[Virus] Infecté par spy trojan-spy.win32@mx
Résolu/Fermé
livetliz
Messages postés
20
Date d'inscription
lundi 4 décembre 2006
Statut
Membre
Dernière intervention
31 mars 2007
-
5 déc. 2006 à 21:00
plouf plouf Messages postés 4538 Date d'inscription mercredi 19 avril 2006 Statut Contributeur Dernière intervention 20 décembre 2019 - 27 avril 2008 à 09:31
plouf plouf Messages postés 4538 Date d'inscription mercredi 19 avril 2006 Statut Contributeur Dernière intervention 20 décembre 2019 - 27 avril 2008 à 09:31
A voir également:
- [Virus] Infecté par spy trojan-spy.win32@mx
- Trojan remover - Télécharger - Antivirus & Antimalwares
- L'ordinateur de mustapha a été infecté par un virus répertorié récemment. son anti-virus ne l'a pas détecté. qu'a-t-il pu se passer ? - Forum Virus
- Message virus iphone site adulte - Forum iPhone
- Trojan wacatac ✓ - Forum Virus
- Youtu.be virus - Accueil - Guide virus
87 réponses
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
12 déc. 2007 à 22:54
12 déc. 2007 à 22:54
Crée ton propre poste
A+
A+
Salut Quentin,
Tout d'abord, je te souhaite une très bonne année avec une santé à toute épreuve, un porte-monnaie bien rempli et une vie amoureuse qui rendrait jaloux Dom Juan et Casanova réunis !
Mais si je te re-contacte, c'est parce que j'ai un problème...! Je crois bien avoir un virus et j'ai besoin de ton aide !
Je t'explique : aujourd'hui, j'ai passé ma journée au boulot, et ma copine (qui n'est pas trop au courant de "comment fonctionnent les virus") a discuté avec sa cousine sur MSN quand subitement, elle a reçu plusieurs messages dans sa fenêtre de discussion où il était écrit "C'est pas toi ça ?" suivi d'un lien.
Bien entendu, elle a cliqué sur ce lien qui l'a amenée sur une page. S'en est suivi un téléchargement avec une photo à la c** !
Depuis, chaque fois que je veux parler avec un ami sur MSN, ce même message ("c'est pas toi...") apparaît systématiquement (j'ai prévenu tous mes contacts qu'il y avait de gros risques pour que ce soit un virus et de ne pas cliquer sur ce lien) et je reçois régulièrement un message de mon antivirus (Norton) qui me dit qu'il empêche un virus de passer et l'efface à chaque fois (d'après Norton, le nom du virus serait "Downloader" et il se trouverait dans un fichier qui n'existe pas : Norton me donne le "lieu" exact dudit virus, mais celui-ci n'existe pas dans mon ordi !). Mais le truc est que ce message de Norton revient très régulièrement et que, tout aussi régulièrement, il se passe un truc bizarre : quand une fenêtre est ouverte et que je suis par exemple en train d'écrire quelque chose (d'envoyer un mail, ou de t'écrire ce message) la fenêtre se "déconnecte" et ce que j'écris n'apparaît pas ! Je ne sais pas si je me fais bien comprendre. C'est comme si une fenêtre invisible s'ouvrait par-dessus celle que j'utilise sur le moment. Tu comprends ? Je sais pas si je suis clair...!
"This is how it is", comme on dit (en Angleterre) ! Voilà ce qui m'arrive ! J'ai lancé mon antivirus et je t'envoie ce message en attendant qu'il termine sa recherche de virus. Si tu as une idée de ce que cela pourrait être, je te prie de bien vouloir éclairer ma vessie (que je prends pour une lanterne, lol) !
J'espère vraiment que tu pourras m'aider parce que ça commence vraiement à être chiant ces messages de Norton !!!!!
J'attends de tes nouvelles avec impatience.
@+
Tout d'abord, je te souhaite une très bonne année avec une santé à toute épreuve, un porte-monnaie bien rempli et une vie amoureuse qui rendrait jaloux Dom Juan et Casanova réunis !
Mais si je te re-contacte, c'est parce que j'ai un problème...! Je crois bien avoir un virus et j'ai besoin de ton aide !
Je t'explique : aujourd'hui, j'ai passé ma journée au boulot, et ma copine (qui n'est pas trop au courant de "comment fonctionnent les virus") a discuté avec sa cousine sur MSN quand subitement, elle a reçu plusieurs messages dans sa fenêtre de discussion où il était écrit "C'est pas toi ça ?" suivi d'un lien.
Bien entendu, elle a cliqué sur ce lien qui l'a amenée sur une page. S'en est suivi un téléchargement avec une photo à la c** !
