Worm brontok,fichier exe et redémarrage autom

meriem3105 -  
 meriem3105 -
Bonjour à tous,

J'ai infecté mon ordinateur à partir d'une clé USB du Virus Worm Brontok, il copie chaque dossier existant. Mon PC redémarrait à chaque fois mais depuis je suis confrontée à deux autres poblèmes:

1. Après avoir nettoyé les fichiers infectés par le virus Worm brontok par Cleaner, deux fichiers executables (host.exe et svchost.exe) ont été supprimés mais le virus est toujours présents.

2. Depuis, dès que j'essaye de télécharger sur Inernet un antivirus (bifender et norton) le redémarrage de l'ordinateur se fait automatiquement dès l'exécution.

Merci de me répondre car le PC en question est celui du bureau où je travaille.
A voir également:

36 réponses

meriem3105
 
ceci est le rapprot clean avant l'opération 2 c à dire 1 la rechrche d fichiers infectés.
17/06/2007 a 10:10:57,67

*** Recherche des fichiers dans D:
D:\autorun.inf FOUND
D:\host.exe FOUND

*** Recherche des fichiers dans D:\WINDOWS\
D:\WINDOWS\svchost.exe FOUND

*** Recherche des fichiers dans D:\WINDOWS\system32

*** Recherche des fichiers dans D:\Program Files
*** Fin du rapport !
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

1) Ton antivirus semble déconnecté.

Regarde ce qui se passe;

2) trouve moi le rapport qui t'a détecté 2 malwares et poste le.
@+
0
meriem3105
 
bonjour,

je ne pense pas pouvoir ou savoir car c lorsque g installé zone alarm l'analyse a été effectuée juste après

deux fenetres se sont ouvertes:

1.temps2.exe a rencontré un probleme et doit fermer...envoyer le rapport, ne pas envoyer le rappot
2.vous avez choisi de mettre fin au programme ne répondant pas, rundll32.exe....envoyer le rapprort, ne pas envoyer le rapport
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Re,

fais les points 1, 2 et 3 de ce lien :

virus methode preliminaire de desinfection version fr

Poste les rapports.
@+
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
meriem3105
 
Bonjour,

J'ai suivis les étapes du lien proposé hier.Arrivée à Bitfender g arrêté l'application au milieu du scan.
En téléchargeant AVG, le sdeux virus ont été intercepté, mis en quarantaine et supprimé après.

Voici le rapprot AVG

VG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 11:06:29 19/06/2007

+ Résultat de l'analyse:
Rien à signaler.

Fin du rapport

Le rapport Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 13:12:33, on 19/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\WINDOWS\system32\cisvc.exe
D:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Program Files\Norton Utilities\NPROTECT.EXE
D:\WINDOWS\system32\tcpsvcs.exe
D:\Program Files\Speed Disk\nopdb.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE
D:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
D:\WINDOWS\SOUNDMAN.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\WISPTIS.EXE
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCSVR.EXE
D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
D:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006\EDICT.EXE
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\NOTEPAD.EXE
D:\Documents and Settings\isra\Bureau\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
F3 - REG:win.ini: load=D:\WINDOWS\svchost.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - D:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - D:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] D:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [EPSON Stylus C45 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB001" /M "Stylus C45"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [E06FDXRC_26102765] "D:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006\EDICT.EXE" -m
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Windows Live Search - res://D:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - D:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://www.mayeticvillage.fr/qp2.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{29936F45-DAAE-4BFC-B28C-D402C2146540}: NameServer = 208.67.222.222 193.55.10.102
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Boonty Games - BOONTY - D:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - D:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - D:\Program Files\Speed Disk\nopdb.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZONELABS\vsmon.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - D:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

ton antivirus semble toujours désactivé.

