Virut.q File: D:\HP Software Update\hpwuSchd2.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\util\common\hpzghl12.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzmsi01.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\common\drivers\com_os\hpztbx12.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\common\drivers\com_os\hpzeng12.exe
disinfected: virus Virus.Win32.Virut.q File: d:\digital imaging\unload\hpqpsmon.exe
disinfected: virus Virus.Win32.Virut.q File: d:\digital imaging\unload\hpqphunl.exe
disinfected: virus Virus.Win32.Virut.q File: d:\digital imaging\unload\hpqapkil.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpqtra08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpqpprop.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpqEmlsz.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hposvc08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpostl08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpospd08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hposid01.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hposfx08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpofxs08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpofxm08.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpoews01.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\hpfccopy.exe
disinfected: virus Virus.Win32.Virut.q File: D:\Digital Imaging\bin\DestTest.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\PASnap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\Monitor.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\KillTray.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\DeINF.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\CleanDev.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\VGA USB Camera\AMCap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sisagp\SiS7012\Uninst\uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\WinXP_2K\InstFunc.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\WinXP64\InstFunc.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\utilDLL\LCDMode.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\setupDLL\waitwnd.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\setupDLL\Progress.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\setupDLL\IsUninst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\USB\Win9x\SiSFiles\Mp_s3.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\USB\Win2K_XP\WinXPUSB\SiSUSBrg.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\SISfiles\waitwnd.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\SISfiles\ata133ap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\uvga3_373\3[1].73Logo\373_Logo\Setup\AGPPack\SISfiles\AMDInst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\sl119\sl119\WINXP2K\uninst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\sl119\sl119\SRV2003\uninst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\waitwnd.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\SisFilter.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\infinstall.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\HDinfo.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\DMA98.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\SISfiles\ata133ap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\IDE\IdeUtil\SISIDE.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\ide204a\R204a\IDE\IdeUtil\PropInstall.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\USB\Win9x\SiSFiles\Mp_s3.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\USB\Win2K_XP\WinXPUSB\SiSUSBrg.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\SISfiles\waitwnd.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\SISfiles\ata133ap.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\agp121\agp121\SISfiles\AMDInst.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\WS03XP64\Uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\WinXP\Uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\win95_98\SiSsynth.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\Win2000\Uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\WAITWND.EXE
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\srv2003\Uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\NT40\SISUIAUD.EXE
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\AudiRack\unAuRack.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\AudiRack\AudiRack.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\App\unDrvApp.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\App\SoundMan.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\App\SiSaudUt.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\sis\a12112d\a12112d\App\SiSAudHk.exe
disinfected: virus Virus.Win32.Virut.q File: D:\ASUS Terminator P4_fichiers\SiS7012\Uninst\uninst2k.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\zip.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\winrep.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\winhlp32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\welcome.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\VFIND.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\upwizun.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\unvise32qt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\twunk_32.exe
deleted: virus Email-Worm.Win32.Iksmas.de File: C:\WINNT\temp\TMP5.tmp
deleted: virus Email-Worm.Win32.Iksmas.de File: C:\WINNT\temp\TMP1E.tm_
deleted: virus Email-Worm.Win32.Iksmas.de File: C:\WINNT\temp\TMP10.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BNF.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BN24.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BN20.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BN12.tmp
deleted: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BN10.tmp
deleted: Trojan program Trojan-Dropper.Win32.Small.azk File: C:\WINNT\temp\0.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\TASKMAN.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system\SmWizard.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Écran de veille des chaînes.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\xcopy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wzcsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wupdmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\write.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\wpnpinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winver.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winmsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winmine.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\winhlp32.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\windres.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\windres.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Windows Media\Server\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wextract.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\System32\WBEM\WinMgmt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\wbemtest.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\unsecapp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\scrcons.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\mofcomp.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\vmware-ufad.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\vmware-ufad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\verifier.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\utilman.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\userinit.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ups.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\updcrl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\unlodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tracert.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\tlntsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tlntsess.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tlntadmn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\themes.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\telnet.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tcpsvcs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tcmsetup.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\taskmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\taskman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\systray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sysocmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\syskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\syncapp.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\svchost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\subst.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\stisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\stimon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sstext3d.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssstars.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sspipes.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmyst.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmaze.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmarque.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssflwbox.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssbezier.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ss3dfo.scr
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\spoolsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\spiisupd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sp4iis.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sort.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sol.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\smlogsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\skeys.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\sistray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sigverif.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\shrpubw.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\shmgrate.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sfc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\setup\wmpocm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\setreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sethc.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\secedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\scrnsave.scr
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\scardsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\savedump.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\runonce.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rundll32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\runas.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rsvp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\routemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\route.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\replace.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\regwiz.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\regwiz.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\regsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\regedt32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\reg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\recover.exe
detected: Trojan program Backdoor.Win32.Small.hik File: C:\WINNT\System32\reader_s.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rcp.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rasphone.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasdial.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasautou.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\QuickTime\QuickTimeUpdateHelper.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\QuickTime\QTPluginInstaller.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\PROXYCFG.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\proquota.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\progman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\print.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\posix.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ping.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\perfmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pentnt.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\pdbcopy.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\pdbcopy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pax.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pathping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\packager.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\osk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\os2srv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\os2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\odbcconf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\odbcad32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nwscript.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ntsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ntdsutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nslookup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\npp\nppagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\netstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\netsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nddeapir.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nbtstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\narrator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mstinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\msswchx.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mspmspsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\msiregmv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\msdtc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mrinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mpnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mplay32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mountvol.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mobsync.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mnmsrvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\migpwd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\makecab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\magnify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lpr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lpq.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\logon.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lodctr.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\locator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lnkstub.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lights.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\javaws.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\javaw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\java.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\irftp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipxroute.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\iexpress.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ieshwiz.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ie4uinit.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\i386kd.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\i386kd.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\hpzipm12.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\HPZinw12.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\hostname.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\hhupd.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\hhupd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\help.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\GRPCONV.EXE
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\gcc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\freecell.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\forcedos.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\fixmapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\finger.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\findstr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\find.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\fc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\faxsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxsend.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxqueue.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxcover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\extrac32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\export\encinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\expand.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\eudcedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\esentutl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dxdllreg.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\drwtsn32.exe
deleted: Trojan program Rootkit.Win32.Agent.jj File: c:\winnt\system32\drivers\protect.sys
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\drivers\kodakccs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dpvsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dpnsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\doskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dmremote.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\dmadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllhst3g.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllhost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\xcopy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wzcsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wupdmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\write.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wpnpinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wordpad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winver.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wins.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winrep.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winmsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winmine.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winmgmt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\WINLOGON.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winhstb.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winhlp32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wextract.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\welcome.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wbemtest.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wbemperm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wb32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wangimg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\WABMIG.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\WAB.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\w32tm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\verifier.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\vcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\utilman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\userinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\upwizun.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ups.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\unsecapp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\unregmp2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\unlodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\twunk_32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tracert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tlntsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tlntsess.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tlntadmn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\themes.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\telnet.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tcptest.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tcpsvcs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tcmsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\taskmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\taskman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\systray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sysocmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\syskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\syncapp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\svchost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\subst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\stisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\stimon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\spoolsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sort.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\snmptrap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\snmp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sndvol32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sndrec32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\smtp_regtrace.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\smlogsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\skeys.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sigverif.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\shtml.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\shrpubw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\shmgrate.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sfc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\setup50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\setreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sethc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\secedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\scrcons.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\scardsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\savedump.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\runonce.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rundll32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\runas.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsvp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\routemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\route.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\replace.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regsvr32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regedt32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\recover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rcp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasphone.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasdial.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasautou.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\qtest32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pwstray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pws.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\proquota.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\progman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\print.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pinball.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\perfmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pentnt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pax.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pathping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\packager.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\osk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\os2srv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\os2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\OEMIG50.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcconf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcad32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nwscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntdsutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntbackup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nslookup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nppagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\notepad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\net1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nddeapir.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nbtstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\narrator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwssw32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwremind.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwmdmsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcsw32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcpyrt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcloadw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcload.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mtstocom.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msswchx.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mspaint.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msinfo32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\MSIMN.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mshta.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msdtc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mrinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqexchng.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqbkup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mq1sync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mpnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplayer2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplay32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mountvol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mofcomp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mobsync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mnmsrvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migregdb.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migpwd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migisol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\makecab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\magnify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpq.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\locator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lnkstub.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\LLSSRV.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lights.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\label.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakprv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakimg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\isignup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\irftp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipxroute.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\internat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpuex.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imagemap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iissync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisrstas.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisreset.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexpress.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexplore.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ieshwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ie4uinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwtutor.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwrmind.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\htimage.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hostname.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\help.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\gameenum.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\freecell.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpremadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpcount.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpadmcgi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fp98swin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fp98sadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fortutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\forcedos.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fltmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fixmapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\finger.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\findstr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\find.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxsend.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxqueue.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxcover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\extrac32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\explorer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\expand.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\evntwin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\evntcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\eventvwr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\eudcedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\esentutl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\encinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\drwtsn32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\doskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dmremote.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dmadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dllhst3g.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dllhost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\diskperf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\discover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\diantz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dialer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dfrgntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dfrgfat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\delttsul.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ddmprxy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ddeshare.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dcomcnfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cplexe.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\convlog.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\convert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\control.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\conime.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\conf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comrereg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comrepl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\compact.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comclust.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmstp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmmon32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmmgr32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmdl32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\CMD.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cluster.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clussvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ClusCfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clipsrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clipbrd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cleanmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ckcnv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cipher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cidaemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\chkntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\charmap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cfgwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cdplayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cb32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\calc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cacls.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\bootvrfy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\bootok.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\author.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\attrib.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\atmadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\at.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\arp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\admin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\actmovie.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\accwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\diskperf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\diantz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dfrgntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dfrgfat.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\deviceemulator.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\deviceemulator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ddmprxy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ddeshare.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dcomcnfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\convert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\control.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\conime.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\compact.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\comp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\comclust.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Com\comrereg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Com\comrepl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmstp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmmon32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\cmmgr32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmirmdrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmdl32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmd.execf
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CMD.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cluster.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\clipsrv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\clipbrd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cliconfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cleanmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ckcnv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\cisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cipher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cidaemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\chkntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CHKDSK.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\charmap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CF11233.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CF10965.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cdplayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\calc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cacls.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\bootvrfy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\bootok.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\attrib.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\atmadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\at.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\arp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\actmovie.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\actcontroller.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\actcontroller.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\accwiz.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: c:\winnt\system32\7z.exe//PE_Patch.UPX//UPX
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\7z.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWXCACLS.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWSC.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWREG.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Speech\vcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\fa4b0db30b43f91158e7521435d65d29\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\f8be264a53925fc5b1c9668562b23365\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm9l\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm9\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm71\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\b5cae5c643ad60578df1bfab32fbcb38\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\ad9c4c2a779933f83b51a49a2c88838d\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\7e2a6ab8c08390d6ca0624962723abb4\wm41\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\6bd7eb68d000be3199ca46f3c39521ac\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wordpad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wms\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wins.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\winlogon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\w32tm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\netmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\llssrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\fltmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\cmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\clussvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\cluscfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\254ef2369b4f2311a1e81cf87ee93d47\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SiS\900\uninst.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\services.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\services.ex_
disinfected:
bon je viens de voir que le scan ne s'était pas affiché totalement, la fin est elle importante?
J'ai essayé d'installer avg antivirus, mais la c'est une clé qui empeche l'installation complete.
Je viens de relancer un scan avg tool. Mais sans antivirus je suis pas sure que ca avance vraiment, et ca bug en plus pour envoyer le prédécent message (trop lourd?) du pc. Faudrait que j'enregistre le rapport avg tool sur la clé usb et que je l'envoie par le portable, mais scan en cours.
Antivir et avg antivirus ne s'installe pas, et je crois avoir vu que kaspersky en essai trente jours recquiert une installation qui n'est pas celle du pc, une autre proposition? :-)
J'ai essayé d'installer avg antivirus, mais la c'est une clé qui empeche l'installation complete.
Je viens de relancer un scan avg tool. Mais sans antivirus je suis pas sure que ca avance vraiment, et ca bug en plus pour envoyer le prédécent message (trop lourd?) du pc. Faudrait que j'enregistre le rapport avg tool sur la clé usb et que je l'envoie par le portable, mais scan en cours.
Antivir et avg antivirus ne s'installe pas, et je crois avoir vu que kaspersky en essai trente jours recquiert une installation qui n'est pas celle du pc, une autre proposition? :-)
Bonjour,
on verra le rapport du 2ème tour.
Il faut que tu évites au maximum de connecter l'ordi au net.
En gros, uniquement pour transmettre les rapports.
Ne pas avoir le rapport intégral n'est pas grave pour le moment.
on verra le rapport du 2ème tour.
Il faut que tu évites au maximum de connecter l'ordi au net.
En gros, uniquement pour transmettre les rapports.