Depuis, chaque fois que je veux parler avec un ami sur MSN, ce même message ("c'est pas toi...") apparaît systématiquement (j'ai prévenu tous mes contacts qu'il y avait de gros risques pour que ce soit un virus et de ne pas cliquer sur ce lien) et je reçois régulièrement un message de mon antivirus (Norton) qui me dit qu'il empêche un virus de passer et l'efface à chaque fois (d'après Norton, le nom du virus serait "Downloader" et il se trouverait dans un fichier qui n'existe pas : Norton me donne le "lieu" exact dudit virus, mais celui-ci n'existe pas dans mon ordi !). Mais le truc est que ce message de Norton revient très régulièrement et que, tout aussi régulièrement, il se passe un truc bizarre : quand une fenêtre est ouverte et que je suis par exemple en train d'écrire quelque chose (d'envoyer un mail, ou de t'écrire ce message) la fenêtre se "déconnecte" et ce que j'écris n'apparaît pas ! Je ne sais pas si je me fais bien comprendre. C'est comme si une fenêtre invisible s'ouvrait par-dessus celle que j'utilise sur le moment. Tu comprends ? Je sais pas si je suis clair...!
"This is how it is", comme on dit (en Angleterre) ! Voilà ce qui m'arrive ! J'ai lancé mon antivirus et je t'envoie ce message en attendant qu'il termine sa recherche de virus. Si tu as une idée de ce que cela pourrait être, je te prie de bien vouloir éclairer ma vessie (que je prends pour une lanterne, lol) !
J'espère vraiment que tu pourras m'aider parce que ça commence vraiement à être chiant ces messages de Norton !!!!!
J'attends de tes nouvelles avec impatience.
@+
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
24 janv. 2008 à 23:06
24 janv. 2008 à 23:06
Salut
lol j arrive en retard.
Meilleurs voeux egalement, tu es toujours infecté ou pas? Et oui je sais ce que c est.
A+
lol j arrive en retard.
Meilleurs voeux egalement, tu es toujours infecté ou pas? Et oui je sais ce que c est.
A+
bonjour est c que qqun pourrai m aider svp j ai le meme probleme que les autres sauf que j ai un probleme en plus qui fait que je ne peux plus scanner mon pc avec un antivirus ou un antispyware j ai demander a plusieur personnes de m aider mais personnes n a reussi alors est ce qu il y aurrai un profesionnel parmi vous j suis vraiment en galere depuis plusieurs jours je remerci d avance celui qui essayera de m aider reponder moi vite svp
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
29 janv. 2008 à 23:37
29 janv. 2008 à 23:37
Salut
Crée ton propre poste LENUM91, quelqu'un te répondra.
A+
Crée ton propre poste LENUM91, quelqu'un te répondra.
A+
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
31 janv. 2008 à 21:28
31 janv. 2008 à 21:28
Soit tu n'es pas assez précis, soit ta demande n'est pas bien formulée, ou soit personne ne sait lol
Salut Quentin,
Je ne pense pas être encore infecté, j'ai cherché sur Internet ce que j'avais pu avoir, et j'ai découvert que je n'étais pas seul dans ce cas-là. J'ai suivi diverses explications (j'ai d'ailleurs changé d'antivirus : de Norton à Antivir), j'ai aussi scanné mon ordi avec MSNFix qui m'a dit que j'étais infecté mais qui a aussi résolu le problème.
Je pense toutefois qu'il reste quelque chose car j'ai régulièrement des messages d'Antivir concernant "TR/Crypt.ULPM.Gen", je le met en quarantaine à chaque fois mais il revient toujours !
Sais-tu ce que c'est ?
J'ai une autre question, j'utilise Azureus, je ne sais pas si tu sais ce que c'est, c'est un logiciel de P2P (oui, je sais, honte à moi ! mais, chuuut). Je ne l'utilise que depuis hier mais depuis ce matin, chaque fois que je le lance, ma connexion Internet se coupe toute seule au bout de quelques minutes et je suis obligé de redémarrer ma FreeBox pour me reconnecter. Mais ce problème recommence encore et encore. J'ai désactivé mon Pare-Feu donc le problème ne doit pas venir de là. Pourrais-tu m'aider ?
J'attend ta réponse impatiemment...
Ciao Quentin.
Je ne pense pas être encore infecté, j'ai cherché sur Internet ce que j'avais pu avoir, et j'ai découvert que je n'étais pas seul dans ce cas-là. J'ai suivi diverses explications (j'ai d'ailleurs changé d'antivirus : de Norton à Antivir), j'ai aussi scanné mon ordi avec MSNFix qui m'a dit que j'étais infecté mais qui a aussi résolu le problème.
Je pense toutefois qu'il reste quelque chose car j'ai régulièrement des messages d'Antivir concernant "TR/Crypt.ULPM.Gen", je le met en quarantaine à chaque fois mais il revient toujours !
