Au secour! Alerte NetSky
Estel
-
Estel -
Estel -
Bonjour,
J'ai de plus en plus de soucis avec un PC qui est continuellement infestés de trojans et autres saletés. La dernière en date se nomme NetSky.Y. Je n'arrive pas à m'en défaire et je pense que ce n'est pas le seul problème de cet ordi.
Voici ce que donne le log :
Logfile of HijackThis v1.99.1
Scan saved at 07:37:30, on 27/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\windows\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\Program Files\NavNT\vptray.exe
C:\windows\SOUNDMAN.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Easyphp\easyphp.exe
C:\Program Files\AGS\CBSysTray.exe
C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Easyphp\MySql\bin\mysqld-nt.exe
C:\PROGRA~1\Easyphp\Apache\apache.exe
C:\PROGRA~1\Easyphp\Apache\apache.exe
C:\Program Files\AGS\AgentSrv.EXE
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\NavNT\rtvscan.exe
C:\windows\System32\svchost.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\windows\system32\MsgSys.EXE
C:\windows\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Elisabeth\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.wanadoo.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Easyphp.lnk = ?
O4 - Global Startup: Icône de Barre des tâches de AGS.LNK = C:\Program Files\AGS\CBSysTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://encyclo.voila.fr/JS/tdserver.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {53E0076D-F213-4A39-8705-A8C628DB1133} (SVSViewerCtrl Class) - http://webstatic.masternaut.com/webstatic/activex/SVSXViewer.cab
O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://www.maisonphenix.com/npaecviz.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B7E979F-EB81-466E-AC19-F3ABFB0F643E}: NameServer = 192.168.1.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A3BF33F-5B38-4569-BFDC-4E70C219BF36}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E960E44-95B4-44DE-9EBB-F305235F47CD}: NameServer = 80.10.246.1 80.10.246.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{6B7E979F-EB81-466E-AC19-F3ABFB0F643E}: NameServer = 192.168.1.100
O17 - HKLM\System\CS2\Services\Tcpip\..\{6B7E979F-EB81-466E-AC19-F3ABFB0F643E}: NameServer = 192.168.1.100
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Connected Agent Service (AgentSrv) - Connected Corporation - C:\Program Files\AGS\AgentSrv.EXE
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
Tout vos conseils seront les bienvenus.
Merci d'avance
J'ai de plus en plus de soucis avec un PC qui est continuellement infestés de trojans et autres saletés. La dernière en date se nomme NetSky.Y. Je n'arrive pas à m'en défaire et je pense que ce n'est pas le seul problème de cet ordi.
Voici ce que donne le log :
Logfile of HijackThis v1.99.1
Scan saved at 07:37:30, on 27/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\windows\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\Program Files\NavNT\vptray.exe
C:\windows\SOUNDMAN.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Easyphp\easyphp.exe
C:\Program Files\AGS\CBSysTray.exe
C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Easyphp\MySql\bin\mysqld-nt.exe
C:\PROGRA~1\Easyphp\Apache\apache.exe
C:\PROGRA~1\Easyphp\Apache\apache.exe
C:\Program Files\AGS\AgentSrv.EXE
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\NavNT\rtvscan.exe
C:\windows\System32\svchost.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\windows\system32\MsgSys.EXE
C:\windows\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Elisabeth\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.wanadoo.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Easyphp.lnk = ?
O4 - Global Startup: Icône de Barre des tâches de AGS.LNK = C:\Program Files\AGS\CBSysTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://encyclo.voila.fr/JS/tdserver.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {53E0076D-F213-4A39-8705-A8C628DB1133} (SVSViewerCtrl Class) - http://webstatic.masternaut.com/webstatic/activex/SVSXViewer.cab
O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://www.maisonphenix.com/npaecviz.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B7E979F-EB81-466E-AC19-F3ABFB0F643E}: NameServer = 192.168.1.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A3BF33F-5B38-4569-BFDC-4E70C219BF36}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E960E44-95B4-44DE-9EBB-F305235F47CD}: NameServer = 80.10.246.1 80.10.246.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{6B7E979F-EB81-466E-AC19-F3ABFB0F643E}: NameServer = 192.168.1.100
O17 - HKLM\System\CS2\Services\Tcpip\..\{6B7E979F-EB81-466E-AC19-F3ABFB0F643E}: NameServer = 192.168.1.100
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Connected Agent Service (AgentSrv) - Connected Corporation - C:\Program Files\AGS\AgentSrv.EXE
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
Tout vos conseils seront les bienvenus.