Ne pas avoir le rapport intégral n'est pas grave pour le moment.
voici le 2d rapport avg tool :
je l'envoie du portable, pour éviter de connecter à internet le pc
Scan
----
Scanned: 122948
Detected: 851
Untreated: 0
Start time: 2009-01-26 17:35
Duration: 01:20:45
Finish time: 2009-01-26 18:55
Detected
--------
Status Object
------ ------
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\services.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\svchost.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\System32\WBEM\WinMgmt.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\TEMP\init.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\Explorer.EXE
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\accwiz.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\windows media player\mplayer2.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rundll32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\outlook express\wab.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\clipbrd.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\cmmgr32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\winhlp32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\winhlp32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\windows nt\hypertrm.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\java\jre1.6.0_07\bin\javaw.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\nokia\nokia pc suite 6\pcsynclv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rasphone.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\perfmon.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\wpnpinst.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\drwtsn32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\userinit.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mobsync.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\quicktime\qttask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-7BOEO\startup.exe
deleted: Trojan program Backdoor.Win32.Small.hik File: c:\winnt\system32\reader_s.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\nokia\nokia pc suite 6\pcsync2.exe
deleted: Trojan program Backdoor.Win32.Small.hik File: c:\documents and settings\default user\reader_s.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\cisvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\clipsrv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\dmadmin.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\faxsvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\drivers\kodakccs.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mnmsrvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\msdtc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\hpzipm12.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\regsvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\locator.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rsvp.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\scardsvr.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\pc connectivity solution\servicelayer.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\spoolsv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\stisvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\smlogsvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\tlntsvr.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ups.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\utilman.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mspmspsv.exe
deleted: Trojan program Rootkit.Win32.Agent.jj File: c:\winnt\system32\drivers\protect.sys
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\setup\wmpocm.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\shmgrate.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\outlook express\setup50.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ie4uinit.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\updcrl.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\progman.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\logon.scr
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\taskmgr.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\zip.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\windows nt\dialer.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\outlook express\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\fichiers communs\microsoft shared\msinfo\msinfo32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\openoffice.org 2.4\program\scalc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\openoffice.org 2.4\program\soffice.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\openoffice.org 2.4\program\swriter.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\openoffice.org 2.4\program\unopkg.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\outlook express\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ntsd.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\kodak\kodak easyshare software\bin\easyshare.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\sistray.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: c:\documents and settings\chouchouk\bureau\virus removal tool\is-7boeo\is-7boeo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\32788R22FWJFW\hidec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\32788R22FWJFW\swreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstCCD.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstPCS.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstPCSFEMsi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_0_8288de\Setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_0_893f41\Setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\CCS\CCSStop.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\Ksu\KSUStop.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\IDEUtil\SISIDE.exe
deleted: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\chouchouk\reader_s.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-7BOEO\minst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-7BOEO\drivers\drvins32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Local Settings\temp\CF23129.exe
deleted: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\0XQNOP2J\abb[1].txt
deleted: Trojan program Trojan-Downloader.Win32.Agent.ayxy File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\8X6RCXMZ\sev[2].exe
deleted: Trojan program Backdoor.Win32.Rbot.knh File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\KXAV0TYF\ge[1].txt
deleted: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\S9A7OHY7\abb[1].txt
deleted: Trojan program Backdoor.Win32.Agent.absk File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\S9A7OHY7\gh[1].txt
deleted: Trojan program Trojan-Downloader.Win32.Agent.ayxy File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\S9A7OHY7\sev[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\0NAZKDG1\0032[1].exe
deleted: Trojan program Backdoor.Win32.Agent.absk File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\0NAZKDG1\gh[1].txt
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EFAXK1IJ\0032[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[10].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[2].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[3].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[4].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[5].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[6].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[7].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[8].exe
deleted: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\abb[1].txt
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\0032[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\0032[2].exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.ayxy File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\sev[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\7-Zip\7z.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\7-Zip\7zG.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\launcher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\zipper.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Kodak\kodak_dr\inst_act.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Kodak\kodak_dr\KodakCCS.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\PCSuite\DataLayer\DataLayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\InstallShield Installation Information\{39345B45-A64A-4BA2-A235-F3632281A5A5}\Setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Internet Explorer\DW15.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Internet Explorer\IE Uninstall\w2kexcp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\java-rmi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\java.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\javacpl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\keytool.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\kinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\klist.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\ktab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\orbd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\pack200.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\policytool.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\rmid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\rmiregistry.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\servertool.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\ssvagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\tnameserv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak EasyShare software\bin\ptswia.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak Utilities\kodnotif.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Nokia\Connectivity Cable Driver\setupext.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\configimport.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\crashrep.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\gengal.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\msfontextract.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\msi-pkgchk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\nsplugin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\odbcconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\pkgchk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\senddoc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\setofficelang.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\stclient_wrapper.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\uno.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\python-core-2.3.4\bin\python.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\python-core-2.3.4\lib\distutils\command\wininst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Outlook Express\OEMIG50.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\QuickTime\QTInfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Tukanas Files Converter\UNWISE.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Tukanas Files Converter\zvprt40\uninstall.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Tukanas Files Converter\zvprt40\zvprt40_setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Tukanas Files Converter\zvprt40\zvprtsrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Windows Media Player\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Windows NT\Accessoires\ImageVue\kodakprv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Yahoo!\Messenger\UNWISE.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\delttsul.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\discover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\fdsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\grep.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\InstFunc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\IsUn040c.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\IsUninst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\NIRCMD.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\sed.exe
quarantined: virus Email-Worm.Win32.Joleee.w (modification) File: C:\WINNT\services.ex_
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWREG.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWSC.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWXCACLS.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\TASKMAN.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\twunk_32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\unvise32qt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\upwizun.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\VFIND.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\welcome.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\winrep.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$MSI31Uninstall_KB893803v2$\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB842773$\spuninst\spuninst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB896358$\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB896423$\spoolsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB911280$\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB913580$\mtstocom.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB920213$\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB923810$\kodakimg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB923810$\kodakprv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB937894$\mq1sync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB937894$\mqbkup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB937894$\mqmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB937894$\mqsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB951066-OE6SP1-20080625.120000$\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB951066-OE6SP1-20080625.120000$\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB951066-OE6SP1-20080625.120000$\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB951066-OE6SP1-20080625.120000$\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB952069_WM71$\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB954600_WM41$\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallQ828026$\spuninst\spuninst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\cmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\w32tm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\winlogon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\wordpad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\ERDNT\Hiv-backup\ERDNT.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\ERUNT\SDFIX\ERDNT.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\ERUNT\SDFIX_First_Run\ERDNT.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\inf\unregmp2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{17293791-C82E-476C-9997-9A0FF234A19B}\NewShortcut1_17293791C82E476C99979A0FF234A19B.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{1E0FF527-971B-4BBF-83D1-987E8DEE437D}\soffice.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}\NewShortcut1.A6CC6977_F7B4_4C0B_9510_BCD847D4BDB2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{6F716DA0-398F-11D3-85E1-005004838609}\places.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{8F7A4D82-B168-4F89-99C2-B9873EC877AF}\ARPPRODUCTICON.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{8F7A4D82-B168-4F89-99C2-B9873EC877AF}\Icon8F7A4D82.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}\NewShortcut1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}\NewShortcut2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}\NewShortcut3.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut11.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut12.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut13.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut4.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut5.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut6.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut7.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut8.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut9.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\TutorialSC.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{FCDB1C92-03C6-4C76-8625-371224256091}\NewShortcut2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\msagent\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\msiinst.tmp\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\PixArt\Pac7302\AmCap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\PixArt\Pac7302\PASnap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdllreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SiS\900\uninst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\254ef2369b4f2311a1e81cf87ee93d47\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\cluscfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\clussvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\cmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\fltmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\llssrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\netmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\w32tm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\winlogon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wins.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wordpad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wms\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\6bd7eb68d000be3199ca46f3c39521ac\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\7e2a6ab8c08390d6ca0624962723abb4\wm41\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\ad9c4c2a779933f83b51a49a2c88838d\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\b5cae5c643ad60578df1bfab32fbcb38\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm71\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm9\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm9l\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\f8be264a53925fc5b1c9668562b23365\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\fa4b0db30b43f91158e7521435d65d29\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Speech\vcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system\SmWizard.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\actmovie.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\arp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\at.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\atmadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\attrib.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\bootok.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\bootvrfy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cacls.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\calc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cdplayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CF10965.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CF11233.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\charmap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CHKDSK.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\chkntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cidaemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cipher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ckcnv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cleanmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cliconfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cluster.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CMD.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmdl32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmirmdrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmmon32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmstp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\comclust.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\comp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\compact.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\conime.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\control.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\convert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dcomcnfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ddeshare.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ddmprxy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dfrgfat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dfrgntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\diantz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\diskperf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllhost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllhst3g.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dmremote.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\doskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dpnsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dpvsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dxdllreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\esentutl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\eudcedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\expand.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\extrac32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxcover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxqueue.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxsend.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\fc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\find.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\findstr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\finger.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\fixmapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\forcedos.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\freecell.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\gcc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\GRPCONV.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\help.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\hostname.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\HPZinw12.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\i386kd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ieshwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\iexpress.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipxroute.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\irftp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\java.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\javaw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\javaws.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lights.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lnkstub.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lpq.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lpr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\magnify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\makecab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\migpwd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mountvol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mplay32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mpnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mrinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\msiregmv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\msswchx.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mstinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\narrator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nbtstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nddeapir.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\netsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\netstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nslookup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ntdsutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nwscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\odbcad32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\odbcconf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\os2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\os2srv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\osk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\packager.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pathping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pax.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pentnt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\posix.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\print.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\proquota.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\PROXYCFG.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasautou.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasdial.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rcp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\recover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\reg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\regedt32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\replace.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\route.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\routemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\runas.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\runonce.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\savedump.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\scrnsave.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\secedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sethc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\setreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sfc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\shrpubw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sigverif.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\skeys.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sort.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sp4iis.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\spiisupd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ss3dfo.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssbezier.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssflwbox.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmarque.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmaze.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmyst.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sspipes.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssstars.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sstext3d.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\stimon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\subst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\syncapp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\syskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sysocmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\systray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\taskman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tcmsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tcpsvcs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\telnet.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\themes.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tlntadmn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tlntsess.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tracert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\unlodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\verifier.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wextract.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winmine.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winmsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winver.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\write.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wupdmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wzcsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\xcopy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Écran de veille des chaînes.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Com\comrepl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Com\comrereg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\accwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\actmovie.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\admin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\arp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\at.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\atmadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\attrib.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\author.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\bootok.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\bootvrfy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cacls.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\calc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cb32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cdplayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cfgwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\charmap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\chkntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cidaemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cipher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ckcnv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cleanmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clipbrd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clipsrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ClusCfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clussvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cluster.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\CMD.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmdl32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmmgr32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmmon32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmstp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comclust.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\compact.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comrepl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comrereg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\conf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\conime.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\control.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\convert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\convlog.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cplexe.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dcomcnfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ddeshare.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ddmprxy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\delttsul.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dfrgfat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dfrgntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dialer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\diantz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\discover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\diskperf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dllhost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dllhst3g.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dmadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dmremote.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\doskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\drwtsn32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\encinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\esentutl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\eudcedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\eventvwr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\evntcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\evntwin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\expand.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\explorer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\extrac32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxcover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxqueue.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxsend.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\find.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\findstr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\finger.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fixmapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fltmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\forcedos.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fortutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fp98sadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fp98swin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpadmcgi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpcount.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpremadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\freecell.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\gameenum.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\help.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hostname.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\htimage.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwrmind.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwtutor.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ie4uinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ieshwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexplore.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexpress.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisreset.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisrstas.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iissync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imagemap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpuex.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\internat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipxroute.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\irftp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\isignup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakimg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakprv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\label.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lights.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\LLSSRV.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lnkstub.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\locator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpq.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\magnify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\makecab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migisol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migpwd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migregdb.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mnmsrvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mobsync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mofcomp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mountvol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplay32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplayer2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mpnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mq1sync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqbkup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqexchng.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mrinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msdtc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mshta.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\MSIMN.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msinfo32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mspaint.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msswchx.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mtstocom.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcload.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcloadw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcpyrt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcsw32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwmdmsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwremind.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwssw32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\narrator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nbtstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nddeapir.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\net1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\notepad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nppagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nslookup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntbackup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntdsutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nwscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcad32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcconf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\OEMIG50.EXE
disinf
je l'envoie du portable, pour éviter de connecter à internet le pc
Scan
----
Scanned: 122948
Detected: 851
Untreated: 0
Start time: 2009-01-26 17:35
Duration: 01:20:45
Finish time: 2009-01-26 18:55
Detected
--------
Status Object
------ ------
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\services.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\svchost.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\System32\WBEM\WinMgmt.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\TEMP\init.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\Explorer.EXE
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\accwiz.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\windows media player\mplayer2.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rundll32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\outlook express\wab.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\clipbrd.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\cmmgr32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\winhlp32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\winhlp32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\windows nt\hypertrm.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\java\jre1.6.0_07\bin\javaw.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\nokia\nokia pc suite 6\pcsynclv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rasphone.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\perfmon.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\wpnpinst.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\drwtsn32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\userinit.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mobsync.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\quicktime\qttask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-7BOEO\startup.exe