Sais-tu ce que c'est ?
J'ai une autre question, j'utilise Azureus, je ne sais pas si tu sais ce que c'est, c'est un logiciel de P2P (oui, je sais, honte à moi ! mais, chuuut). Je ne l'utilise que depuis hier mais depuis ce matin, chaque fois que je le lance, ma connexion Internet se coupe toute seule au bout de quelques minutes et je suis obligé de redémarrer ma FreeBox pour me reconnecter. Mais ce problème recommence encore et encore. J'ai désactivé mon Pare-Feu donc le problème ne doit pas venir de là. Pourrais-tu m'aider ?
J'attend ta réponse impatiemment...
Ciao Quentin.
plouf plouf
Messages postés
4538
Date d'inscription
mercredi 19 avril 2006
Statut
Contributeur
Dernière intervention
20 décembre 2019
801
2 févr. 2008 à 19:15
2 févr. 2008 à 19:15
Bonjour ,
Pour avancer Quentin , de plus, comme tu sembles , impatient ..(cf Par livetliz :J'attend ta réponse impatiemment... )
,
Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
Procèdes comme ceci :
http://pageperso.aol.fr/balltrap34/demofairesontmessage.htm
Merci a bientôt !
Au passage : coucou Quentin :p ;)
Pour avancer Quentin , de plus, comme tu sembles , impatient ..(cf Par livetliz :J'attend ta réponse impatiemment... )
,
Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
Procèdes comme ceci :
http://pageperso.aol.fr/balltrap34/demofairesontmessage.htm
Merci a bientôt !
Au passage : coucou Quentin :p ;)
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
2 févr. 2008 à 23:14
2 févr. 2008 à 23:14
Salut Olivier, Salut Cathy :)
Olivier est un client particulier :p
Comme il etait a l origine de ce poste, ca ne me derange pas de continuer ici :)
Olivier, tu as un rapport HijackThis a me montrer?
Pour azereus oui je connais, ca marche via des torrents...
A+
Olivier est un client particulier :p
Comme il etait a l origine de ce poste, ca ne me derange pas de continuer ici :)
Olivier, tu as un rapport HijackThis a me montrer?
Pour azereus oui je connais, ca marche via des torrents...
A+
Voilà le rapport HiJackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:02:14, on 03/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20696)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\USISrv.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\USB Disk Win98 Driver\Res.EXE
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
C:\Program Files\Fichiers communs\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\eChanblard\emule.exe
C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe
C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead DVD MovieFactory 4.0\AgentVideo.exe
C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Burn.Now 2.0\AgentDataAudio.exe
C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\AgentCopy.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\BLONDE~1\LOCALS~1\Temp\Rar$EX00.641\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.ldlc.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.ldlc.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ldlc-drivers/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par LDLC.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb125\SearchSettings.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [Ulead Quick-Drop] "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Fichiers communs\Ulead Systems\DVD\USISrv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [L08FXLRD_44063687] "C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WkCalRem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.2.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{31F5B7E5-D336-4DC7-9E14-8FF7CB9F9B25}: NameServer = 217.27.32.5,213.228.0.168
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:02:14, on 03/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20696)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\USISrv.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\USB Disk Win98 Driver\Res.EXE
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
C:\Program Files\Fichiers communs\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\eChanblard\emule.exe
C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe
C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead DVD MovieFactory 4.0\AgentVideo.exe
C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Burn.Now 2.0\AgentDataAudio.exe
C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\AgentCopy.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\BLONDE~1\LOCALS~1\Temp\Rar$EX00.641\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.ldlc.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.ldlc.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ldlc-drivers/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par LDLC.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb125\SearchSettings.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [Ulead Quick-Drop] "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Fichiers communs\Ulead Systems\DVD\USISrv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [L08FXLRD_44063687] "C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WkCalRem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.2.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{31F5B7E5-D336-4DC7-9E14-8FF7CB9F9B25}: NameServer = 217.27.32.5,213.228.0.168
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
3 févr. 2008 à 10:54
3 févr. 2008 à 10:54
Re,
Tu as encore des traces de Norton/Symantec, il faut les supprimer!
Pour azereus, non comme ca je ne sais pas, faudrait chercher sur la toile.
Antivir te le détecte sur quel fichier?
A+
Tu as encore des traces de Norton/Symantec, il faut les supprimer!
Pour azereus, non comme ca je ne sais pas, faudrait chercher sur la toile.
Antivir te le détecte sur quel fichier?