Merci d'avance
A voir également:
- Au secour! Alerte NetSky
- Fausse alerte mcafee - Accueil - Piratage
- Fausse alerte connexion facebook - Guide
- Alerte virus google - Accueil - Virus
- Fausse alerte virus google - Guide
- Alerte changement page web - Forum Réseaux sociaux
1 réponse
salut
ton log semble bon, donc applique ceci
tu charges Sysclean Package là:
http://fr.trendmicro-europe.com/enterprise/support/tsc.php
et le fichier dernière version signatures virus « LTPxxx.ZIP » (xxx représente les chiffres indiquant la version ) là
http://fr.trendmicro-europe.com/enterprise/support/pattern.php
*tu décomprimes le ltpxxx.zip et place le fichier ltp$vpn.xxx dans le même répertoire que Sysclean
* tu redémarres en mode sans échec
*tu lances le scan en cliquant sur sysclean.com et il est créé un fichier sysclean.log dans ce répertoire ;
a+
ton log semble bon, donc applique ceci
tu charges Sysclean Package là:
http://fr.trendmicro-europe.com/enterprise/support/tsc.php
et le fichier dernière version signatures virus « LTPxxx.ZIP » (xxx représente les chiffres indiquant la version ) là
http://fr.trendmicro-europe.com/enterprise/support/pattern.php
*tu décomprimes le ltpxxx.zip et place le fichier ltp$vpn.xxx dans le même répertoire que Sysclean
* tu redémarres en mode sans échec
*tu lances le scan en cliquant sur sysclean.com et il est créé un fichier sysclean.log dans ce répertoire ;
a+
/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/
2005-10-27, 09:09:46, Auto-clean mode specified.
2005-10-27, 09:09:46, Running scanner "C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)\TSC.BIN"...
2005-10-27, 09:11:03, Scanner "C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)\TSC.BIN" has finished running.
2005-10-27, 09:11:03, TSC Log:
Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: Service Pack 2)
Start time : jeu. oct. 27 2005 09:09:46
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)\tsc.ptn" (version 670) [success]
Complete time : jeu. oct. 27 2005 09:11:03
Execute pattern count(4482), Virus found count(0), Virus clean count(0), Clean failed count(0)
2005-10-27, 09:12:27, An error occurred while scanning file "C:\Documents and Settings\Elisabeth\ntuser.dat": Accès refusé.
2005-10-27, 09:12:27, An error occurred while scanning file "C:\Documents and Settings\Elisabeth\ntuser.dat.LOG": Accès refusé.
2005-10-27, 09:35:58, An error occurred while scanning file "C:\Documents and Settings\Elisabeth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Accès refusé.
2005-10-27, 09:35:58, An error occurred while scanning file "C:\Documents and Settings\Elisabeth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Accès refusé.
2005-10-27, 09:41:54, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Accès refusé.
2005-10-27, 09:41:54, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Accès refusé.
2005-10-27, 09:41:54, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Accès refusé.
2005-10-27, 09:41:54, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Accès refusé.
2005-10-27, 09:49:06, An error was detected on "C:\System Volume Information\*.*": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\A2SCAN.EXE-063BA2F1.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\A2UPD.EXE-04632ABF.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\ACRORD32.EXE-20C463C1.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\AGENTLOGGER.EXE-218450CC.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\AGENTSRV.EXE-01F48201.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\AHUI.EXE-10CE5D84.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\APACHE.EXE-10CEF086.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\APICLS.EXE-0F1F0379.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\APICLS.EXE-17F791E0.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\APICMPT8.EXE-3785EDE9.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\ARPIDFIX.EXE-06714C4C.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\ARPIDFIX.EXE-10AA19E0.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\ARPIDFIX.EXE-12B91902.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\ARPIDFIX.EXE-17D99E59.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\ARPIDFIX.EXE-20AF23B6.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\ARPIDFIX.EXE-2252DC6C.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\ARPIDFIX.EXE-235008C6.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\ARPIDFIX.EXE-2C4CADAF.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\BRSPL01A.EXE-0BCDFE17.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\CALC.EXE-02CD573A.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\CLEANUP.EXE-1B0F5664.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\COBACKUP.EXE-0968CD3E.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\CONTROL.EXE-013DBFB5.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\COPERNICAGENTUNINSTALL.EXE-1D95D472.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\COPERN~1.EXE-2CDF8F75.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\DESIGNP.EXE-061B9D74.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\DIRECTCD.EXE-0A60B47C.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\DSLMON.EXE-1476FDB3.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\DUMPREP.EXE-1B46F901.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\DWHWIZRD.EXE-2329ED85.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\EXCEL.EXE-1C75F8D6.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\FAX.EXE-1A04CF65.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\FIREFOX.EXE-28641590.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\FXNETSKY.EXE-0FAC66CE.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\FXNETSKY[1].EXE-00AD20F0.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\GESTION.EXE-3515AB9E.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\GLB1A2B.EXE-2C18B0B9.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-0D3287F0.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\IS-CFCFO.TMP-1CE0398B.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\JUSCHED.EXE-012EA23E.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\KPF4GUI.EXE-2F166019.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\LAUNCHER.EXE-164E19EE.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\Layout.ini": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\LUALL.EXE-2BCC229F.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\LUCOMS~1.EXE-02DB5950.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\MMC.EXE-0ED7F20E.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\MRT.EXE-1B4A8D49.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\MRTSTUB.EXE-141C1EA3.