Si c'est le cas, tu vas rapidement avoir des ennuis.
Scan AVG et rapport

Scan Bit defender et rapport.
@+

0
meriem3105
 
j'ai téléchargé avast.

au démarrage de l'ordinateur une verification inteminable commence que j'iterrompt en rebootant.

voici le rapprot avg

---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 12:07:21 28/06/2007

+ Résultat de l'analyse:

D:\Documents and Settings\isra\Cookies\isra@advertising[2].txt -> TrackingCookie.Advertising : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@adviva[1].txt -> TrackingCookie.Adviva : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@bluestreak[2].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@casalemedia[1].txt -> TrackingCookie.Casalemedia : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@fastclick[1].txt -> TrackingCookie.Fastclick : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Aucune action entreprise.
D:\Documents and Settings\isra\Cookies\isra@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
D:\WINDOWS\xcopy.exe -> Trojan.Copyself : Aucune action entreprise.
D:\WINDOWS\KesenjanganSosial.exe -> Worm.Brontok.c : Aucune action entreprise.

Fin du rapport
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonsoir,

l'infection est revenue.

Essaye de supprimer D:\WINDOWS\xcopy.exe

recommence le post 2
@+
0
meriem3105
 
bonjour,
voici le rapport avg

--------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 10:20:32 07/07/2007

+ Résultat de l'analyse:

D:\Documents and Settings\isra\Cookies\isra@2o7[2].txt -> TrackingCookie.2o7 : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@microsoftwlmessengermkt.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@adrevolver[1].txt -> TrackingCookie.Adrevolver : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@statcounter[2].txt -> TrackingCookie.Statcounter : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Nettoyé.
D:\Documents and Settings\isra\Cookies\isra@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Nettoyé.
D:\WINDOWS\xcopy.exe -> Trojan.Copyself : Nettoyé.
D:\WINDOWS\KesenjanganSosial.exe -> Worm.Brontok.c : Nettoyé.

Fin du rapport

et mon ordinateur fait un drole de bruit
0
meriem3105
 
bonjour,

les deux fenetres s'affichent encore :

windows ne trouve pas d:/windows/svchost.exe
et
impossible de charger ou d'exécuter d:/windows/svchost.exe
0
meriem3105
 
Bonjour,
Mon ordinateur bloque parfois.
Je redémarre pour pouvoir m'en servir
0
yallax Messages postés 3 Statut Membre
 
salut
voila g u le mm problem g u un virus ac une clé USB g le log du fix et le log hijackthis
mai pouvai maider a les déchiffrer svp

Norman Generic Fix
Copyright © 1990 - 2006, Norman ASA. Built 2006/12/07 16:49:23

Norman Scanner Engine Version: 5.90.27
Nvcbin.def Version: 5.90.00, Date: 2006/12/07 16:49:23, Variants: 1469
Nvcmacro.def Version: 5.90.00, Date: 2006/05/30 15:17:46, Variants: 12

Running pre-scan cleanup routine:
Operating System: Microsoft Windows XP Professional 5.1.2600(Safe mode) Service Pack 2
Logged on user: NOM-5A5F9B7060C\jerome

Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell = "Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"" -> "Explorer.exe"
Removed registry value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00AAEFE0

Scan started: 09/07/2007 00:04:43

Scanning running processes and process memory...

C:\Documents and Settings\jerome\Local Settings\Application Data\winlogon.exe (Infected with W32/Rontokbro.CX@mm)
Terminated process
Deleted file

C:\Documents and Settings\jerome\Local Settings\Application Data\services.exe (Infected with W32/Rontokbro.CX@mm)
Terminated process
Deleted file

C:\Documents and Settings\jerome\Local Settings\Application Data\lsass.exe (Infected with W32/Rontokbro.CX@mm)
Terminated process
Deleted file

Number of processes/threads found: 506
Number of processes/threads scanned: 506
Number of processes/threads not scanned: 0
Number of infected processes/threads terminated: 3
Total scanning time: 0 minutes 15 seconds

Scanning file system...