A+
plouf plouf
Messages postés
4538
Date d'inscription
mercredi 19 avril 2006
Statut
Contributeur
Dernière intervention
20 décembre 2019
801
3 févr. 2008 à 13:08
3 févr. 2008 à 13:08
Salut Quentin , et livtlz
Olivier est un client particulier :
Je m'en doutais bien aprés lecture , mais je ne savais pas , que tu pratiques ça , sur le forum :o))
Enfin bonne désinf à vous2.
;)
En tout cas , je pensais, bien faire !
-
Olivier est un client particulier :
Je m'en doutais bien aprés lecture , mais je ne savais pas , que tu pratiques ça , sur le forum :o))
Enfin bonne désinf à vous2.
;)
En tout cas , je pensais, bien faire !
-
bonjour, j'avais le meme virus que toi sur mon disque dur mais quand j'ai installé AVAST! antivirus sur mon disque dur ...il disparu pour debon ainssi j'ai installé le SUPERAntiSpyware (il faut le chercher sur googl). bon courage.
Salut,
J'ai enlever tout ce qui restait de Norton et j'ai relancé Antivir.
Voici le rapport d'Antivir :
AntiVir PersonalEdition Classic
Report file date: dimanche 3 février 2008 11:25
Scanning for 1089295 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: SYSTEM
Computer name: LIVETLIZ
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 17:21:25
ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 25/01/2008 17:24:06
ANTIVIR3.VDF : 7.0.2.82 259072 Bytes 01/02/2008 17:19:53
AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 01/02/2008 17:19:53
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 18/01/2008 17:21:27
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: L:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: dimanche 3 février 2008 11:25
Starting search for hidden objects.
'45060' objects were checked, '0' hidden objects were found.
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avnotify.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'Azureus.exe' - '1' Module(s) have been scanned
Scan process 'emule.exe' - '1' Module(s) have been scanned
Scan process 'dwwin.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'hposts08.exe' - '1' Module(s) have been scanned
Scan process 'KHALMNPR.exe' - '1' Module(s) have been scanned
Scan process 'hpoevm08.exe' - '1' Module(s) have been scanned
Scan process 'WkCalRem.exe' - '1' Module(s) have been scanned
Scan process 'WZQKPICK.EXE' - '1' Module(s) have been scanned
Scan process 'SetPoint.exe' - '1' Module(s) have been scanned
Scan process 'PMSHost.exe' - '1' Module(s) have been scanned
Scan process 'LogitechDesktopMessenger.exe' - '1' Module(s) have been scanned
Scan process 'hpotdd01.exe' - '1' Module(s) have been scanned
Scan process 'hpohmr08.exe' - '1' Module(s) have been scanned
Scan process 'uphclean.exe' - '1' Module(s) have been scanned
Scan process 'ULCDRSvr.exe' - '1' Module(s) have been scanned
Scan process 'BlueSoleil.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'StarWindService.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'sqlservr.exe' - '1' Module(s) have been scanned
Scan process 'LWEMon.exe' - '1' Module(s) have been scanned
Scan process 'BTNtService.exe' - '1' Module(s) have been scanned
Scan process 'EDICT.EXE' - '1' Module(s) have been scanned
Scan process 'daemon.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'SearchSettings.exe' - '1' Module(s) have been scanned
Scan process 'Res.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'LVComS.exe' - '1' Module(s) have been scanned
Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
Scan process 'qttask.exe' - '1' Module(s) have been scanned
Scan process 'USISrv.exe' - '1' Module(s) have been scanned
Scan process 'Monitor.exe' - '1' Module(s) have been scanned
Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'WFWIZ.exe' - '1' Module(s) have been scanned
Scan process 'DTVSchdl.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
58 processes with 58 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'K:\'
[NOTE] No virus was found!