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\MSIEXEC.EXE-2F8A8CAE.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\MYSQLADMIN.EXE-06B00072.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\MYSQLD-NT.EXE-1DCF6C6B.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\OLFMOD32.EXE-35D4773F.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\OUTLOOK.EXE-179DEC04.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\OUTLOOK.EXE-3784AE71.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\POWARC950.EXE-1223E5D8.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\POWERARC.EXE-37FF1F0A.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\RASAUTOU.EXE-18B88A68.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\REGISTRYPLANEDITOR.EXE-05FB5D38.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-1793274A.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-1EFACBAB.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-268BFF96.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-2E789874.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-347B8711.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-43C186A8.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP.EXE-393E66AE.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\SOUNDMAN.EXE-19745A34.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\SSMYPICS.SCR-01C62024.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.COM-0FAF268F.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.COM-11C4357B.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-075FC502.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-388DBBCC.pf": Accès refusé.
2005-10-27, 09:59:25, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-3AA2CAB8.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSOCMGR.EXE-31169C54.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.EXE-12A95C43.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.EXE-1E62F8C9.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.EXE-26B1779C.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UNPACK200.EXE-09358BF8.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UNWISE.EXE-09A60022.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-00835EC6.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-01F38E48.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-044D3AEC.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-0C651609.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-0E368481.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-13BDF80C.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-13E349B8.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1847A3BB.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-19327AA1.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1C0E6E76.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2D91828D.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2EEC1067.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-36210406.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-37D2370B.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-39658E66.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\VPC32.EXE-29593AFF.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\VPDN_LU.EXE-1D1611C8.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\VPTRAY.EXE-01C37178.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\VTTIMER.EXE-023BA77F.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\WATCH.EXE-0DACDE18.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\WFXMSRVR.EXE-1AF06447.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWS-KB890830-V1.9-DELTA-F-2F902C1E.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\WINNT32.EXE-07CE5394.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\WINWORD.EXE-10D55173.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\WSCNTFY.EXE-1B24F5EB.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\WZQKPICK.EXE-350A392A.pf": Accès refusé.
2005-10-27, 09:59:26, Could not set file for reading on "C:\WINDOWS\Prefetch\_PASETUP.EXE-0F518B2C.pf": Accès refusé.
2005-10-27, 10:02:50, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Accès refusé.
2005-10-27, 10:02:50, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Accès refusé.
2005-10-27, 10:02:50, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Accès refusé.
2005-10-27, 10:02:50, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Accès refusé.
2005-10-27, 10:02:50, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Accès refusé.
2005-10-27, 10:02:50, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Accès refusé.
2005-10-27, 10:02:50, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Accès refusé.
2005-10-27, 10:02:50, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Accès refusé.
2005-10-27, 10:02:51, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Accès refusé.
2005-10-27, 10:02:51, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Accès refusé.
2005-10-27, 10:04:54, Running scanner "C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)\VSCANTM.BIN"...
2005-10-27, 10:34:58, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 10/27/2005 10:04:55
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 913 (111750 Patterns) (2005/10/26) (291300)
Command Line: C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)
41831 files have been read.
41831 files have been checked.
37167 files have been scanned.
73784 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/27/2005 10:34:58
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-27, 10:34:58, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 10/27/2005 10:04:55
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 913 (111750 Patterns) (2005/10/26) (291300)
Command Line: C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)
41831 files have been read.
41831 files have been checked.
37167 files have been scanned.
73784 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/27/2005 10:34:58 29 minutes 58 seconds (1798.05 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-27, 10:34:58, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 10/27/2005 10:04:55
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 913 (111750 Patterns) (2005/10/26) (291300)
Command Line: C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)
41831 files have been read.
41831 files have been checked.
37167 files have been scanned.
73784 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/27/2005 10:34:58 29 minutes 58 seconds (1798.05 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-27, 10:34:58, Scanner "C:\Documents and Settings\Elisabeth\Bureau\Nouveau dossier (3)\VSCANTM.BIN" has finished running.