deleted: Trojan program Backdoor.Win32.Small.hik File: c:\winnt\system32\reader_s.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\nokia\nokia pc suite 6\pcsync2.exe
deleted: Trojan program Backdoor.Win32.Small.hik File: c:\documents and settings\default user\reader_s.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\cisvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\clipsrv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\dmadmin.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\faxsvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\drivers\kodakccs.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mnmsrvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\msdtc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\hpzipm12.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\regsvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\locator.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\rsvp.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\scardsvr.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\pc connectivity solution\servicelayer.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\spoolsv.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\stisvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\smlogsvc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\tlntsvr.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ups.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\utilman.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\mspmspsv.exe
deleted: Trojan program Rootkit.Win32.Agent.jj File: c:\winnt\system32\drivers\protect.sys
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\setup\wmpocm.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\shmgrate.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\outlook express\setup50.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ie4uinit.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\updcrl.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\progman.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\logon.scr
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\taskmgr.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\zip.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\windows nt\dialer.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\outlook express\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\fichiers communs\microsoft shared\msinfo\msinfo32.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\openoffice.org 2.4\program\scalc.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\openoffice.org 2.4\program\soffice.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\openoffice.org 2.4\program\swriter.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\openoffice.org 2.4\program\unopkg.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\outlook express\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\ntsd.exe
disinfected: virus Virus.Win32.Virut.q File: c:\program files\kodak\kodak easyshare software\bin\easyshare.exe
disinfected: virus Virus.Win32.Virut.q File: c:\winnt\system32\sistray.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: c:\documents and settings\chouchouk\bureau\virus removal tool\is-7boeo\is-7boeo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\32788R22FWJFW\hidec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\32788R22FWJFW\swreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstCCD.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstPCS.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstPCSFEMsi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_0_8288de\Setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_0_893f41\Setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\CCS\CCSStop.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\Ksu\KSUStop.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\IDEUtil\SISIDE.exe
deleted: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\chouchouk\reader_s.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-7BOEO\minst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-7BOEO\drivers\drvins32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Local Settings\temp\CF23129.exe
deleted: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\0XQNOP2J\abb[1].txt
deleted: Trojan program Trojan-Downloader.Win32.Agent.ayxy File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\8X6RCXMZ\sev[2].exe
deleted: Trojan program Backdoor.Win32.Rbot.knh File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\KXAV0TYF\ge[1].txt
deleted: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\S9A7OHY7\abb[1].txt
deleted: Trojan program Backdoor.Win32.Agent.absk File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\S9A7OHY7\gh[1].txt
deleted: Trojan program Trojan-Downloader.Win32.Agent.ayxy File: C:\Documents and Settings\chouchouk\Local Settings\Temporary Internet Files\Content.IE5\S9A7OHY7\sev[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\0NAZKDG1\0032[1].exe
deleted: Trojan program Backdoor.Win32.Agent.absk File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\0NAZKDG1\gh[1].txt
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EFAXK1IJ\0032[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[10].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[2].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[3].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[4].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[5].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[6].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[7].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[8].exe
deleted: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\abb[1].txt
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\0032[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\0032[2].exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.ayxy File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\sev[1].exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\7-Zip\7z.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\7-Zip\7zG.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\launcher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\zipper.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Kodak\kodak_dr\inst_act.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Kodak\kodak_dr\KodakCCS.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\PCSuite\DataLayer\DataLayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\InstallShield Installation Information\{39345B45-A64A-4BA2-A235-F3632281A5A5}\Setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Internet Explorer\DW15.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Internet Explorer\IE Uninstall\w2kexcp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\java-rmi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\java.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\javacpl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\keytool.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\kinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\klist.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\ktab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\orbd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\pack200.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\policytool.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\rmid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\rmiregistry.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\servertool.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\ssvagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\tnameserv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak EasyShare software\bin\ptswia.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak Utilities\kodnotif.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Nokia\Connectivity Cable Driver\setupext.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\configimport.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\crashrep.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\gengal.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\msfontextract.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\msi-pkgchk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\nsplugin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\odbcconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\pkgchk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\senddoc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\setofficelang.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\stclient_wrapper.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\uno.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\python-core-2.3.4\bin\python.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\python-core-2.3.4\lib\distutils\command\wininst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Outlook Express\OEMIG50.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\QuickTime\QTInfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Tukanas Files Converter\UNWISE.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Tukanas Files Converter\zvprt40\uninstall.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Tukanas Files Converter\zvprt40\zvprt40_setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Tukanas Files Converter\zvprt40\zvprtsrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Windows Media Player\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Windows NT\Accessoires\ImageVue\kodakprv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\Program Files\Yahoo!\Messenger\UNWISE.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\delttsul.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\discover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\fdsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\grep.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\InstFunc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\IsUn040c.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\IsUninst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\NIRCMD.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\sed.exe
quarantined: virus Email-Worm.Win32.Joleee.w (modification) File: C:\WINNT\services.ex_
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWREG.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWSC.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SWXCACLS.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\TASKMAN.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\twunk_32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\unvise32qt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\upwizun.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\VFIND.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\welcome.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\winrep.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$MSI31Uninstall_KB893803v2$\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB842773$\spuninst\spuninst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB896358$\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB896423$\spoolsv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB911280$\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB913580$\mtstocom.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB920213$\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB923810$\kodakimg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB923810$\kodakprv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB937894$\mq1sync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB937894$\mqbkup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB937894$\mqmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB937894$\mqsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB951066-OE6SP1-20080625.120000$\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB951066-OE6SP1-20080625.120000$\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB951066-OE6SP1-20080625.120000$\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB951066-OE6SP1-20080625.120000$\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB952069_WM71$\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallKB954600_WM41$\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUninstallQ828026$\spuninst\spuninst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\cmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\w32tm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\winlogon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\$NtUpdateRollupPackUninstall$\wordpad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\ERDNT\Hiv-backup\ERDNT.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\ERUNT\SDFIX\ERDNT.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\ERUNT\SDFIX_First_Run\ERDNT.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\inf\unregmp2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{17293791-C82E-476C-9997-9A0FF234A19B}\NewShortcut1_17293791C82E476C99979A0FF234A19B.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{1E0FF527-971B-4BBF-83D1-987E8DEE437D}\soffice.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}\NewShortcut1.A6CC6977_F7B4_4C0B_9510_BCD847D4BDB2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{6F716DA0-398F-11D3-85E1-005004838609}\places.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{8F7A4D82-B168-4F89-99C2-B9873EC877AF}\ARPPRODUCTICON.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{8F7A4D82-B168-4F89-99C2-B9873EC877AF}\Icon8F7A4D82.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}\NewShortcut1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}\NewShortcut2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}\NewShortcut3.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut11.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut12.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut13.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut4.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut5.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut6.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut7.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut8.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\NewShortcut9.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{CA60320D-6A16-49C8-A34F-84EEF4799567}\TutorialSC.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Installer\{FCDB1C92-03C6-4C76-8625-371224256091}\NewShortcut2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\msagent\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\msiinst.tmp\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\PixArt\Pac7302\AmCap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\PixArt\Pac7302\PASnap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdllreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SiS\900\uninst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\129d0763ba0ae24b3668bfe1e19bb3ec\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\254ef2369b4f2311a1e81cf87ee93d47\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\msimn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\oemig50.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\wab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\451374f30879ab6ad2ae664ac011bb74\wabmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\cluscfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\clussvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\cmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\fltmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\llssrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\netmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\services.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\w32tm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\winlogon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wins.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wordpad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\5f1f98b38a02ea4262e21bbeb3ede9f0\wms\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\6bd7eb68d000be3199ca46f3c39521ac\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\7e2a6ab8c08390d6ca0624962723abb4\wm41\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\ad9c4c2a779933f83b51a49a2c88838d\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\b5cae5c643ad60578df1bfab32fbcb38\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm71\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm9\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\c5f6c1460fc9fb16a7608938dd04fb93\wm9l\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\f8be264a53925fc5b1c9668562b23365\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\SoftwareDistribution\Download\fa4b0db30b43f91158e7521435d65d29\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\Speech\vcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system\SmWizard.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\actmovie.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\arp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\at.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\atmadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\attrib.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\bootok.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\bootvrfy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cacls.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\calc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cdplayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CF10965.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CF11233.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\charmap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CHKDSK.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\chkntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cidaemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cipher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ckcnv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cleanmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cliconfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cluster.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\CMD.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmdl32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmirmdrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmmon32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cmstp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\comclust.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\comp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\compact.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\conime.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\control.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\convert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\cscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dcomcnfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ddeshare.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ddmprxy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dfrgfat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dfrgntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\diantz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\diskperf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllhost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllhst3g.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dmremote.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\doskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dpnsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dpvsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dxdllreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\esentutl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\eudcedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\expand.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\extrac32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxcover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxqueue.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\faxsend.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\fc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\find.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\findstr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\finger.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\fixmapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\forcedos.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\freecell.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\gcc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\GRPCONV.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\help.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\hostname.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\HPZinw12.exe
deleted: virus Email-Worm.Win32.Mydoom.bj File: C:\WINNT\system32\i386kd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ieshwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\iexpress.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ipxroute.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\irftp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\java.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\javaw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\javaws.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lights.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lnkstub.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lpq.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\lpr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\magnify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\makecab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\migpwd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mountvol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mplay32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mpnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mrinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\msiregmv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\msswchx.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\mstinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\narrator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nbtstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nddeapir.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\netsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\netstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nslookup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ntdsutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\nwscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\odbcad32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\odbcconf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\os2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\os2srv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\osk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\packager.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pathping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pax.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\pentnt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ping.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\posix.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\print.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\proquota.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\PROXYCFG.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\psxss.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasautou.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rasdial.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rcp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\recover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\reg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\regedt32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\replace.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\route.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\routemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\rsnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\runas.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\runonce.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\savedump.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\scrnsave.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\secedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sethc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\setreg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\setup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sfc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\shrpubw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sigverif.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\skeys.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sort.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sp4iis.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\spiisupd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ss3dfo.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssbezier.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssflwbox.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmarque.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmaze.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssmyst.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sspipes.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\ssstars.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sstext3d.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\stimon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\subst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\syncapp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\syskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\sysocmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\systray.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\taskman.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tcmsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tcpsvcs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\telnet.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\themes.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tlntadmn.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tlntsess.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\tracert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\unlodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\verclsid.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\verifier.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wextract.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winmine.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winmsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\winver.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\write.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wupdmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wzcsetup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\xcopy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Écran de veille des chaînes.scr
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Com\comrepl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Com\comrereg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\accwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\actmovie.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\admin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\agentsvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\arp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\at.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\atmadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\attrib.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\author.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\bootok.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\bootvrfy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cacls.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\calc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cb32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cdplayer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cfgwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\charmap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\chkdsk.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\chkntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cidaemon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cipher.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cisvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ckcnv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cleanmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clipbrd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clipsrv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ClusCfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\clussvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cluster.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\CMD.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmdl32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmmgr32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmmon32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cmstp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comclust.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\compact.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comrepl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\comrereg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\conf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\conime.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\control.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\convert.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\convlog.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cplexe.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\cscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dcomcnfg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ddeshare.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ddmprxy.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\delttsul.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dfrgfat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dfrgntfs.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dialer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\diantz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\discover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\diskperf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dllhost.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dllhst3g.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dmadmin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dmremote.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\doskey.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dplaysvr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\drwtsn32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\dxdiag.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\encinst.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\esentutl.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\eudcedit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\eventvwr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\evntcmd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\evntwin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\expand.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\explorer.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\extrac32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxcover.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxqueue.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxsend.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\faxsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\find.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\findstr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\finger.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fixmapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fltmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fontview.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\forcedos.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fortutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fp98sadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fp98swin.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpadmcgi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpcount.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpremadm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\freecell.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\gameenum.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\grpconv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\help.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hostname.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\htimage.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwrmind.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwtutor.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ie4uinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ieshwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexplore.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexpress.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisreset.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisrstas.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iissync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imagemap.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpuex.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetmgr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetwiz.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\internat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipconfig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipsecmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipxroute.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\irftp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\isignup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakimg.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakprv.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\label.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lights.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\LLSSRV.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lnkstub.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\locator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lodctr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\logagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpq.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpr.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lsass.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\magnify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\makecab.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migisol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migpwd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migregdb.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mmc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mnmsrvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mobsync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mofcomp.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mountvol.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplay32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplayer2.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mpnotify.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mq1sync.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqbkup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqexchng.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqmig.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mrinfo.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msdtc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mshta.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msiexec.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\MSIMN.EXE
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msinfo32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mspaint.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msswchx.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstask.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstinit.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mtstocom.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcload.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcloadw.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcpyrt.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcsw32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwmdmsvc.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwremind.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwssw32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\narrator.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nbtstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nddeapir.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\net1.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netdde.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netmon.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netsh.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netstat.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\notepad.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nppagent.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nsisapi.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nslookup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntbackup.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntdsutil.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntsd.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntvdm.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nwscript.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcad32.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcconf.exe
disinfected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\OEMIG50.EXE
disinf
Bonjour,
redémarre l'ordi et fais un scan combofix.
Poste le rapport.
Faites ce que l'on vous demande, ni plus, ni moins.
Ne créez pas de doublons, ni sur CCM ni sur un autre site. Merci
redémarre l'ordi et fais un scan combofix.
Poste le rapport.
Faites ce que l'on vous demande, ni plus, ni moins.
Ne créez pas de doublons, ni sur CCM ni sur un autre site. Merci
je crois que ca tourne un peu en rond :-(
ComboFix 09-01-21.04 - chouchouk 2009-01-26 20:11:07.6 - NTFSx86 MINIMAL
Microsoft Windows 2000 Professionnel 5.0.2195.4.1252.1.1036.18.480.343 [GMT 1:00]
Lancé depuis: c:\documents and settings\chouchouk\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\winnt\system32\drivers\tdssserv.sys
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_LPTRDCSRV
-------\Legacy_PROTECT
-------\Legacy_RESTORE
-------\Service_restore
-------\Service_TDSSserv.sys
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-26 au 2009-01-26 ))))))))))))))))))))))))))))))))))))
.