Boot sector 'L:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '68' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP221\A0029091.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '47d59f80.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029547.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f85.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029548.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ee.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029549.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f86.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029550.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ef.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029551.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f98.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029552.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f87.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029553.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029554.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f89.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029555.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f88.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029556.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029557.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8a.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029558.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029559.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8b.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029560.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029561.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029562.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8c.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029563.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029564.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8d.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029565.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029566.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8f.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029567.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8e.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029568.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029569.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029570.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029571.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f91.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029572.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fa.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029573.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f82.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029574.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0eb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029575.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f84.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029576.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f93.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029577.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fc.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029578.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f95.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029579.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f90.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029580.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029581.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f92.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029582.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fe.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029583.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f97.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029584.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029585.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f99.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029586.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029587.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f94.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029588.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029589.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029590.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9b.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029591.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029592.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f96.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029593.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ff.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029594.exe
[DETECTION] Contains detection pattern of the dropper DR/Zlob.Gen
[INFO] The file was moved to '47d59e68.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029595.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9d.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029596.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029597.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9f.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029598.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f101.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029599.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e6a.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029600.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f103.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029601.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029602.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029603.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029604.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9a.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029605.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029606.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9c.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029607.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ca.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029608.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029609.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0cc.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029610.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029611.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9e.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029612.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029613.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029614.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ce.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029615.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029616.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e6c.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029617.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f105.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029618.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e6e.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029619.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029621.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029622.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029623.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f107.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029624.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e60.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029625.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f109.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029626.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fab.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029627.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029628.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fad.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029629.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029630.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029631.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029632.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029633.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59faf.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029634.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029635.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0cb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029636.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029637.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0cd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029638.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029639.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0da.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029640.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029641.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029642.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0cf.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029643.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029644.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0dc.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029645.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029646.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0de.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029647.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029648.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fba.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029649.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029650.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029651.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029652.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029653.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029654.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029655.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59faa.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029656.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029657.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029658.exe
[DETECTION] Contains detection pattern of a probably damaged sample CC/00233
[INFO] The file was moved to '4675f0d4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029659.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029660.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fac.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029661.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029662.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029663.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029664.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbf.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029665.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029666.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fae.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029667.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029668.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbc.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029669.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029670.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0aa.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029671.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029672.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbe.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029673.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029674.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029675.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ac.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029676.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029677.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029678.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029679.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029680.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ae.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029681.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029682.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029683.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0db.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029684.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029685.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0dd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029686.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029687.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029688.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fcb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029689.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029690.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0df.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029691.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ed.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029692.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e62.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029693.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029694.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fcd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029695.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f10b.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029696.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e64.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029697.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f10d.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029698.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029699.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fcf.qua'!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
Begin scan in 'K:\' <DD Ext. 2>
Begin scan in 'L:\' <DD Ext. 1>
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP198\A0025613.exe
[DETECTION] Is the Trojan horse TR/Dldr.Zlob.bon.21
[INFO] The file was moved to '47d5b2de.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP206\A0028496.exe
[DETECTION] Contains detection pattern of a probably damaged sample CC/00233
[INFO] The file was moved to '4675ddb7.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029098.com
[DETECTION] Is the Trojan horse TR/Agent.dwd.4
[INFO] The file was moved to '47d5b2e8.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029099.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd81.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029100.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2e9.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029101.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd82.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029102.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2eb.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029103.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd84.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029104.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ea.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029105.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd83.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029106.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ec.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029107.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd85.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029108.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ed.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029109.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd86.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029110.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ef.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029111.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ee.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029112.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd87.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029113.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2e0.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029114.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd89.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029115.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd98.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029116.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f1.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029117.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029118.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2e2.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029119.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd8b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029120.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2e4.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029121.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd8d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029122.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f3.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029123.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9c.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029124.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f5.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029125.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9e.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029126.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f0.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029127.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd99.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029128.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f2.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029129.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f7.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029130.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd90.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029131.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f9.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029132.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd92.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029133.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029134.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f4.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029135.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029136.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f6.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029137.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fb.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029138.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd94.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029139.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fd.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029140.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd96.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029141.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9f.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029142.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2c8.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029143.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda1.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029144.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ff.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029145.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc68.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029146.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b301.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029147.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029148.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ca.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029149.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda3.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029150.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2cc.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029151.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda5.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029152.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b303.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029153.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6c.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029154.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b305.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029155.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6e.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029156.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f8.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029157.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd91.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029158.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fa.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029159.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b307.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029160.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc60.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029161.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b309.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029162.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc62.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029163.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd93.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029164.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fc.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029165.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd95.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029166.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fe.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029167.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b30b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029168.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc64.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029169.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b30d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029170.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd97.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029171.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ce.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029172.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda7.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029173.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2c0.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029174.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc66.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029175.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b30f.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029176.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc78.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029177.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b311.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029178.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda9.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029179.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2c2.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029180.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675ddab.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029181.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2c4.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029182.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc7a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029183.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b313.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029184.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc7c.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029185.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b300.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029186.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc69.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029187.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b302.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029188.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029189.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b315.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029190.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc7e.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029191.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b317.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc70.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029193.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b304.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029194.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029195.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b306.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029196.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b319.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029197.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc72.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029198.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b31b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029199.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc74.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029200.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6f.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029201.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b318.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029202.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] Th
J'ai enlever tout ce qui restait de Norton et j'ai relancé Antivir.
Voici le rapport d'Antivir :
AntiVir PersonalEdition Classic
Report file date: dimanche 3 février 2008 11:25
Scanning for 1089295 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: SYSTEM
Computer name: LIVETLIZ
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 17:21:25
ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 25/01/2008 17:24:06
ANTIVIR3.VDF : 7.0.2.82 259072 Bytes 01/02/2008 17:19:53
AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 01/02/2008 17:19:53
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 18/01/2008 17:21:27
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: L:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: dimanche 3 février 2008 11:25
Starting search for hidden objects.
