Help, je suis envahi de virus/vers W32 merci

scoubidou78 -  
 scoubidou78 -
Bonjour a toutes et a tous,

depuis un certain moment je suis envahi de virus /vers W32, mon ordinateur rame a un point que je n arive meme plus a me connecter car sa coupe et je ne sais pas du tout quoi faire sachant que je suis nul en informatique.

j ai avast comme antivirus avec un ordinateur hp de 256mo de ram

merci de m aidez tres vite

a bientot

je vous laisse mon Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:51:51, on 08/12/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\dllcache\windmns.exe
C:\WINDOWS\System32\dllcache\wintcpack.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\Gothic.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\System32\load.exe
C:\WINDOWS\System32\eXtream.exe
C:\WINDOWS\System32\kdjfsdklfjsl.exe
C:\WINDOWS\System32\SADASDA.exe
C:\WINDOWS\System32\Srb0ty.exe
C:\WINDOWS\System32\Syst3m32.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\WINDOWS\System32\pctspk.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\GetWaylayer32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\xbvuxowlewiv.exe
C:\WINDOWS\System32\Win.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr3.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr3.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr3.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr3.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [kiss] C:\Program Files\killSh\pingy.exe
O4 - HKLM\..\Run: [Critical Error Safe32] C:\WINDOWS\System32\GetWaylayer32.exe
O4 - HKLM\..\Run: [HOT FIX] Gothic.exe
O4 - HKLM\..\Run: [Windows Service Agccnt] wanwwsx.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MicroSoft sys3s1] h4ckn3t.exe
O4 - HKLM\..\Run: [MicroSoft ssadsadas3s1] eXtream.exe
O4 - HKLM\..\Run: [MicroSoft ssadssjdhasjadas3s1] kdjfsdklfjsl.exe
O4 - HKLM\..\Run: [MicroSoft Getway mqbol] xbvuxowlewiv.exe
O4 - HKLM\..\Run: [MicroSoft ssas3s1] SADASDA.exe
O4 - HKLM\..\Run: [MicroSoft Legal Service] Srb0ty.exe
O4 - HKLM\..\Run: [Windows Secure Update] load.exe
O4 - HKLM\..\Run: [MicroSoft Legal Syst3m32] Syst3m32.exe
O4 - HKLM\..\Run: [smsger] C:\WINDOWS\System32\Win.exe
O4 - HKLM\..\Run: [MicroSoft Visual Framwork] MS32.exe
O4 - HKLM\..\Run: [WinDLL (Wseclayer.exe)] rundll32.exe C:\WINDOWS\System32\Wseclayer.exe,start
O4 - HKLM\..\RunServices: [HOT FIX] Gothic.exe
O4 - HKLM\..\RunServices: [Windows Service Agccnt] wanwwsx.exe
O4 - HKLM\..\RunServices: [MicroSoft sys3s1] h4ckn3t.exe
O4 - HKLM\..\RunServices: [MicroSoft ssadsadas3s1] eXtream.exe
O4 - HKLM\..\RunServices: [MicroSoft ssadssjdhasjadas3s1] kdjfsdklfjsl.exe
O4 - HKLM\..\RunServices: [MicroSoft Getway mqbol] xbvuxowlewiv.exe
O4 - HKLM\..\RunServices: [MicroSoft ssas3s1] SADASDA.exe
O4 - HKLM\..\RunServices: [MicroSoft Legal Service] Srb0ty.exe
O4 - HKLM\..\RunServices: [Windows Secure Update] load.exe
O4 - HKLM\..\RunServices: [MicroSoft Legal Syst3m32] Syst3m32.exe
O4 - HKLM\..\RunServices: [smsger] C:\WINDOWS\System32\Win.exe
O4 - HKLM\..\RunServices: [MicroSoft Visual Framwork] MS32.exe