2009-01-25 23:55 . 09-01-25 23:55 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\Grisoft
2009-01-23 08:19 . 09-01-26 00:01 1,391 --a------ c:\winnt\imsins.BAK
2009-01-21 19:49 . 09-01-21 20:02 131 --a-s---- c:\winnt\system32\3756265427.dat
2009-01-21 17:21 . 09-01-23 09:39 7,168 --a------ c:\winnt\system32\drivers\utqxndm3.sys
2009-01-21 13:48 . 08-07-08 13:54 148,496 --a------ c:\winnt\system32\drivers\86179875.sys
2009-01-21 13:14 . 09-01-21 20:19 149,420 --a------ c:\winnt\system32\bio-22-10-10.exe
2009-01-21 13:13 . 09-01-21 19:49 54,424 --a------ c:\winnt\system32\head-22-10-10.exe
2009-01-19 23:44 . 09-01-23 12:57 54,156 --ah----- c:\winnt\QTFont.qfn
2009-01-19 23:44 . 09-01-23 12:57 1,409 --a------ c:\winnt\QTFont.for
2009-01-12 18:09 . 09-01-12 18:09 186,592 --a------ c:\winnt\system32\drivers\windrvr6.sys
2009-01-11 22:07 . 09-01-11 22:07 0 --a------ c:\winnt\nsreg.dat
2009-01-11 22:01 . 09-01-11 22:01 7,679,120 --a------ c:\program files\setupmozilla.exe
2009-01-10 19:25 . 09-01-10 19:25 144,034 --a------ C:\Sans titre.bmp
2009-01-10 11:03 . 09-01-10 11:03 24,172 --a------ c:\winnt\system32\syncps.dl_
2009-01-09 20:56 . 09-01-09 20:56 <DIR> d-------- c:\program files\microsoft frontpage
2009-01-09 11:14 . 09-01-09 11:14 <DIR> d-------- c:\winnt\ERUNT
2009-01-08 00:34 . 09-01-26 18:52 118,272 --a------ c:\winnt\system32\reg.exe
2009-01-07 03:51 . 09-01-07 03:51 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\Malwarebytes
2009-01-07 03:44 . 09-01-07 03:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-06 23:52 . 04-03-09 01:00 609,824 --a------ c:\winnt\system32\comctl32.ocx
2009-01-05 22:04 . 09-01-05 22:04 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\AVGTOOLBAR
2009-01-04 23:32 . 09-01-04 23:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\Grisoft
2009-01-03 19:24 . 07-10-25 09:00 230,912 -----c--- c:\winnt\system32\dllcache\wmasf.dll
2009-01-03 19:24 . 08-02-15 14:24 96,528 --a------ c:\winnt\system32\dnsrslvr.dll
2009-01-03 16:08 . 09-01-19 15:57 <DIR> d-a------ c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 15:55 . 09-01-03 15:55 <DIR> d-------- c:\winnt\BDOSCAN8
2009-01-03 15:08 . 08-10-16 14:08 27,672 --a------ c:\winnt\system32\wuapi.dll.mui
2009-01-01 16:28 . 09-01-01 16:28 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\dvdcss
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 17:44 607,232 ----a-w c:\winnt\system32\drivers\KodakCCS.exe
2009-01-26 13:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\OpenOffice.org2
2008-12-11 12:09 239,472 ----a-w c:\winnt\system32\drivers\SRV.SYS
2008-03-19 11:34 271 ---h--w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [07-08-30 17:43 4670704]
"internat.exe"="internat.exe" [09-01-22 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [09-01-26 18:42 385024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [08-06-10 03:27 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [09-01-21 09:09 305152]
"VideoLAN"="c:\winnt\system32\head-22-10-10.exe" [09-01-21 19:49 54424]
"CCleaner"="c:\winnt\system32\head-22-10-10.exe" [09-01-21 19:49 54424]
"Synchronization Manager"="mobsync.exe" [09-01-26 18:42 484864 c:\winnt\system32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [09-01-26 18:44 1404928]
"internat.exe"="internat.exe" [09-01-22 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [09-01-21 09:09 224256]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-04-27 843776]
Utility Tray.lnk - c:\winnt\system32\sistray.exe [2008-04-04 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
R3 openhci;Pilote de contrôleur hôte ouvert USB Microsoft;c:\winnt\system32\drivers\openhci.sys [2003-06-23 24784]
S1 is-0RKSTdrv;is-0RKSTdrv;c:\winnt\system32\DRIVERS\43621225.sys --> c:\winnt\system32\DRIVERS\43621225.sys [?]
S1 is-3TB85drv;is-3TB85drv;c:\winnt\system32\DRIVERS\51870077.sys --> c:\winnt\system32\DRIVERS\51870077.sys [?]
S1 is-7BOEOdrv;is-7BOEOdrv;c:\winnt\system32\DRIVERS\[u]0/u0626145.sys --> c:\winnt\system32\DRIVERS\[u]0/u0626145.sys [?]
S1 is-8CPV3drv;is-8CPV3drv;c:\winnt\system32\DRIVERS\13819532.sys --> c:\winnt\system32\DRIVERS\13819532.sys [?]
S1 is-HGME0drv;is-HGME0drv;c:\winnt\system32\DRIVERS\63575778.sys --> c:\winnt\system32\DRIVERS\63575778.sys [?]
S1 is-LD105drv;is-LD105drv;c:\winnt\system32\DRIVERS\92195390.sys --> c:\winnt\system32\DRIVERS\92195390.sys [?]
S3 banshee;banshee;c:\winnt\system32\drivers\banshee.sys [2008-03-24 38928]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\winnt\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S3 nv3;nv3;c:\winnt\system32\drivers\nv3.sys [2008-03-19 201328]
S3 PAC7302;PAC7302 VGA USB Camera;c:\winnt\system32\drivers\PAC7302.SYS [2008-06-03 457856]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\winnt\system32\drivers\sis7012.sys [2004-11-03 267136]
S3 SISNIC2K;SiS PCI Fast Ethernet Adapter Driver for NDIS5;c:\winnt\system32\drivers\sisnic2k.sys [2006-02-14 32768]
S3 utqxndm3;AVZ Kernel Driver;c:\winnt\system32\drivers\utqxndm3.sys [2009-01-21 7168]
S4 ptssvc;ptssvc;d:\kodak easyshare software\bin\ptssvc.exe --> d:\kodak easyshare software\bin\ptssvc.exe [?]
.
Contenu du dossier 'Tâches planifiées'
2009-01-07 c:\winnt\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe []
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Windows NT - c:\winnt\vmmreg32.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.xeoo.com/?p=h&a=f
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
IE: Download with &Shareaza - c:\program files\Shareaza\Plugins\RazaWebHook.dll/3000
LSP: %SystemRoot%\system32\msafd.dll
FF - ProfilePath - c:\documents and settings\chouchouk\Application Data\Mozilla\Firefox\Profiles\gh9pde39.default\
FF - prefs.js: browser.search.selectedEngine - xeoo.com
FF - prefs.js: keyword.URL - hxxp://xeoo.com/?p=url&a=firefox&k=
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-26 20:20:12
Windows 5.0.2195 Service Pack 4 NTFS
detected NTDLL code modification:
ZwOpenFile
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(160)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Heure de fin: 2009-01-26 20:24:02 - La machine a redémarré [chouchouk]
ComboFix-quarantined-files.txt 2009-01-26 19:23:55
Avant-CF: 811,708,416 octets libres
Après-CF: 795,897,856 octets libres
157 --- E O F --- 2009-01-23 07:19:58
ComboFix 09-01-21.04 - chouchouk 2009-01-26 20:11:07.6 - NTFSx86 MINIMAL
Microsoft Windows 2000 Professionnel 5.0.2195.4.1252.1.1036.18.480.343 [GMT 1:00]
Lancé depuis: c:\documents and settings\chouchouk\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\winnt\system32\drivers\tdssserv.sys
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_LPTRDCSRV
-------\Legacy_PROTECT
-------\Legacy_RESTORE
-------\Service_restore
-------\Service_TDSSserv.sys
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-26 au 2009-01-26 ))))))))))))))))))))))))))))))))))))
.
2009-01-25 23:55 . 09-01-25 23:55 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\Grisoft
2009-01-23 08:19 . 09-01-26 00:01 1,391 --a------ c:\winnt\imsins.BAK
2009-01-21 19:49 . 09-01-21 20:02 131 --a-s---- c:\winnt\system32\3756265427.dat
2009-01-21 17:21 . 09-01-23 09:39 7,168 --a------ c:\winnt\system32\drivers\utqxndm3.sys
2009-01-21 13:48 . 08-07-08 13:54 148,496 --a------ c:\winnt\system32\drivers\86179875.sys
2009-01-21 13:14 . 09-01-21 20:19 149,420 --a------ c:\winnt\system32\bio-22-10-10.exe
2009-01-21 13:13 . 09-01-21 19:49 54,424 --a------ c:\winnt\system32\head-22-10-10.exe
2009-01-19 23:44 . 09-01-23 12:57 54,156 --ah----- c:\winnt\QTFont.qfn
2009-01-19 23:44 . 09-01-23 12:57 1,409 --a------ c:\winnt\QTFont.for
2009-01-12 18:09 . 09-01-12 18:09 186,592 --a------ c:\winnt\system32\drivers\windrvr6.sys
2009-01-11 22:07 . 09-01-11 22:07 0 --a------ c:\winnt\nsreg.dat
2009-01-11 22:01 . 09-01-11 22:01 7,679,120 --a------ c:\program files\setupmozilla.exe
2009-01-10 19:25 . 09-01-10 19:25 144,034 --a------ C:\Sans titre.bmp
2009-01-10 11:03 . 09-01-10 11:03 24,172 --a------ c:\winnt\system32\syncps.dl_
2009-01-09 20:56 . 09-01-09 20:56 <DIR> d-------- c:\program files\microsoft frontpage
2009-01-09 11:14 . 09-01-09 11:14 <DIR> d-------- c:\winnt\ERUNT
2009-01-08 00:34 . 09-01-26 18:52 118,272 --a------ c:\winnt\system32\reg.exe
2009-01-07 03:51 . 09-01-07 03:51 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\Malwarebytes
2009-01-07 03:44 . 09-01-07 03:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-06 23:52 . 04-03-09 01:00 609,824 --a------ c:\winnt\system32\comctl32.ocx
2009-01-05 22:04 . 09-01-05 22:04 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\AVGTOOLBAR
2009-01-04 23:32 . 09-01-04 23:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\Grisoft
2009-01-03 19:24 . 07-10-25 09:00 230,912 -----c--- c:\winnt\system32\dllcache\wmasf.dll
2009-01-03 19:24 . 08-02-15 14:24 96,528 --a------ c:\winnt\system32\dnsrslvr.dll
2009-01-03 16:08 . 09-01-19 15:57 <DIR> d-a------ c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 15:55 . 09-01-03 15:55 <DIR> d-------- c:\winnt\BDOSCAN8
2009-01-03 15:08 . 08-10-16 14:08 27,672 --a------ c:\winnt\system32\wuapi.dll.mui
2009-01-01 16:28 . 09-01-01 16:28 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\dvdcss
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 17:44 607,232 ----a-w c:\winnt\system32\drivers\KodakCCS.exe
2009-01-26 13:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\OpenOffice.org2
2008-12-11 12:09 239,472 ----a-w c:\winnt\system32\drivers\SRV.SYS
2008-03-19 11:34 271 ---h--w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [07-08-30 17:43 4670704]
"internat.exe"="internat.exe" [09-01-22 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [09-01-26 18:42 385024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [08-06-10 03:27 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [09-01-21 09:09 305152]
"VideoLAN"="c:\winnt\system32\head-22-10-10.exe" [09-01-21 19:49 54424]
"CCleaner"="c:\winnt\system32\head-22-10-10.exe" [09-01-21 19:49 54424]
"Synchronization Manager"="mobsync.exe" [09-01-26 18:42 484864 c:\winnt\system32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [09-01-26 18:44 1404928]
"internat.exe"="internat.exe" [09-01-22 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [09-01-21 09:09 224256]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-04-27 843776]
Utility Tray.lnk - c:\winnt\system32\sistray.exe [2008-04-04 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
R3 openhci;Pilote de contrôleur hôte ouvert USB Microsoft;c:\winnt\system32\drivers\openhci.sys [2003-06-23 24784]
S1 is-0RKSTdrv;is-0RKSTdrv;c:\winnt\system32\DRIVERS\43621225.sys --> c:\winnt\system32\DRIVERS\43621225.sys [?]
S1 is-3TB85drv;is-3TB85drv;c:\winnt\system32\DRIVERS\51870077.sys --> c:\winnt\system32\DRIVERS\51870077.sys [?]
S1 is-7BOEOdrv;is-7BOEOdrv;c:\winnt\system32\DRIVERS\[u]0/u0626145.sys --> c:\winnt\system32\DRIVERS\[u]0/u0626145.sys [?]
S1 is-8CPV3drv;is-8CPV3drv;c:\winnt\system32\DRIVERS\13819532.sys --> c:\winnt\system32\DRIVERS\13819532.sys [?]