'45060' objects were checked, '0' hidden objects were found.
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avnotify.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'Azureus.exe' - '1' Module(s) have been scanned
Scan process 'emule.exe' - '1' Module(s) have been scanned
Scan process 'dwwin.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'hposts08.exe' - '1' Module(s) have been scanned
Scan process 'KHALMNPR.exe' - '1' Module(s) have been scanned
Scan process 'hpoevm08.exe' - '1' Module(s) have been scanned
Scan process 'WkCalRem.exe' - '1' Module(s) have been scanned
Scan process 'WZQKPICK.EXE' - '1' Module(s) have been scanned
Scan process 'SetPoint.exe' - '1' Module(s) have been scanned
Scan process 'PMSHost.exe' - '1' Module(s) have been scanned
Scan process 'LogitechDesktopMessenger.exe' - '1' Module(s) have been scanned
Scan process 'hpotdd01.exe' - '1' Module(s) have been scanned
Scan process 'hpohmr08.exe' - '1' Module(s) have been scanned
Scan process 'uphclean.exe' - '1' Module(s) have been scanned
Scan process 'ULCDRSvr.exe' - '1' Module(s) have been scanned
Scan process 'BlueSoleil.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'StarWindService.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'sqlservr.exe' - '1' Module(s) have been scanned
Scan process 'LWEMon.exe' - '1' Module(s) have been scanned
Scan process 'BTNtService.exe' - '1' Module(s) have been scanned
Scan process 'EDICT.EXE' - '1' Module(s) have been scanned
Scan process 'daemon.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'SearchSettings.exe' - '1' Module(s) have been scanned
Scan process 'Res.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'LVComS.exe' - '1' Module(s) have been scanned
Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
Scan process 'qttask.exe' - '1' Module(s) have been scanned
Scan process 'USISrv.exe' - '1' Module(s) have been scanned
Scan process 'Monitor.exe' - '1' Module(s) have been scanned
Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'WFWIZ.exe' - '1' Module(s) have been scanned
Scan process 'DTVSchdl.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
58 processes with 58 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'K:\'
[NOTE] No virus was found!
Boot sector 'L:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '68' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP221\A0029091.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '47d59f80.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029547.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f85.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029548.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ee.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029549.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f86.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029550.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ef.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029551.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f98.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029552.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f87.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029553.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029554.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f89.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029555.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f88.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029556.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029557.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8a.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029558.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029559.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8b.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029560.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029561.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029562.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8c.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029563.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029564.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8d.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029565.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029566.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8f.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029567.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f8e.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029568.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029569.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0e9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029570.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029571.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f91.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029572.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fa.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029573.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f82.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029574.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0eb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029575.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f84.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029576.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f93.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029577.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fc.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029578.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f95.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029579.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f90.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029580.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029581.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f92.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029582.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fe.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029583.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f97.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029584.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029585.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f99.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029586.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029587.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f94.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029588.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0fd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029589.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029590.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9b.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029591.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029592.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f96.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029593.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ff.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029594.exe
[DETECTION] Contains detection pattern of the dropper DR/Zlob.Gen
[INFO] The file was moved to '47d59e68.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029595.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9d.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029596.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029597.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9f.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029598.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f101.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029599.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e6a.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029600.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f103.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029601.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029602.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029603.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029604.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9a.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029605.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029606.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9c.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029607.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ca.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029608.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029609.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0cc.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029610.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029611.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59f9e.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029612.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0f7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029613.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029614.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ce.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029615.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029616.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e6c.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029617.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f105.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029618.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e6e.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029619.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029621.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029622.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029623.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f107.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029624.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e60.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029625.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f109.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029626.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fab.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029627.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029628.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fad.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029629.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029630.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029631.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029632.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029633.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59faf.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029634.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029635.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0cb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029636.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029637.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0cd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029638.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029639.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0da.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029640.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029641.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029642.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0cf.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029643.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029644.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0dc.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029645.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029646.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0de.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029647.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029648.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fba.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029649.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029650.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029651.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029652.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029653.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fa8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029654.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029655.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59faa.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029656.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029657.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029658.exe
[DETECTION] Contains detection pattern of a probably damaged sample CC/00233
[INFO] The file was moved to '4675f0d4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029659.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029660.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fac.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029661.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029662.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029663.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029664.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbf.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029665.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a8.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029666.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fae.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029667.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0c7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029668.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbc.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029669.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc1.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029670.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0aa.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029671.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029672.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fbe.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029673.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029674.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc3.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029675.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ac.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029676.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc5.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029677.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029678.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0d9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029679.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029680.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ae.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029681.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc7.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029682.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a0.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029683.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0db.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029684.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029685.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0dd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029686.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fc9.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029687.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a2.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029688.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fcb.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029689.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fb6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029690.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0df.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029691.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0ed.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029692.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e62.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029693.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a4.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029694.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fcd.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029695.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f10b.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029696.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59e64.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029697.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f10d.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029698.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675f0a6.qua'!
C:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029699.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d59fcf.qua'!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
Begin scan in 'K:\' <DD Ext. 2>
Begin scan in 'L:\' <DD Ext. 1>
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP198\A0025613.exe
[DETECTION] Is the Trojan horse TR/Dldr.Zlob.bon.21
[INFO] The file was moved to '47d5b2de.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP206\A0028496.exe
[DETECTION] Contains detection pattern of a probably damaged sample CC/00233
[INFO] The file was moved to '4675ddb7.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029098.com
[DETECTION] Is the Trojan horse TR/Agent.dwd.4
[INFO] The file was moved to '47d5b2e8.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029099.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd81.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029100.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2e9.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029101.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd82.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029102.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2eb.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029103.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd84.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029104.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ea.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029105.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd83.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029106.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ec.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029107.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd85.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029108.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ed.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029109.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd86.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029110.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ef.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029111.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ee.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029112.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd87.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029113.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2e0.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029114.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd89.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029115.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd98.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029116.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f1.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029117.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029118.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2e2.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029119.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd8b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029120.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2e4.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029121.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd8d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029122.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f3.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029123.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9c.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029124.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f5.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029125.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9e.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029126.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f0.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029127.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd99.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029128.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f2.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029129.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f7.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029130.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd90.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029131.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f9.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029132.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd92.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029133.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029134.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f4.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029135.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029136.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f6.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029137.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fb.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029138.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd94.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029139.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fd.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029140.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd96.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029141.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd9f.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029142.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2c8.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029143.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda1.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029144.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ff.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029145.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc68.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029146.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b301.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029147.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029148.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ca.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029149.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda3.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029150.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2cc.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029151.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda5.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029152.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b303.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029153.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6c.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029154.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b305.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029155.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6e.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029156.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2f8.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029157.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd91.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029158.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fa.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029159.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b307.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029160.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc60.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029161.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b309.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029162.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc62.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029163.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd93.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029164.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fc.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029165.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd95.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029166.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2fe.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029167.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b30b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029168.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc64.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029169.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b30d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029170.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dd97.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029171.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2ce.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029172.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda7.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029173.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2c0.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029174.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc66.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029175.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b30f.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029176.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc78.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029177.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b311.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029178.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dda9.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029179.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2c2.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029180.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675ddab.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029181.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b2c4.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029182.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc7a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029183.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b313.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029184.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc7c.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029185.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b300.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029186.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc69.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029187.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b302.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029188.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029189.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b315.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029190.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc7e.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029191.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b317.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc70.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029193.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b304.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029194.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029195.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b306.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029196.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b319.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029197.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc72.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029198.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b31b.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029199.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc74.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029200.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc6f.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029201.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b318.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029202.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] Th
Le message n'est pas entièrement passé... Voilà le reste :
[INFO] The file was moved to '4675dc71.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029203.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b31a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029204.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b31d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029205.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc76.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029206.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b31f.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029493.exe
[DETECTION] Contains detection pattern of the dropper DR/WhenU.A.47
[INFO] The file was moved to '47d5b30a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029494.exe
[DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F
[INFO] The file was moved to '4675dc63.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029495.exe
[DETECTION] Contains detection pattern of the dropper DR/BHO.W.9
[INFO] The file was moved to '4675dc48.qua'!
End of the scan: dimanche 3 février 2008 13:26
Used time: 2:01:01 min
The scan has been done completely.
16883 Scanning directories
641592 Files were scanned
267 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
267 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
641325 Files not concerned
3873 Archives were scanned
2 Warnings
186 Notes
45060 Objects were scanned with rootkit scan
0 Hidden objects were found
Voici le rapport HiJackThis :
Logfile of HijackThis v1.99.1
Scan saved at 13:35:28, on 03/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20696)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\USISrv.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\USB Disk Win98 Driver\Res.EXE
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Fichiers communs\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\eChanblard\emule.exe
C:\Program Files\Azureus\Azureus.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
C:\Program Files\Mozilla Firefox\firefox.exe
L:\Program Files\VirtualDub\VirtualDub.exe
L:\Programmes\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.ldlc.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.ldlc.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ldlc-drivers/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par LDLC.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb125\SearchSettings.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [Ulead Quick-Drop] "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Fichiers communs\Ulead Systems\DVD\USISrv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [L08FXLRD_44063687] "C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WkCalRem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.2.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{31F5B7E5-D336-4DC7-9E14-8FF7CB9F9B25}: NameServer = 217.27.32.5,213.228.0.168
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSSQL$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe" -sPINNACLESYS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SQLAgent$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE" -i PINNACLESYS (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
Je pense que tu pourras trouver où se trouve le virus qu'Antivir détecte (je ne sais pas où chercher cette info ;p).