C:\*.*

C:\Documents and Settings\jerome\Local Settings\Application Data\br3951on.exe (Infected with W32/Rontokbro.CX@mm)
Removed registry value: HKCU\Software\Microsoft\Windows\CurrentVersion\Run -> Tok-Cirrhatus-1464 = ""C:\Documents and Settings\jerome\Local Settings\A...."
Deleted file

C:\Documents and Settings\jerome\Local Settings\Application Data\csrss.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Local Settings\Application Data\inetinfo.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Local Settings\Application Data\smss.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Local Settings\Application Data\svchost.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Menu Démarrer\Programmes\Démarrage\Empty.pif (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Mes documents.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\carote\carote.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Ma musique\Ma musique.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Ma musique\Artiste inconnu\Album inconnu (23-05-2007 17-22-29)\Album inconnu (23-05-2007 17-22-29).exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Ma musique\Artiste inconnu\Album inconnu (23-05-2007 17-30-45)\Album inconnu (23-05-2007 17-30-45).exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Ma musique\Downloads1\Downloads1.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Ma musique\Downloads1\Metadata\Metadata.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Ma musique\louise attaque\Album inconnu (23-05-2007 16-46-20)\Album inconnu (23-05-2007 16-46-20).exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Ma musique\mony\mony.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Ma musique\tek\tek.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Mes fichiers reçus\Mes fichiers reçus.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Mes images\Mes images.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Mes images\chez g\chez g.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Mes images\lrems\lrems.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Mes images\martine\martine.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Mes images\mixte\mixte.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Mes images\moi et gros\moi et gros.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\Mes vidéos\Mes vidéos.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\otre\otre.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Mes documents\portables video\portables video.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\Documents and Settings\jerome\Modèles\6084-NendangBro.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc77.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc78.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc79.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc80.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc81.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc82.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc83.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc84.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc85.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\RECYCLER\S-1-5-21-3754816547-2936463933-4123483005-1005\Dc86.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013395.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013396.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013397.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013398.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013399.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013400.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013401.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013402.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013408.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013409.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013410.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013411.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013412.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013413.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013414.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013416.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013417.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013418.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013419.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013420.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013421.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013429.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013430.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013431.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013432.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013433.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013434.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013435.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013436.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013437.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013438.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013439.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013441.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013444.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013469.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013470.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013471.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013472.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013473.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013475.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013476.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013478.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013480.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013481.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013482.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013483.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013484.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013489.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013490.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013491.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013492.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013493.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013494.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013495.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013496.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013500.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013501.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013502.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0013503.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014489.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014490.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014491.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014492.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014493.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014494.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014495.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014496.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014497.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014498.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014499.pif (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014500.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014501.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014502.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014507.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014508.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014509.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014510.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014511.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014512.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014513.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014514.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014515.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014519.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014520.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014521.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014522.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014528.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014529.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014530.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014531.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014532.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014533.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014534.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014535.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014539.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014540.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014541.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014542.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014551.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014552.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014553.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014554.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014556.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014557.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014559.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014560.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014561.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014563.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014564.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014565.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014571.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014572.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014573.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014574.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014575.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014576.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014577.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014578.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014579.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014584.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014585.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014586.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014594.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014595.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014596.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014597.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014598.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014599.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014600.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014601.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014603.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014606.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014607.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014608.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014609.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014613.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014614.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014615.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014616.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014617.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014618.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014619.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014620.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014621.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014622.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014623.pif (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014624.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014625.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014626.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014644.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014645.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014646.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014647.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014648.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014649.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014650.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014651.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014655.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014656.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014657.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014658.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014665.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014666.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014667.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014668.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014669.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014670.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014671.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014672.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014673.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014674.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014675.pif (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014676.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014677.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014678.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014692.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014693.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014694.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014695.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014696.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014697.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014698.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014699.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014703.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014704.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014705.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014706.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014707.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014713.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014714.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014715.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014716.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014717.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014718.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014719.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014720.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014721.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014725.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014726.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP30\A0014727.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014731.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014732.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014733.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014737.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014738.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014739.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014740.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014741.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014742.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014743.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014744.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014745.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014749.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP31\A0014760.pif (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014774.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014775.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014776.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014780.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014781.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014782.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014783.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014784.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014785.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014786.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014787.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014788.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014789.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014800.pif (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014809.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014810.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014811.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014812.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014813.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014814.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014815.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014816.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014817.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014821.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014822.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014823.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014831.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014832.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014833.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014834.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014835.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014836.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014837.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014838.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014842.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014843.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014844.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014850.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014851.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014852.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014853.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014854.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014855.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014856.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014857.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014861.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014862.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014863.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP32\A0014864.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014870.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014871.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014872.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014873.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014874.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014875.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014876.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014877.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014878.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014882.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014883.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014884.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP34\A0014885.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014887.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014888.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014889.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014890.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014894.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014895.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014896.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014897.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014898.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014899.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014900.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014901.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014902.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014911.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014912.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014913.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014914.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014915.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014916.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014917.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014918.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014919.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014923.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014924.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP35\A0014925.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014927.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014928.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014929.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014933.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014934.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014935.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014936.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014937.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014938.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014939.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014940.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014941.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014946.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014957.pif (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014968.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014969.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014970.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014972.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014974.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014975.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014976.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014977.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014978.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014979.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014980.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014981.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014988.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014989.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014990.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014991.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014992.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014993.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014994.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014995.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0014996.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015000.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015001.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015002.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015003.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015009.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015010.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015011.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015012.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015013.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015014.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015015.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015016.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015020.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015021.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015022.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015023.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015027.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015028.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015029.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015030.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015031.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015032.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015033.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015034.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015035.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015036.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015037.pif (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015038.com (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015039.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A00
0
yallax Messages postés 3 Statut Membre
 