S1 is-HGME0drv;is-HGME0drv;c:\winnt\system32\DRIVERS\63575778.sys --> c:\winnt\system32\DRIVERS\63575778.sys [?]
S1 is-LD105drv;is-LD105drv;c:\winnt\system32\DRIVERS\92195390.sys --> c:\winnt\system32\DRIVERS\92195390.sys [?]
S3 banshee;banshee;c:\winnt\system32\drivers\banshee.sys [2008-03-24 38928]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\winnt\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S3 nv3;nv3;c:\winnt\system32\drivers\nv3.sys [2008-03-19 201328]
S3 PAC7302;PAC7302 VGA USB Camera;c:\winnt\system32\drivers\PAC7302.SYS [2008-06-03 457856]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\winnt\system32\drivers\sis7012.sys [2004-11-03 267136]
S3 SISNIC2K;SiS PCI Fast Ethernet Adapter Driver for NDIS5;c:\winnt\system32\drivers\sisnic2k.sys [2006-02-14 32768]
S3 utqxndm3;AVZ Kernel Driver;c:\winnt\system32\drivers\utqxndm3.sys [2009-01-21 7168]
S4 ptssvc;ptssvc;d:\kodak easyshare software\bin\ptssvc.exe --> d:\kodak easyshare software\bin\ptssvc.exe [?]
.
Contenu du dossier 'Tâches planifiées'
2009-01-07 c:\winnt\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe []
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Windows NT - c:\winnt\vmmreg32.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.xeoo.com/?p=h&a=f
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
IE: Download with &Shareaza - c:\program files\Shareaza\Plugins\RazaWebHook.dll/3000
LSP: %SystemRoot%\system32\msafd.dll
FF - ProfilePath - c:\documents and settings\chouchouk\Application Data\Mozilla\Firefox\Profiles\gh9pde39.default\
FF - prefs.js: browser.search.selectedEngine - xeoo.com
FF - prefs.js: keyword.URL - hxxp://xeoo.com/?p=url&a=firefox&k=
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-26 20:20:12
Windows 5.0.2195 Service Pack 4 NTFS
detected NTDLL code modification:
ZwOpenFile
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(160)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Heure de fin: 2009-01-26 20:24:02 - La machine a redémarré [chouchouk]
ComboFix-quarantined-files.txt 2009-01-26 19:23:55
Avant-CF: 811,708,416 octets libres
Après-CF: 795,897,856 octets libres
157 --- E O F --- 2009-01-23 07:19:58
Re,
je regarde un certain nombre de choses.
J'espère qu'il n'y avait aucun fichier .exe dans la clé USB.
Je voudrais que tu télécharges sur le portable le SP4 et que regardes si tu as les fichiers infectés dans le SP4.
Je cherche pourquoi, alors que l'outil dit que la désinfection se fera au reboot, celle-ci ne se fait pas.
Une possibilité est que c'est parce qu'il ne trouve pas de fichier sain.
Il y en a 5
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
Je ne sais pas, dans le fichier téléchargé, si ils sont en .exe ou en .ex_
Le lien de téléchargement :
http://www.microsoft.com/downloads/details.aspx?FamilyID=DC27B8C6-2A5A-4399-AD3D-4A97A25F41D9&displaylang=fr
Comme il est dit en bas de la page, "pour copier le téléchargement pour installer plus tard, cliquer sur sauvegarder ou sauvegarder sur le disque".
===============================================
Fais passer ATF-Cleaner et CCleaner. Tu as les modes d'emploi ?
===================================================
Pendant que je te prépare un script combofix, refais tourner combofix et poste le nouveau rapport.
je regarde un certain nombre de choses.
J'espère qu'il n'y avait aucun fichier .exe dans la clé USB.
Je voudrais que tu télécharges sur le portable le SP4 et que regardes si tu as les fichiers infectés dans le SP4.
Je cherche pourquoi, alors que l'outil dit que la désinfection se fera au reboot, celle-ci ne se fait pas.
Une possibilité est que c'est parce qu'il ne trouve pas de fichier sain.
Il y en a 5
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
Je ne sais pas, dans le fichier téléchargé, si ils sont en .exe ou en .ex_
Le lien de téléchargement :
http://www.microsoft.com/downloads/details.aspx?FamilyID=DC27B8C6-2A5A-4399-AD3D-4A97A25F41D9&displaylang=fr
Comme il est dit en bas de la page, "pour copier le téléchargement pour installer plus tard, cliquer sur sauvegarder ou sauvegarder sur le disque".
===============================================
Fais passer ATF-Cleaner et CCleaner. Tu as les modes d'emploi ?
===================================================
Pendant que je te prépare un script combofix, refais tourner combofix et poste le nouveau rapport.
alors malheureusement je crois que des fichiers.exe étaient dans ma clé usb : tels que : RSIT, lopSD,registrycleaner , en regardanr dns propriétés, ils sont marqués XXXX.exe,0. Faut il recommencer la procédure du début?
Je ne comprends pas bien la manip concernant le sp4 sur le portable. J'ai téléchargé le sp4 mais le portable est sous xp, je dois le mettre sur le pc? Je suis en train de vider ma clé usb, je le fais par ce biais?
Ah oui, est ce que pour faire retourner un outil, je le vire du pc et je le réinstalle a chaque fois par le cd? Cad je vire combo et le réinstalle, ainsi que avp tool?
Je ne comprends pas bien la manip concernant le sp4 sur le portable. J'ai téléchargé le sp4 mais le portable est sous xp, je dois le mettre sur le pc? Je suis en train de vider ma clé usb, je le fais par ce biais?
Ah oui, est ce que pour faire retourner un outil, je le vire du pc et je le réinstalle a chaque fois par le cd? Cad je vire combo et le réinstalle, ainsi que avp tool?
Re,
je voudrais surtout que tu analyses le portable avec ton antivirus.
===========
Ensuite, dans le répertoire du SP4, tu as des fichiers et ces fichiers ont un nom qui dotr être lisible aussi sur XP.
Si ce n'est pas le cas, copie sur ta clé USB le SP4 et implante le sur l'ordi malade.
Conserve encore le fichier téléchargé sur le portable mais formatte la clé dans l'ordi malade (vide, elle ne peut pas transmettre de virus.
En relisant le post, tu as une partition C et 2 partitions (D et E si je me souviens). Il y avait des fichiers infectés dedans.
C'est ce que tu appelles tes disques internes externes ?
C'est quoi les fichiers .exe sur ces disques ?
je voudrais surtout que tu analyses le portable avec ton antivirus.
===========
Ensuite, dans le répertoire du SP4, tu as des fichiers et ces fichiers ont un nom qui dotr être lisible aussi sur XP.
Si ce n'est pas le cas, copie sur ta clé USB le SP4 et implante le sur l'ordi malade.
Conserve encore le fichier téléchargé sur le portable mais formatte la clé dans l'ordi malade (vide, elle ne peut pas transmettre de virus.
En relisant le post, tu as une partition C et 2 partitions (D et E si je me souviens). Il y avait des fichiers infectés dedans.
C'est ce que tu appelles tes disques internes externes ?
C'est quoi les fichiers .exe sur ces disques ?
alors :
- pour l'antivirus du portable, je l'ai changé ce matin (voir topic : http://www.commentcamarche.net/forum/affich 10592260 petite verif vundo pour gen hackman à partir du post 18) antivir m'a trouvé 4 trojans... Mais je n'ai pas passer l'outil qui permet de trouver le virut.q, si je suis bien ton raisonnement :-(
- oui j'ai dézippé le sp4 sur le portable, mais je ne vois que des fichiers que je ne connais pas (aucun des 5 fichiers infectés sur le pc), veux tu la liste des fichiers pour etre sur (si j'ai bien compris ta demande)
- quant à mon pc : j'ai un DD de 7Go partitionné en C (4Go) et D(3Go) environ, à coté de cela, j'ai un autre disque dur d'un ancien ordi qui avait cramé, de 10 Go qui me permet de caser des documents que je ne peux pas garder sur C ou D par manque de place. Je l'utilise plutot rarement, mais je l'utilise, lorsque je le branche c'est à la place du lecteur de ma tour, il fonctionne en esclave de C et D. Je crois qu'effectivement il se nomme E dans ces cas là.
Mais si je le branche je n'ai plus accès au lecteur cd
- A quoi reconnait on des fichiers .exe ? Sur D j'ai adobeRd, quick time, vlc, windows media, 7z457, files converter. Plus tous plein de dossiers de travail, photos. Mon frère m'avait conseillé de mettre dans D tout programme (pilotes etc... ) au cas ou je devrai formater C.
Et pour E je sais pas, je suis pas branchée dessus.
- Dois je t'envoyer le 2d rapport combofix du pc par le pc meme?
- pour l'antivirus du portable, je l'ai changé ce matin (voir topic : http://www.commentcamarche.net/forum/affich 10592260 petite verif vundo pour gen hackman à partir du post 18) antivir m'a trouvé 4 trojans... Mais je n'ai pas passer l'outil qui permet de trouver le virut.q, si je suis bien ton raisonnement :-(
- oui j'ai dézippé le sp4 sur le portable, mais je ne vois que des fichiers que je ne connais pas (aucun des 5 fichiers infectés sur le pc), veux tu la liste des fichiers pour etre sur (si j'ai bien compris ta demande)
- quant à mon pc : j'ai un DD de 7Go partitionné en C (4Go) et D(3Go) environ, à coté de cela, j'ai un autre disque dur d'un ancien ordi qui avait cramé, de 10 Go qui me permet de caser des documents que je ne peux pas garder sur C ou D par manque de place. Je l'utilise plutot rarement, mais je l'utilise, lorsque je le branche c'est à la place du lecteur de ma tour, il fonctionne en esclave de C et D. Je crois qu'effectivement il se nomme E dans ces cas là.
Mais si je le branche je n'ai plus accès au lecteur cd
- A quoi reconnait on des fichiers .exe ? Sur D j'ai adobeRd, quick time, vlc, windows media, 7z457, files converter. Plus tous plein de dossiers de travail, photos. Mon frère m'avait conseillé de mettre dans D tout programme (pilotes etc... ) au cas ou je devrai formater C.
Et pour E je sais pas, je suis pas branchée dessus.
- Dois je t'envoyer le 2d rapport combofix du pc par le pc meme?
Re,
antivir ne traite pas Virut.q, mais il le "voit". Si tu n'as pas d'alerte, pas de souci.
Pour tes autres partitions, ici
http://www.commentcamarche.net/forum/affich 10354070 vundo ou autre chose?page=8#143
tu as les "restes" d'une partition Xp. Elle fonctionne ?
Si tu peux ne pas connecter l'ordi malade au Net, cela vaut mieux (rien ne peut rajouter de l'infection).
Tu formates la clé dans l'ordi malade et tu copies le fichier combofix.txt.
Tu le recopies sur le portable, tu l'ouvre avec le Bloc notes et tu le postes.
pour moi, la suite au jour.
antivir ne traite pas Virut.q, mais il le "voit". Si tu n'as pas d'alerte, pas de souci.
Pour tes autres partitions, ici
http://www.commentcamarche.net/forum/affich 10354070 vundo ou autre chose?page=8#143
tu as les "restes" d'une partition Xp. Elle fonctionne ?
Si tu peux ne pas connecter l'ordi malade au Net, cela vaut mieux (rien ne peut rajouter de l'infection).
Tu formates la clé dans l'ordi malade et tu copies le fichier combofix.txt.
Tu le recopies sur le portable, tu l'ouvre avec le Bloc notes et tu le postes.
pour moi, la suite au jour.
bon alors a priori pas d'alertes pour le portable . Tant mieux! Par contre mon disque dur de rajout (E) est infecté lui aussi :-( bouhhhh lol
Les "restes" de xp, je sais pas vraiment par ou je peux les voir ...
Pourquoi faut il formater la clé dans l'ordi malade? Néanmoins je vais le faire. De toute maniere combofix.txt n'est pas infectable si j'ai bien suivi...
Je te souhaite une bonne nuit Lyonnais et je te remercie encore :-)
Les "restes" de xp, je sais pas vraiment par ou je peux les voir ...
Pourquoi faut il formater la clé dans l'ordi malade? Néanmoins je vais le faire. De toute maniere combofix.txt n'est pas infectable si j'ai bien suivi...