Merci de prendre du temps pour mon problème Quentin.
Bonne journée !
[INFO] The file was moved to '4675dc71.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029203.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b31a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029204.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b31d.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029205.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '4675dc76.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP222\A0029206.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '47d5b31f.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029493.exe
[DETECTION] Contains detection pattern of the dropper DR/WhenU.A.47
[INFO] The file was moved to '47d5b30a.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029494.exe
[DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F
[INFO] The file was moved to '4675dc63.qua'!
L:\System Volume Information\_restore{09A3C614-66F8-4445-8937-2A594F0A3506}\RP223\A0029495.exe
[DETECTION] Contains detection pattern of the dropper DR/BHO.W.9
[INFO] The file was moved to '4675dc48.qua'!
End of the scan: dimanche 3 février 2008 13:26
Used time: 2:01:01 min
The scan has been done completely.
16883 Scanning directories
641592 Files were scanned
267 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
267 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
641325 Files not concerned
3873 Archives were scanned
2 Warnings
186 Notes
45060 Objects were scanned with rootkit scan
0 Hidden objects were found
Voici le rapport HiJackThis :
Logfile of HijackThis v1.99.1
Scan saved at 13:35:28, on 03/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20696)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\USISrv.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\USB Disk Win98 Driver\Res.EXE
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Fichiers communs\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\eChanblard\emule.exe
C:\Program Files\Azureus\Azureus.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
C:\Program Files\Mozilla Firefox\firefox.exe
L:\Program Files\VirtualDub\VirtualDub.exe
L:\Programmes\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.ldlc.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.ldlc.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ldlc-drivers/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par LDLC.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb125\SearchSettings.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [Ulead Quick-Drop] "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Fichiers communs\Ulead Systems\DVD\USISrv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [L08FXLRD_44063687] "C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WkCalRem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.2.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{31F5B7E5-D336-4DC7-9E14-8FF7CB9F9B25}: NameServer = 217.27.32.5,213.228.0.168
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSSQL$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe" -sPINNACLESYS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SQLAgent$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE" -i PINNACLESYS (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
Je pense que tu pourras trouver où se trouve le virus qu'Antivir détecte (je ne sais pas où chercher cette info ;p).
Merci de prendre du temps pour mon problème Quentin.
Bonne journée !
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
3 févr. 2008 à 21:06
3 févr. 2008 à 21:06
Bonsoir.
Cathy oui je sais t'inquietes pas :) Bha c'est rare que je fasse cela :)
Olivier, oui, rassures toi, l'infection est inactive.
¤Désactive ta restauration système (uniquement si tu es sous XP):
Clic droit sur poste de travail puis,
propriété, tu cliques sur onglet restauration système
tu coches la case « désactiver la restauration » et applique.
Puis,
¤Réactive ta restauration système (uniquement si tu es sous XP):
Clic droit sur poste de travail puis,
propriété, tu cliques sur onglet restauration système
tu décoches la case « désactiver la restauration » et applique.
A+
Cathy oui je sais t'inquietes pas :) Bha c'est rare que je fasse cela :)
Olivier, oui, rassures toi, l'infection est inactive.
¤Désactive ta restauration système (uniquement si tu es sous XP):
Clic droit sur poste de travail puis,
propriété, tu cliques sur onglet restauration système
tu coches la case « désactiver la restauration » et applique.
Puis,
¤Réactive ta restauration système (uniquement si tu es sous XP):
Clic droit sur poste de travail puis,
propriété, tu cliques sur onglet restauration système
tu décoches la case « désactiver la restauration » et applique.
A+
OK, c'est fait.
Est-ce que je dois redémarrer l'ordi entre ces deux manip' ? Et à quoi ça sert de faire ça...?
Merci.
Est-ce que je dois redémarrer l'ordi entre ces deux manip' ? Et à quoi ça sert de faire ça...?
Merci.
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
3 févr. 2008 à 21:20
3 févr. 2008 à 21:20
Non ne redemarre pas.
En fait, c est un point de ta restauration systeme qui est infecté mais l infection est inactive. Tu la réactiverais si tu utiliserais ta restauration systeme. Ca sert justement a supprimer les anciens points infectes et d en créer un nouveau tout propre :)
En fait, c est un point de ta restauration systeme qui est infecté mais l infection est inactive. Tu la réactiverais si tu utiliserais ta restauration systeme. Ca sert justement a supprimer les anciens points infectes et d en créer un nouveau tout propre :)