O4 - HKLM\..\RunOnce: [HOT FIX] Gothic.exe
O4 - HKLM\..\RunOnce: [Windows Secure Update] load.exe
O4 - HKLM\..\RunOnce: [MicroSoft sys3s1] h4ckn3t.exe
O4 - HKLM\..\RunOnce: [MicroSoft ssadsadas3s1] eXtream.exe
O4 - HKLM\..\RunOnce: [MicroSoft ssadssjdhasjadas3s1] kdjfsdklfjsl.exe
O4 - HKLM\..\RunOnce: [MicroSoft ssas3s1] SADASDA.exe
O4 - HKLM\..\RunOnce: [MicroSoft Legal Service] Srb0ty.exe
O4 - HKLM\..\RunOnce: [MicroSoft Legal Syst3m32] Syst3m32.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ErrorSafeFree] "C:\Program Files\ErrorSafe Free\uers.exe" /min
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Critical Error Safe32] C:\WINDOWS\System32\GetWaylayer32.exe
O4 - HKCU\..\Run: [HOT FIX] Gothic.exe
O4 - HKCU\..\Run: [Windows Service Agccnt] wanwwsx.exe
O4 - HKCU\..\Run: [MicroSoft sys3s1] h4ckn3t.exe
O4 - HKCU\..\Run: [MicroSoft ssadsadas3s1] eXtream.exe
O4 - HKCU\..\Run: [MicroSoft ssadssjdhasjadas3s1] kdjfsdklfjsl.exe
O4 - HKCU\..\Run: [MicroSoft Getway mqbol] xbvuxowlewiv.exe
O4 - HKCU\..\Run: [MicroSoft ssas3s1] SADASDA.exe
O4 - HKCU\..\Run: [MicroSoft Legal Service] Srb0ty.exe
O4 - HKCU\..\Run: [Windows Secure Update] load.exe
O4 - HKCU\..\Run: [MicroSoft Legal Syst3m32] Syst3m32.exe
O4 - HKCU\..\RunOnce: [Windows Secure Update] load.exe
O4 - HKCU\..\RunOnce: [MicroSoft Legal Syst3m32] Syst3m32.exe
O4 - HKCU\..\RunOnce: [MicroSoft ssas3s1] SADASDA.exe
O4 - HKCU\..\RunOnce: [MicroSoft sys3s1] h4ckn3t.exe
O4 - HKCU\..\RunOnce: [MicroSoft ssadssjdhasjadas3s1] kdjfsdklfjsl.exe
O4 - HKCU\..\RunOnce: [HOT FIX] Gothic.exe
O4 - HKCU\..\RunOnce: [MicroSoft ssadsadas3s1] eXtream.exe
O4 - HKCU\..\RunOnce: [MicroSoft Legal Service] Srb0ty.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MicroSoft ssadssjdhasjadas3s1] kdjfsdklfjsl.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MicroSoft sys3s1] h4ckn3t.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MicroSoft Getway mqbol] qrcffqqysayn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MicroSoft ssas3s1] SADASDA.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Critical Error Safe32] C:\WINDOWS\System32\GetWaylayer32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MicroSoft Legal Service] Srb0ty.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Secure Update] load.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MicroSoft Legal Syst3m32] Syst3m32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MicroSoft Visual Framwork] MS32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [MicroSoft sys3s1] h4ckn3t.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [MicroSoft sys3s1] h4ckn3t.exe (User 'Default user')
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://www.securite.neuf.fr/Ols/fscax.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Microsoft Windows DNS Manager - Unknown owner - C:\WINDOWS\System32\dllcache\windmns.exe
O23 - Service: Microsoft Windows TCP Ack Timing - Unknown owner - C:\WINDOWS\System32\dllcache\wintcpack.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