Je te souhaite une bonne nuit Lyonnais et je te remercie encore :-)
bonjour lyonnais,
rapport combofix d'hier
ComboFix 09-01-21.04 - chouchouk 26/01/2009 22:33:04.7 - NTFSx86 MINIMAL
Microsoft Windows 2000 Professionnel 5.0.2195.4.1252.1.1036.18.480.345 [GMT 1:00]
Lancé depuis: c:\documents and settings\chouchouk\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-26 au 2009-01-26 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 21:29 --------- d-----w c:\program files\CCleaner
2009-01-26 17:44 640,512 ----a-w c:\winnt\system32\drivers\KodakCCS.exe
2009-01-26 13:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\OpenOffice.org2
2009-01-25 22:55 --------- d-----w c:\documents and settings\chouchouk\Application Data\Grisoft
2009-01-23 08:39 7,168 ----a-w c:\winnt\system32\drivers\utqxndm3.sys
2009-01-19 14:57 --------- d---a-w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-12 17:09 186,592 ----a-w c:\winnt\system32\drivers\windrvr6.sys
2009-01-11 21:01 7,679,120 ----a-w c:\program files\setupmozilla.exe
2009-01-09 19:56 --------- d-----w c:\program files\microsoft frontpage
2009-01-07 02:51 --------- d-----w c:\documents and settings\chouchouk\Application Data\Malwarebytes
2009-01-07 02:44 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-05 21:04 --------- d-----w c:\documents and settings\chouchouk\Application Data\AVGTOOLBAR
2009-01-04 22:32 --------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2009-01-01 15:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\dvdcss
2008-12-11 12:09 239,472 ----a-w c:\winnt\system32\drivers\SRV.SYS
2008-03-19 11:34 271 ---h--w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [30/08/07 17:43 4670704]
"internat.exe"="internat.exe" [22/01/09 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [26/01/09 18:42 385024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [10/06/08 03:27 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [21/01/09 09:09 305152]
"VideoLAN"="c:\winnt\system32\head-22-10-10.exe" [21/01/09 19:49 54424]
"CCleaner"="c:\winnt\system32\head-22-10-10.exe" [21/01/09 19:49 54424]
"Synchronization Manager"="mobsync.exe" [26/01/09 18:42 484864 c:\winnt\system32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [26/01/09 18:44 1404928]
"internat.exe"="internat.exe" [22/01/09 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [21/01/09 09:09 224256]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-04-27 843776]
Utility Tray.lnk - c:\winnt\system32\sistray.exe [2008-04-04 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
R3 openhci;Pilote de contrôleur hôte ouvert USB Microsoft;c:\winnt\system32\drivers\openhci.sys [2003-06-23 24784]
S1 is-0RKSTdrv;is-0RKSTdrv;c:\winnt\system32\DRIVERS\43621225.sys --> c:\winnt\system32\DRIVERS\43621225.sys [?]
S1 is-3TB85drv;is-3TB85drv;c:\winnt\system32\DRIVERS\51870077.sys --> c:\winnt\system32\DRIVERS\51870077.sys [?]
S1 is-7BOEOdrv;is-7BOEOdrv;c:\winnt\system32\DRIVERS\[u]0/u0626145.sys --> c:\winnt\system32\DRIVERS\[u]0/u0626145.sys [?]
S1 is-8CPV3drv;is-8CPV3drv;c:\winnt\system32\DRIVERS\13819532.sys --> c:\winnt\system32\DRIVERS\13819532.sys [?]
S1 is-HGME0drv;is-HGME0drv;c:\winnt\system32\DRIVERS\63575778.sys --> c:\winnt\system32\DRIVERS\63575778.sys [?]
S1 is-LD105drv;is-LD105drv;c:\winnt\system32\DRIVERS\92195390.sys --> c:\winnt\system32\DRIVERS\92195390.sys [?]
S3 banshee;banshee;c:\winnt\system32\drivers\banshee.sys [2008-03-24 38928]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\winnt\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S3 nv3;nv3;c:\winnt\system32\drivers\nv3.sys [2008-03-19 201328]
S3 PAC7302;PAC7302 VGA USB Camera;c:\winnt\system32\drivers\PAC7302.SYS [2008-06-03 457856]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\winnt\system32\drivers\sis7012.sys [2004-11-03 267136]
S3 SISNIC2K;SiS PCI Fast Ethernet Adapter Driver for NDIS5;c:\winnt\system32\drivers\sisnic2k.sys [2006-02-14 32768]
S3 utqxndm3;AVZ Kernel Driver;c:\winnt\system32\drivers\utqxndm3.sys [2009-01-21 7168]
S4 ptssvc;ptssvc;d:\kodak easyshare software\bin\ptssvc.exe --> d:\kodak easyshare software\bin\ptssvc.exe [?]
.
Contenu du dossier 'Tâches planifiées'
2009-01-07 c:\winnt\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.xeoo.com/?p=h&a=f
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
IE: Download with &Shareaza - c:\program files\Shareaza\Plugins\RazaWebHook.dll/3000
LSP: %SystemRoot%\system32\msafd.dll
FF - ProfilePath - c:\documents and settings\chouchouk\Application Data\Mozilla\Firefox\Profiles\gh9pde39.default\
FF - prefs.js: browser.search.selectedEngine - xeoo.com
FF - prefs.js: keyword.URL - hxxp://xeoo.com/?p=url&a=firefox&k=
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-26 22:36:50
Windows 5.0.2195 Service Pack 4 NTFS
detected NTDLL code modification:
ZwOpenFile
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
-------------- =ãþ DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(156)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Heure de fin: 26/01/2009 22:39:28
ComboFix-quarantined-files.txt 2009-01-26 21:39:15
ComboFix2.txt 2009-01-26 19:24:03
Avant-CF: 801 689 600 octets libres
Après-CF: 796,377,088 octets libres
133 --- E O F --- 2009-01-23 07:19:58
rapport combofix d'hier
ComboFix 09-01-21.04 - chouchouk 26/01/2009 22:33:04.7 - NTFSx86 MINIMAL
Microsoft Windows 2000 Professionnel 5.0.2195.4.1252.1.1036.18.480.345 [GMT 1:00]
Lancé depuis: c:\documents and settings\chouchouk\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-26 au 2009-01-26 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 21:29 --------- d-----w c:\program files\CCleaner
2009-01-26 17:44 640,512 ----a-w c:\winnt\system32\drivers\KodakCCS.exe
2009-01-26 13:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\OpenOffice.org2
2009-01-25 22:55 --------- d-----w c:\documents and settings\chouchouk\Application Data\Grisoft
2009-01-23 08:39 7,168 ----a-w c:\winnt\system32\drivers\utqxndm3.sys
2009-01-19 14:57 --------- d---a-w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-12 17:09 186,592 ----a-w c:\winnt\system32\drivers\windrvr6.sys
2009-01-11 21:01 7,679,120 ----a-w c:\program files\setupmozilla.exe
2009-01-09 19:56 --------- d-----w c:\program files\microsoft frontpage
2009-01-07 02:51 --------- d-----w c:\documents and settings\chouchouk\Application Data\Malwarebytes
2009-01-07 02:44 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-05 21:04 --------- d-----w c:\documents and settings\chouchouk\Application Data\AVGTOOLBAR
2009-01-04 22:32 --------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2009-01-01 15:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\dvdcss
2008-12-11 12:09 239,472 ----a-w c:\winnt\system32\drivers\SRV.SYS
2008-03-19 11:34 271 ---h--w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [30/08/07 17:43 4670704]
"internat.exe"="internat.exe" [22/01/09 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [26/01/09 18:42 385024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [10/06/08 03:27 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [21/01/09 09:09 305152]
"VideoLAN"="c:\winnt\system32\head-22-10-10.exe" [21/01/09 19:49 54424]
"CCleaner"="c:\winnt\system32\head-22-10-10.exe" [21/01/09 19:49 54424]
"Synchronization Manager"="mobsync.exe" [26/01/09 18:42 484864 c:\winnt\system32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [26/01/09 18:44 1404928]
"internat.exe"="internat.exe" [22/01/09 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [21/01/09 09:09 224256]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-04-27 843776]
Utility Tray.lnk - c:\winnt\system32\sistray.exe [2008-04-04 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
R3 openhci;Pilote de contrôleur hôte ouvert USB Microsoft;c:\winnt\system32\drivers\openhci.sys [2003-06-23 24784]
S1 is-0RKSTdrv;is-0RKSTdrv;c:\winnt\system32\DRIVERS\43621225.sys --> c:\winnt\system32\DRIVERS\43621225.sys [?]
S1 is-3TB85drv;is-3TB85drv;c:\winnt\system32\DRIVERS\51870077.sys --> c:\winnt\system32\DRIVERS\51870077.sys [?]
S1 is-7BOEOdrv;is-7BOEOdrv;c:\winnt\system32\DRIVERS\[u]0/u0626145.sys --> c:\winnt\system32\DRIVERS\[u]0/u0626145.sys [?]
S1 is-8CPV3drv;is-8CPV3drv;c:\winnt\system32\DRIVERS\13819532.sys --> c:\winnt\system32\DRIVERS\13819532.sys [?]
S1 is-HGME0drv;is-HGME0drv;c:\winnt\system32\DRIVERS\63575778.sys --> c:\winnt\system32\DRIVERS\63575778.sys [?]
S1 is-LD105drv;is-LD105drv;c:\winnt\system32\DRIVERS\92195390.sys --> c:\winnt\system32\DRIVERS\92195390.sys [?]
S3 banshee;banshee;c:\winnt\system32\drivers\banshee.sys [2008-03-24 38928]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\winnt\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S3 nv3;nv3;c:\winnt\system32\drivers\nv3.sys [2008-03-19 201328]
S3 PAC7302;PAC7302 VGA USB Camera;c:\winnt\system32\drivers\PAC7302.SYS [2008-06-03 457856]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\winnt\system32\drivers\sis7012.sys [2004-11-03 267136]
S3 SISNIC2K;SiS PCI Fast Ethernet Adapter Driver for NDIS5;c:\winnt\system32\drivers\sisnic2k.sys [2006-02-14 32768]
S3 utqxndm3;AVZ Kernel Driver;c:\winnt\system32\drivers\utqxndm3.sys [2009-01-21 7168]
S4 ptssvc;ptssvc;d:\kodak easyshare software\bin\ptssvc.exe --> d:\kodak easyshare software\bin\ptssvc.exe [?]
.
Contenu du dossier 'Tâches planifiées'
2009-01-07 c:\winnt\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.xeoo.com/?p=h&a=f
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
IE: Download with &Shareaza - c:\program files\Shareaza\Plugins\RazaWebHook.dll/3000
LSP: %SystemRoot%\system32\msafd.dll
FF - ProfilePath - c:\documents and settings\chouchouk\Application Data\Mozilla\Firefox\Profiles\gh9pde39.default\
FF - prefs.js: browser.search.selectedEngine - xeoo.com
FF - prefs.js: keyword.URL - hxxp://xeoo.com/?p=url&a=firefox&k=
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-26 22:36:50
Windows 5.0.2195 Service Pack 4 NTFS
detected NTDLL code modification:
ZwOpenFile
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
-------------- =ãþ DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(156)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Heure de fin: 26/01/2009 22:39:28
ComboFix-quarantined-files.txt 2009-01-26 21:39:15
ComboFix2.txt 2009-01-26 19:24:03
Avant-CF: 801 689 600 octets libres
Après-CF: 796,377,088 octets libres
133 --- E O F --- 2009-01-23 07:19:58
bonjour lyonnais,
rapport combofix d'hier
ComboFix 09-01-21.04 - chouchouk 26/01/2009 22:33:04.7 - NTFSx86 MINIMAL
Microsoft Windows 2000 Professionnel 5.0.2195.4.1252.1.1036.18.480.345 [GMT 1:00]
Lancé depuis: c:\documents and settings\chouchouk\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-26 au 2009-01-26 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 21:29 --------- d-----w c:\program files\CCleaner
2009-01-26 17:44 640,512 ----a-w c:\winnt\system32\drivers\KodakCCS.exe
2009-01-26 13:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\OpenOffice.org2
2009-01-25 22:55 --------- d-----w c:\documents and settings\chouchouk\Application Data\Grisoft
2009-01-23 08:39 7,168 ----a-w c:\winnt\system32\drivers\utqxndm3.sys
2009-01-19 14:57 --------- d---a-w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-12 17:09 186,592 ----a-w c:\winnt\system32\drivers\windrvr6.sys
2009-01-11 21:01 7,679,120 ----a-w c:\program files\setupmozilla.exe
2009-01-09 19:56 --------- d-----w c:\program files\microsoft frontpage
2009-01-07 02:51 --------- d-----w c:\documents and settings\chouchouk\Application Data\Malwarebytes
2009-01-07 02:44 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-05 21:04 --------- d-----w c:\documents and settings\chouchouk\Application Data\AVGTOOLBAR
2009-01-04 22:32 --------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2009-01-01 15:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\dvdcss
2008-12-11 12:09 239,472 ----a-w c:\winnt\system32\drivers\SRV.SYS
2008-03-19 11:34 271 ---h--w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [30/08/07 17:43 4670704]
"internat.exe"="internat.exe" [22/01/09 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [26/01/09 18:42 385024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [10/06/08 03:27 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [21/01/09 09:09 305152]
"VideoLAN"="c:\winnt\system32\head-22-10-10.exe" [21/01/09 19:49 54424]
"CCleaner"="c:\winnt\system32\head-22-10-10.exe" [21/01/09 19:49 54424]
"Synchronization Manager"="mobsync.exe" [26/01/09 18:42 484864 c:\winnt\system32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [26/01/09 18:44 1404928]
"internat.exe"="internat.exe" [22/01/09 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [21/01/09 09:09 224256]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-04-27 843776]
Utility Tray.lnk - c:\winnt\system32\sistray.exe [2008-04-04 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
R3 openhci;Pilote de contrôleur hôte ouvert USB Microsoft;c:\winnt\system32\drivers\openhci.sys [2003-06-23 24784]
S1 is-0RKSTdrv;is-0RKSTdrv;c:\winnt\system32\DRIVERS\43621225.sys --> c:\winnt\system32\DRIVERS\43621225.sys [?]
S1 is-3TB85drv;is-3TB85drv;c:\winnt\system32\DRIVERS\51870077.sys --> c:\winnt\system32\DRIVERS\51870077.sys [?]