C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015040.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015041.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015042.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015043.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015044.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015045.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015046.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015047.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015048.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\System Volume Information\_restore{BCC7C08E-B1CE-47C2-B44B-890CE81FE6FC}\RP36\A0015049.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\WINDOWS\KesenjanganSosial.exe (Infected with W32/Rontokbro.CX@mm)
Deleted file

C:\WINDOWS\ShellNew\RakyatKelaparan.exe (Infected with W32/Rontokbro.CX@mm)
Removed registry value: HKLM\Software\Microsoft\Windows\CurrentVersion\Run -> Bron-Spizaetus = ""C:\WINDOWS\ShellNew\RakyatKelaparan.exe""
Deleted file

C:\WINDOWS\system32\cmd-brontok.exe (Infected with W32/Rontokbro.CX@mm)
Removed registry value: HKLM\System\CurrentControlSet\Control\SafeBoot -> AlternateShell = "cmd-brontok.exe"
Deleted file

C:\WINDOWS\system32\jerome's Setting.scr (Infected with W32/Rontokbro.CX@mm)
Deleted file

Running post-scan cleanup routine:

Number of files found: 80297
Number of archives unpacked: 13304
Number of files scanned: 80272
Number of files not scanned: 25
Number of files skipped due to exclude list: 5
Number of infections found: 416
Number of infected files repaired/deleted: 416
Total scanning time: 65 minutes 04 seconds
0
yallax Messages postés 3 Statut Membre
 
et voila le log hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 13:49:19, on 09/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
D:\FIX_VBWORM_RONTOK_LIGHTMOON.EXE
C:\WINDOWS\system32\temp1.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com/fsc/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/fuji/defaults/su/*https://fr.yahoo.com/?p=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Muscbrigade] c:\Musicbrigade\Musicbrigade.exe check
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [fsc-reminder.exe] C:\WINDOWS\reminder\fsc-reminder.exe 2454226 4
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonsoir,

yallax,

Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
Procèdes comme ceci :

http://perso.orange.fr/rginformatique/section%20virus/demofairesontmessage.htm

meriem, où en es tu ?

refais passer le programme anti brontok que tu as téléchargé au post 2 et poste le log.
@+
0
meriem3105
 
Bonjour,
Finalement j'ai fait formater mon ordinateur car il a été totalement bloqué.
C'est pour cette raison que je n'ai pas répondu depuis.
Merci pour tout
Meriem
0