75 réponses

Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

après le rapport de avast, remets un rapport Hijackthis.

c'est quand même incroyable, tu surfes sur quel type de sites ?
0
scoubidou78
 
bonjour,

je vais dans les sites du genre doctissimo je regarde des films en ligne en streaming...
mon fils va beaucoup dans les sites de jeux ( tfou, habbo,msn,jeux.fr...

mais pas de sites pornos !

que dois je faire sa me soule mon micro recommence a ralentir

dois je les supprimer ou les mettre en quarantaine???

voici le rapport avast

26/12/2007 00:16:57 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\yes.exe\Swfwin32.dll" file.
26/12/2007 00:15:23 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\lovely.sys" file.
26/12/2007 00:15:23 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\repcale.exe\[MoleBox]" file.
26/12/2007 00:15:23 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\repcale.exe\[Embedded#0f338]" file.
26/12/2007 00:15:23 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\kiss.exe" file.
26/12/2007 00:15:23 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\aliases.ini" file.
26/12/2007 00:15:23 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\orrl.exe\[Embedded#13738]" file.
26/12/2007 00:15:23 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\ps2m.exe" file.
26/12/2007 00:15:23 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\repcale.exe" file.
26/12/2007 00:15:21 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\cult.exe\[Embedded#10d38]" file.
26/12/2007 00:15:21 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sxfgfd.exe\hd.exe" file.
26/12/2007 00:15:18 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\lovely.sys" file.
26/12/2007 00:15:18 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\ps2m.exe" file.
26/12/2007 00:15:18 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\repcale.exe\[MoleBox]" file.
26/12/2007 00:15:18 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\repcale.exe" file.
26/12/2007 00:15:18 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\aliases.ini" file.
26/12/2007 00:15:18 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\kiss.exe" file.
26/12/2007 00:15:18 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\orrl.exe\[Embedded#13738]" file.
26/12/2007 00:15:18 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\repcale.exe\[Embedded#0f338]" file.
26/12/2007 00:15:16 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\cult.exe\[Embedded#10d38]" file.
26/12/2007 00:15:16 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\Sx.exe\hd.exe" file.
26/12/2007 00:11:00 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\repcale.exe\[Embedded#0f338]" file.
26/12/2007 00:11:00 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\aliases.ini" file.
26/12/2007 00:11:00 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\repcale.exe\[MoleBox]" file.
26/12/2007 00:11:00 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\repcale.exe" file.
26/12/2007 00:10:59 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\kiss.exe" file.
26/12/2007 00:10:59 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\lovely.sys" file.
26/12/2007 00:10:59 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\orrl.exe\[Embedded#13738]" file.
26/12/2007 00:10:59 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\ps2m.exe" file.
26/12/2007 00:10:58 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\hd.exe" file.
26/12/2007 00:10:57 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\eg.exe\cult.exe\[Embedded#10d38]" file.
26/12/2007 00:10:48 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\murdEr.sys" file.
26/12/2007 00:10:48 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\orrl.exe\[Embedded#13738]" file.
26/12/2007 00:10:48 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\ps2m.exe" file.
26/12/2007 00:10:48 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\repcale.exe\[Embedded#0f338]" file.
26/12/2007 00:10:48 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\repcale.exe" file.
26/12/2007 00:10:48 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\kiss.exe" file.
26/12/2007 00:10:48 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\repcale.exe\[MoleBox]" file.
26/12/2007 00:10:48 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\aliases.ini" file.
26/12/2007 00:10:47 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\hd.exe" file.
26/12/2007 00:10:47 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsgsf.exe\cult.exe\[Embedded#10d38]" file.
26/12/2007 00:10:44 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsfsdfscx.exe\hd.exe" file.
26/12/2007 00:10:44 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsfsdfscx.exe\cult.exe\[Embedded#10d38]" file.
26/12/2007 00:10:41 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\aliases.ini" file.
26/12/2007 00:10:41 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\repcale.exe" file.
26/12/2007 00:10:41 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\repcale.exe\[Embedded#0f338]" file.
26/12/2007 00:10:41 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\repcale.exe\[MoleBox]" file.
26/12/2007 00:10:41 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\ps2m.exe" file.
26/12/2007 00:10:41 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\orrl.exe\[Embedded#13738]" file.
26/12/2007 00:10:40 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\kiss.exe" file.
26/12/2007 00:10:40 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\lovely.sys" file.
26/12/2007 00:10:39 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\hd.exe" file.
26/12/2007 00:10:38 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dsfds.pif\cult.exe\[Embedded#10d38]" file.
26/12/2007 00:08:16 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\kiss.exe" file.
26/12/2007 00:08:16 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\murdEr.sys" file.
26/12/2007 00:08:15 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\hd.exe" file.
26/12/2007 00:08:14 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\repcale.exe" file.
26/12/2007 00:08:14 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\aliases.ini" file.
26/12/2007 00:08:14 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\cult.exe\[Embedded#10d38]" file.