S1 is-7BOEOdrv;is-7BOEOdrv;c:\winnt\system32\DRIVERS\[u]0/u0626145.sys --> c:\winnt\system32\DRIVERS\[u]0/u0626145.sys [?]
S1 is-8CPV3drv;is-8CPV3drv;c:\winnt\system32\DRIVERS\13819532.sys --> c:\winnt\system32\DRIVERS\13819532.sys [?]
S1 is-HGME0drv;is-HGME0drv;c:\winnt\system32\DRIVERS\63575778.sys --> c:\winnt\system32\DRIVERS\63575778.sys [?]
S1 is-LD105drv;is-LD105drv;c:\winnt\system32\DRIVERS\92195390.sys --> c:\winnt\system32\DRIVERS\92195390.sys [?]
S3 banshee;banshee;c:\winnt\system32\drivers\banshee.sys [2008-03-24 38928]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\winnt\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S3 nv3;nv3;c:\winnt\system32\drivers\nv3.sys [2008-03-19 201328]
S3 PAC7302;PAC7302 VGA USB Camera;c:\winnt\system32\drivers\PAC7302.SYS [2008-06-03 457856]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\winnt\system32\drivers\sis7012.sys [2004-11-03 267136]
S3 SISNIC2K;SiS PCI Fast Ethernet Adapter Driver for NDIS5;c:\winnt\system32\drivers\sisnic2k.sys [2006-02-14 32768]
S3 utqxndm3;AVZ Kernel Driver;c:\winnt\system32\drivers\utqxndm3.sys [2009-01-21 7168]
S4 ptssvc;ptssvc;d:\kodak easyshare software\bin\ptssvc.exe --> d:\kodak easyshare software\bin\ptssvc.exe [?]
.
Contenu du dossier 'Tâches planifiées'
2009-01-07 c:\winnt\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.xeoo.com/?p=h&a=f
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
IE: Download with &Shareaza - c:\program files\Shareaza\Plugins\RazaWebHook.dll/3000
LSP: %SystemRoot%\system32\msafd.dll
FF - ProfilePath - c:\documents and settings\chouchouk\Application Data\Mozilla\Firefox\Profiles\gh9pde39.default\
FF - prefs.js: browser.search.selectedEngine - xeoo.com
FF - prefs.js: keyword.URL - hxxp://xeoo.com/?p=url&a=firefox&k=
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-26 22:36:50
Windows 5.0.2195 Service Pack 4 NTFS
detected NTDLL code modification:
ZwOpenFile
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
-------------- =ãþ DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(156)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Heure de fin: 26/01/2009 22:39:28
ComboFix-quarantined-files.txt 2009-01-26 21:39:15
ComboFix2.txt 2009-01-26 19:24:03
Avant-CF: 801 689 600 octets libres
Après-CF: 796,377,088 octets libres
133 --- E O F --- 2009-01-23 07:19:58
rapport combofix d'hier
ComboFix 09-01-21.04 - chouchouk 26/01/2009 22:33:04.7 - NTFSx86 MINIMAL
Microsoft Windows 2000 Professionnel 5.0.2195.4.1252.1.1036.18.480.345 [GMT 1:00]
Lancé depuis: c:\documents and settings\chouchouk\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-26 au 2009-01-26 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 21:29 --------- d-----w c:\program files\CCleaner
2009-01-26 17:44 640,512 ----a-w c:\winnt\system32\drivers\KodakCCS.exe
2009-01-26 13:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\OpenOffice.org2
2009-01-25 22:55 --------- d-----w c:\documents and settings\chouchouk\Application Data\Grisoft
2009-01-23 08:39 7,168 ----a-w c:\winnt\system32\drivers\utqxndm3.sys
2009-01-19 14:57 --------- d---a-w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-12 17:09 186,592 ----a-w c:\winnt\system32\drivers\windrvr6.sys
2009-01-11 21:01 7,679,120 ----a-w c:\program files\setupmozilla.exe
2009-01-09 19:56 --------- d-----w c:\program files\microsoft frontpage
2009-01-07 02:51 --------- d-----w c:\documents and settings\chouchouk\Application Data\Malwarebytes
2009-01-07 02:44 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-05 21:04 --------- d-----w c:\documents and settings\chouchouk\Application Data\AVGTOOLBAR
2009-01-04 22:32 --------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2009-01-01 15:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\dvdcss
2008-12-11 12:09 239,472 ----a-w c:\winnt\system32\drivers\SRV.SYS
2008-03-19 11:34 271 ---h--w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [30/08/07 17:43 4670704]
"internat.exe"="internat.exe" [22/01/09 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [26/01/09 18:42 385024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [10/06/08 03:27 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [21/01/09 09:09 305152]
"VideoLAN"="c:\winnt\system32\head-22-10-10.exe" [21/01/09 19:49 54424]
"CCleaner"="c:\winnt\system32\head-22-10-10.exe" [21/01/09 19:49 54424]
"Synchronization Manager"="mobsync.exe" [26/01/09 18:42 484864 c:\winnt\system32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [26/01/09 18:44 1404928]
"internat.exe"="internat.exe" [22/01/09 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [21/01/09 09:09 224256]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-04-27 843776]
Utility Tray.lnk - c:\winnt\system32\sistray.exe [2008-04-04 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
R3 openhci;Pilote de contrôleur hôte ouvert USB Microsoft;c:\winnt\system32\drivers\openhci.sys [2003-06-23 24784]
S1 is-0RKSTdrv;is-0RKSTdrv;c:\winnt\system32\DRIVERS\43621225.sys --> c:\winnt\system32\DRIVERS\43621225.sys [?]
S1 is-3TB85drv;is-3TB85drv;c:\winnt\system32\DRIVERS\51870077.sys --> c:\winnt\system32\DRIVERS\51870077.sys [?]
S1 is-7BOEOdrv;is-7BOEOdrv;c:\winnt\system32\DRIVERS\[u]0/u0626145.sys --> c:\winnt\system32\DRIVERS\[u]0/u0626145.sys [?]
S1 is-8CPV3drv;is-8CPV3drv;c:\winnt\system32\DRIVERS\13819532.sys --> c:\winnt\system32\DRIVERS\13819532.sys [?]
S1 is-HGME0drv;is-HGME0drv;c:\winnt\system32\DRIVERS\63575778.sys --> c:\winnt\system32\DRIVERS\63575778.sys [?]
S1 is-LD105drv;is-LD105drv;c:\winnt\system32\DRIVERS\92195390.sys --> c:\winnt\system32\DRIVERS\92195390.sys [?]
S3 banshee;banshee;c:\winnt\system32\drivers\banshee.sys [2008-03-24 38928]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\winnt\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S3 nv3;nv3;c:\winnt\system32\drivers\nv3.sys [2008-03-19 201328]
S3 PAC7302;PAC7302 VGA USB Camera;c:\winnt\system32\drivers\PAC7302.SYS [2008-06-03 457856]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\winnt\system32\drivers\sis7012.sys [2004-11-03 267136]
S3 SISNIC2K;SiS PCI Fast Ethernet Adapter Driver for NDIS5;c:\winnt\system32\drivers\sisnic2k.sys [2006-02-14 32768]
S3 utqxndm3;AVZ Kernel Driver;c:\winnt\system32\drivers\utqxndm3.sys [2009-01-21 7168]
S4 ptssvc;ptssvc;d:\kodak easyshare software\bin\ptssvc.exe --> d:\kodak easyshare software\bin\ptssvc.exe [?]
.
Contenu du dossier 'Tâches planifiées'
2009-01-07 c:\winnt\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.xeoo.com/?p=h&a=f
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
IE: Download with &Shareaza - c:\program files\Shareaza\Plugins\RazaWebHook.dll/3000
LSP: %SystemRoot%\system32\msafd.dll
FF - ProfilePath - c:\documents and settings\chouchouk\Application Data\Mozilla\Firefox\Profiles\gh9pde39.default\
FF - prefs.js: browser.search.selectedEngine - xeoo.com
FF - prefs.js: keyword.URL - hxxp://xeoo.com/?p=url&a=firefox&k=
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-26 22:36:50
Windows 5.0.2195 Service Pack 4 NTFS
detected NTDLL code modification:
ZwOpenFile
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
-------------- =ãþ DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(156)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Heure de fin: 26/01/2009 22:39:28
ComboFix-quarantined-files.txt 2009-01-26 21:39:15
ComboFix2.txt 2009-01-26 19:24:03
Avant-CF: 801 689 600 octets libres
Après-CF: 796,377,088 octets libres
133 --- E O F --- 2009-01-23 07:19:58
alors la tu m'as gaté ;-). Post un peu complexe, que je fais pas a pas.
Alors tout d'abord, je n'ai plus aucune protection sur le pc, soit ca marche pas(antivir), soit j'ai viré MBAM et avg 7.5 pour faire de la place y a quelques jours.
- Pour combofix, j'ai bien inséré le cfscript, mais il ne m'a pas demandé 1 ou 2, il a enchainé directement, comme d'habitude. Le rapport est en cours, ensuite je réinstalle HJT pour t'envoyer le rapport.
Jusque la tout va bien :-)
Pour la manip suivante : créer le répertoire répara normalement je pense pas avoir de souci,mais :
Mets le disque d'installation de windows2000 dans le lecteur.
Cherche, sur le disque dur :
userinit.ex*
services.ex*
svchost.ex*
spoolsv.ex*
explorer.ex*
(* permet de trouver et les .ee et les .ex_ )
tu recopies tous les fichiers trouvés dans C:\repara.
Tu notes dans quel répertoire du CD tu les as trouvé et tu le mets en réponse.
je cherche sur le cd ou le DD ? (je voudrais pas faire d'erreur)
Ensuite :
Tu remontes le DD "interne externe".
Clique sur démarrer, tous les programmes, accessoires, puis bloc-note
Dès qu'il s'ouvre, copie/colle le texte ci-dessous dans le bloc note:
dir "E:\*" /a > files.txt
notepad files.txt
Ca correspond a quelque chose de précis le *" ?
Bon je t'envoie les deux rapports dans quelques minutes...
Alors tout d'abord, je n'ai plus aucune protection sur le pc, soit ca marche pas(antivir), soit j'ai viré MBAM et avg 7.5 pour faire de la place y a quelques jours.
- Pour combofix, j'ai bien inséré le cfscript, mais il ne m'a pas demandé 1 ou 2, il a enchainé directement, comme d'habitude. Le rapport est en cours, ensuite je réinstalle HJT pour t'envoyer le rapport.
Jusque la tout va bien :-)
Pour la manip suivante : créer le répertoire répara normalement je pense pas avoir de souci,mais :
Mets le disque d'installation de windows2000 dans le lecteur.
Cherche, sur le disque dur :
userinit.ex*
services.ex*
svchost.ex*
spoolsv.ex*
explorer.ex*
(* permet de trouver et les .ee et les .ex_ )
tu recopies tous les fichiers trouvés dans C:\repara.
Tu notes dans quel répertoire du CD tu les as trouvé et tu le mets en réponse.
je cherche sur le cd ou le DD ? (je voudrais pas faire d'erreur)
Ensuite :
Tu remontes le DD "interne externe".
Clique sur démarrer, tous les programmes, accessoires, puis bloc-note
Dès qu'il s'ouvre, copie/colle le texte ci-dessous dans le bloc note:
dir "E:\*" /a > files.txt
notepad files.txt
Ca correspond a quelque chose de précis le *" ?
Bon je t'envoie les deux rapports dans quelques minutes...
combofix tout d'abord :
ComboFix 09-01-21.04 - chouchouk 27/01/2009 12:50:33.8 - NTFSx86 MINIMAL
Microsoft Windows 2000 Professionnel 5.0.2195.4.1252.1.1036.18.480.344 [GMT 1:00]
Lancé depuis: c:\documents and settings\chouchouk\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\chouchouk\Bureau\cfscript
FILE ::
c:\winnt\system32\3756265427.dat
c:\winnt\system32\bio-22-10-10.exe
c:\winnt\system32\DRIVERS\[u]0/u0626145.sys
c:\winnt\system32\DRIVERS\13819532.sys
c:\winnt\system32\DRIVERS\43621225.sys
c:\winnt\system32\DRIVERS\51870077.sys
c:\winnt\system32\DRIVERS\63575778.sys
c:\winnt\system32\drivers\86179875.sys
c:\winnt\system32\DRIVERS\92195390.sys
c:\winnt\system32\head-22-10-10.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\winnt\system32\3756265427.dat
c:\winnt\system32\bio-22-10-10.exe
c:\winnt\system32\drivers\86179875.sys
c:\winnt\system32\head-22-10-10.exe
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IS-0RKSTDRV
-------\Legacy_IS-3TB85DRV
-------\Legacy_IS-7BOEODRV
-------\Legacy_IS-HGME0DRV
-------\Legacy_IS-LD105DRV
-------\Service_is-0RKSTdrv
-------\Service_is-3TB85drv
-------\Service_is-7BOEOdrv
-------\Service_is-8CPV3drv
-------\Service_is-HGME0drv
-------\Service_is-LD105drv
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-27 au 2009-01-27 ))))))))))))))))))))))))))))))))))))
.
2009-01-27 12:58 . 16,384 c:\winnt\system32\Perflib_Perfdata_42c.dat
2009-01-26 22:29 . 09-01-26 22:29 <DIR> d-------- c:\program files\CCleaner
2009-01-25 23:55 . 09-01-25 23:55 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\Grisoft
2009-01-21 17:21 . 09-01-23 09:39 7,168 --a------ c:\winnt\system32\drivers\utqxndm3.sys
2009-01-19 23:44 . 09-01-27 12:59 54,156 --ah----- c:\winnt\QTFont.qfn
2009-01-19 23:44 . 09-01-23 12:57 1,409 --a------ c:\winnt\QTFont.for
2009-01-12 18:09 . 09-01-12 18:09 186,592 --a------ c:\winnt\system32\drivers\windrvr6.sys
2009-01-11 22:07 . 09-01-11 22:07 0 --a------ c:\winnt\nsreg.dat
2009-01-11 22:01 . 09-01-11 22:01 7,679,120 --a------ c:\program files\setupmozilla.exe
2009-01-10 19:25 . 09-01-10 19:25 144,034 --a------ C:\Sans titre.bmp
2009-01-10 11:03 . 09-01-10 11:03 24,172 --a------ c:\winnt\system32\syncps.dl_
2009-01-09 20:56 . 09-01-09 20:56 <DIR> d-------- c:\program files\microsoft frontpage
2009-01-09 11:14 . 09-01-09 11:14 <DIR> d-------- c:\winnt\ERUNT
2009-01-08 00:34 . 09-01-26 18:52 118,272 --a------ c:\winnt\system32\reg.exe
2009-01-07 03:51 . 09-01-07 03:51 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\Malwarebytes
2009-01-07 03:44 . 09-01-07 03:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-06 23:52 . 04-03-09 01:00 609,824 --a------ c:\winnt\system32\comctl32.ocx
2009-01-05 22:04 . 09-01-05 22:04 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\AVGTOOLBAR
2009-01-04 23:32 . 09-01-04 23:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\Grisoft
2009-01-03 19:24 . 07-10-25 09:00 230,912 -----c--- c:\winnt\system32\dllcache\wmasf.dll
2009-01-03 19:24 . 08-02-15 14:24 96,528 --a------ c:\winnt\system32\dnsrslvr.dll
2009-01-03 16:08 . 09-01-19 15:57 <DIR> d-a------ c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 15:55 . 09-01-03 15:55 <DIR> d-------- c:\winnt\BDOSCAN8
2009-01-03 15:08 . 08-10-16 14:08 27,672 --a------ c:\winnt\system32\wuapi.dll.mui
2009-01-01 16:28 . 09-01-01 16:28 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\dvdcss
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 17:44 673,280 ----a-w c:\winnt\system32\drivers\KodakCCS.exe
2009-01-26 13:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\OpenOffice.org2
2008-12-11 12:09 239,472 ----a-w c:\winnt\system32\drivers\SRV.SYS
2008-03-19 11:34 271 ---h--w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [07-08-30 17:43 4670704]
"internat.exe"="internat.exe" [09-01-22 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [09-01-26 18:42 385024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [08-06-10 03:27 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [09-01-21 09:09 305152]
"Synchronization Manager"="mobsync.exe" [09-01-26 18:42 484864 c:\winnt\system32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [09-01-26 18:44 1515520]
"internat.exe"="internat.exe" [09-01-22 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [09-01-21 09:09 224256]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-04-27 843776]
Utility Tray.lnk - c:\winnt\system32\sistray.exe [2008-04-04 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
R3 openhci;Pilote de contrôleur hôte ouvert USB Microsoft;c:\winnt\system32\drivers\openhci.sys [2003-06-23 24784]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\winnt\system32\drivers\sis7012.sys [2004-11-03 267136]
R3 SISNIC2K;SiS PCI Fast Ethernet Adapter Driver for NDIS5;c:\winnt\system32\drivers\sisnic2k.sys [2006-02-14 32768]
S3 banshee;banshee;c:\winnt\system32\drivers\banshee.sys [2008-03-24 38928]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\winnt\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S3 nv3;nv3;c:\winnt\system32\drivers\nv3.sys [2008-03-19 201328]
S3 PAC7302;PAC7302 VGA USB Camera;c:\winnt\system32\drivers\PAC7302.SYS [2008-06-03 457856]
S3 utqxndm3;AVZ Kernel Driver;c:\winnt\system32\drivers\utqxndm3.sys [2009-01-21 7168]
S4 ptssvc;ptssvc;d:\kodak easyshare software\bin\ptssvc.exe --> d:\kodak easyshare software\bin\ptssvc.exe [?]
.
Contenu du dossier 'Tâches planifiées'
2009-01-07 c:\winnt\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.xeoo.com/?p=h&a=f
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
IE: Download with &Shareaza - c:\program files\Shareaza\Plugins\RazaWebHook.dll/3000
LSP: %SystemRoot%\system32\msafd.dll
FF - ProfilePath - c:\documents and settings\chouchouk\Application Data\Mozilla\Firefox\Profiles\gh9pde39.default\
FF - prefs.js: browser.search.selectedEngine - xeoo.com
FF - prefs.js: keyword.URL - hxxp://xeoo.com/?p=url&a=firefox&k=
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-27 12:58:12
Windows 5.0.2195 Service Pack 4 NTFS
detected NTDLL code modification:
ZwOpenFile
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(188)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
c:\winnt\system32\rsabase.dll
.
Heure de fin: 2009-01-27 13:03:42 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-27 12:03:33
ComboFix2.txt 2009-01-26 21:39:30
ComboFix3.txt 2009-01-26 19:24:03
Avant-CF: 803 930 112 octets libres
Après-CF: 793,735,168 octets libres
168 --- E O F --- 2009-01-23 07:19:58
ComboFix 09-01-21.04 - chouchouk 27/01/2009 12:50:33.8 - NTFSx86 MINIMAL
Microsoft Windows 2000 Professionnel 5.0.2195.4.1252.1.1036.18.480.344 [GMT 1:00]
Lancé depuis: c:\documents and settings\chouchouk\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\chouchouk\Bureau\cfscript
FILE ::
c:\winnt\system32\3756265427.dat
c:\winnt\system32\bio-22-10-10.exe
c:\winnt\system32\DRIVERS\[u]0/u0626145.sys
c:\winnt\system32\DRIVERS\13819532.sys
c:\winnt\system32\DRIVERS\43621225.sys
c:\winnt\system32\DRIVERS\51870077.sys
c:\winnt\system32\DRIVERS\63575778.sys
c:\winnt\system32\drivers\86179875.sys
c:\winnt\system32\DRIVERS\92195390.sys
c:\winnt\system32\head-22-10-10.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\winnt\system32\3756265427.dat
c:\winnt\system32\bio-22-10-10.exe
c:\winnt\system32\drivers\86179875.sys
c:\winnt\system32\head-22-10-10.exe
[COLOR=RED] c:\winnt\system32\userinit.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\services.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\svchost.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\system32\spoolsv.exe . . . est infecté!!/COLOR
[COLOR=RED] c:\winnt\explorer.exe . . . est infecté!!/COLOR
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IS-0RKSTDRV
-------\Legacy_IS-3TB85DRV
-------\Legacy_IS-7BOEODRV
-------\Legacy_IS-HGME0DRV
-------\Legacy_IS-LD105DRV
-------\Service_is-0RKSTdrv
-------\Service_is-3TB85drv
-------\Service_is-7BOEOdrv
-------\Service_is-8CPV3drv
-------\Service_is-HGME0drv
-------\Service_is-LD105drv
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-27 au 2009-01-27 ))))))))))))))))))))))))))))))))))))
.
2009-01-27 12:58 . 16,384 c:\winnt\system32\Perflib_Perfdata_42c.dat
2009-01-26 22:29 . 09-01-26 22:29 <DIR> d-------- c:\program files\CCleaner
2009-01-25 23:55 . 09-01-25 23:55 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\Grisoft
2009-01-21 17:21 . 09-01-23 09:39 7,168 --a------ c:\winnt\system32\drivers\utqxndm3.sys
2009-01-19 23:44 . 09-01-27 12:59 54,156 --ah----- c:\winnt\QTFont.qfn
2009-01-19 23:44 . 09-01-23 12:57 1,409 --a------ c:\winnt\QTFont.for
2009-01-12 18:09 . 09-01-12 18:09 186,592 --a------ c:\winnt\system32\drivers\windrvr6.sys
2009-01-11 22:07 . 09-01-11 22:07 0 --a------ c:\winnt\nsreg.dat
2009-01-11 22:01 . 09-01-11 22:01 7,679,120 --a------ c:\program files\setupmozilla.exe
2009-01-10 19:25 . 09-01-10 19:25 144,034 --a------ C:\Sans titre.bmp
2009-01-10 11:03 . 09-01-10 11:03 24,172 --a------ c:\winnt\system32\syncps.dl_
2009-01-09 20:56 . 09-01-09 20:56 <DIR> d-------- c:\program files\microsoft frontpage
2009-01-09 11:14 . 09-01-09 11:14 <DIR> d-------- c:\winnt\ERUNT
2009-01-08 00:34 . 09-01-26 18:52 118,272 --a------ c:\winnt\system32\reg.exe
2009-01-07 03:51 . 09-01-07 03:51 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\Malwarebytes
2009-01-07 03:44 . 09-01-07 03:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-06 23:52 . 04-03-09 01:00 609,824 --a------ c:\winnt\system32\comctl32.ocx
2009-01-05 22:04 . 09-01-05 22:04 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\AVGTOOLBAR
2009-01-04 23:32 . 09-01-04 23:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\Grisoft
2009-01-03 19:24 . 07-10-25 09:00 230,912 -----c--- c:\winnt\system32\dllcache\wmasf.dll
2009-01-03 19:24 . 08-02-15 14:24 96,528 --a------ c:\winnt\system32\dnsrslvr.dll
2009-01-03 16:08 . 09-01-19 15:57 <DIR> d-a------ c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 15:55 . 09-01-03 15:55 <DIR> d-------- c:\winnt\BDOSCAN8
2009-01-03 15:08 . 08-10-16 14:08 27,672 --a------ c:\winnt\system32\wuapi.dll.mui
2009-01-01 16:28 . 09-01-01 16:28 <DIR> d-------- c:\documents and settings\chouchouk\Application Data\dvdcss
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 17:44 673,280 ----a-w c:\winnt\system32\drivers\KodakCCS.exe
2009-01-26 13:28 --------- d-----w c:\documents and settings\chouchouk\Application Data\OpenOffice.org2
2008-12-11 12:09 239,472 ----a-w c:\winnt\system32\drivers\SRV.SYS
2008-03-19 11:34 271 ---h--w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [07-08-30 17:43 4670704]
"internat.exe"="internat.exe" [09-01-22 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [09-01-26 18:42 385024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [08-06-10 03:27 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [09-01-21 09:09 305152]
"Synchronization Manager"="mobsync.exe" [09-01-26 18:42 484864 c:\winnt\system32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [09-01-26 18:44 1515520]
"internat.exe"="internat.exe" [09-01-22 09:14 88576 c:\winnt\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [09-01-21 09:09 224256]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-04-27 843776]
Utility Tray.lnk - c:\winnt\system32\sistray.exe [2008-04-04 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
R3 openhci;Pilote de contrôleur hôte ouvert USB Microsoft;c:\winnt\system32\drivers\openhci.sys [2003-06-23 24784]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\winnt\system32\drivers\sis7012.sys [2004-11-03 267136]
R3 SISNIC2K;SiS PCI Fast Ethernet Adapter Driver for NDIS5;c:\winnt\system32\drivers\sisnic2k.sys [2006-02-14 32768]
S3 banshee;banshee;c:\winnt\system32\drivers\banshee.sys [2008-03-24 38928]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\winnt\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S3 nv3;nv3;c:\winnt\system32\drivers\nv3.sys [2008-03-19 201328]
S3 PAC7302;PAC7302 VGA USB Camera;c:\winnt\system32\drivers\PAC7302.SYS [2008-06-03 457856]
S3 utqxndm3;AVZ Kernel Driver;c:\winnt\system32\drivers\utqxndm3.sys [2009-01-21 7168]
S4 ptssvc;ptssvc;d:\kodak easyshare software\bin\ptssvc.exe --> d:\kodak easyshare software\bin\ptssvc.exe [?]
.
Contenu du dossier 'Tâches planifiées'
2009-01-07 c:\winnt\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.xeoo.com/?p=h&a=f
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
IE: Download with &Shareaza - c:\program files\Shareaza\Plugins\RazaWebHook.dll/3000
LSP: %SystemRoot%\system32\msafd.dll
FF - ProfilePath - c:\documents and settings\chouchouk\Application Data\Mozilla\Firefox\Profiles\gh9pde39.default\
FF - prefs.js: browser.search.selectedEngine - xeoo.com
FF - prefs.js: keyword.URL - hxxp://xeoo.com/?p=url&a=firefox&k=
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-27 12:58:12
Windows 5.0.2195 Service Pack 4 NTFS
detected NTDLL code modification:
ZwOpenFile
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(188)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
c:\winnt\system32\rsabase.dll
.
Heure de fin: 2009-01-27 13:03:42 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-27 12:03:33
ComboFix2.txt 2009-01-26 21:39:30
ComboFix3.txt 2009-01-26 19:24:03
Avant-CF: 803 930 112 octets libres
Après-CF: 793,735,168 octets libres
168 --- E O F --- 2009-01-23 07:19:58