26/12/2007 00:08:14 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\repcale.exe\[MoleBox]" file.
26/12/2007 00:08:14 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\orrl.exe\[Embedded#13738]" file.
26/12/2007 00:08:14 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\ps2m.exe" file.
26/12/2007 00:08:14 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfs.exe\repcale.exe\[Embedded#0f338]" file.
26/12/2007 00:08:10 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\kiss.exe" file.
26/12/2007 00:08:10 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\murdEr.sys" file.
26/12/2007 00:08:09 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\repcale.exe\[MoleBox]" file.
26/12/2007 00:08:09 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\ps2m.exe" file.
26/12/2007 00:08:09 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\repcale.exe" file.
26/12/2007 00:08:09 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\hd.exe" file.
26/12/2007 00:08:09 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\aliases.ini" file.
26/12/2007 00:08:09 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\repcale.exe\[Embedded#0f338]" file.
26/12/2007 00:08:09 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\cult.exe\[Embedded#10d38]" file.
26/12/2007 00:08:08 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe\orrl.exe\[Embedded#13738]" file.
26/12/2007 00:08:02 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\darkworlk.exe\d4rky.exe" file.
26/12/2007 00:08:02 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\darkworlk.exe\d4rky[x]" file.
26/12/2007 00:08:02 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\darkworlk.exe\d4rky[2]" file.
26/12/2007 00:08:02 Propriétaire 3000 Sign of "Win32:Parite" has been found in "C:\WINDOWS\SYSTEM32\darkworlk.exe\d4rk.exe" file.
26/12/2007 00:08:02 Propriétaire 3000 Sign of "IRC:LowJones [Trj]" has been found in "C:\WINDOWS\SYSTEM32\darkworlk.exe\d4rky[6]" file.
26/12/2007 00:07:54 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\d4rk.exe" file.
26/12/2007 00:01:12 Propriétaire 3000 Sign of "Win32:Parite" has been found in "C:\WINDOWS\SYSTEM32\antivirusv1.exe\d4rk.exe" file.
26/12/2007 00:01:12 Propriétaire 3000 Sign of "IRC:LowJones [Trj]" has been found in "C:\WINDOWS\SYSTEM32\antivirusv1.exe\d4rky[6]" file.
26/12/2007 00:01:12 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\antivirusv1.exe\d4rky[2]" file.
26/12/2007 00:01:12 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\antivirusv1.exe\d4rky.exe" file.
26/12/2007 00:01:12 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\WINDOWS\SYSTEM32\antivirusv1.exe\d4rky[x]" file.
26/12/2007 00:00:57 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\-r" file.
26/12/2007 00:00:56 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\-r\th7ya.exe" file.
25/12/2007 22:41:26 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe\virgin.exe" file.
25/12/2007 22:41:25 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe\ps2m.exe" file.
25/12/2007 22:41:25 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:41:24 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:41:24 Propriétaire 3000 Sign of "Win32:Trojan-gen {UPX}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe\ms04.exe" file.
25/12/2007 22:41:24 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe\nass3r.exe" file.
25/12/2007 22:41:23 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006394.exe" file.
25/12/2007 22:41:23 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006395.exe\[Embedded#13738]" file.
25/12/2007 22:41:23 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006393.exe\[Embedded#10d38]" file.
25/12/2007 22:41:19 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006392.exe\Swfwin32.dll" file.
25/12/2007 22:41:17 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006391.exe\jinso.exe" file.
25/12/2007 22:41:14 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006390.exe\jinso.exe" file.
25/12/2007 22:41:11 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006389.pif\th7yax.exe" file.
25/12/2007 22:41:06 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\kiss.exe" file.
25/12/2007 22:41:06 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\aliases.ini" file.
25/12/2007 22:41:06 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\repcale.exe" file.
25/12/2007 22:41:06 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\repcale.exe\[Embedded#0f338]" file.
25/12/2007 22:41:06 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\repcale.exe\[MoleBox]" file.
25/12/2007 22:41:06 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\ps2m.exe" file.
25/12/2007 22:41:06 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:41:06 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\lovely.sys" file.
25/12/2007 22:41:05 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\hd.exe" file.
25/12/2007 22:41:05 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:41:02 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\repcale.exe\[Embedded#0f338]" file.
25/12/2007 22:41:02 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\repcale.exe" file.
25/12/2007 22:41:02 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\aliases.ini" file.
25/12/2007 22:41:02 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\repcale.exe\[MoleBox]" file.
25/12/2007 22:41:01 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\ps2m.exe" file.
25/12/2007 22:41:01 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:41:01 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\lovely.sys" file.
25/12/2007 22:41:01 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\kiss.exe" file.
25/12/2007 22:41:00 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\hd.exe" file.
25/12/2007 22:41:00 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:40:59 Propriétaire 3000 Sign of "Win32:Rbot-FGP [Trj]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006385.exe" file.
25/12/2007 22:40:59 Propriétaire 3000 Sign of "IRC:Flood-B [Trj]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006386.exe\nick.txt" file.
25/12/2007 22:40:58 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006382.dll" file.
25/12/2007 22:40:53 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\ms02.exe" file.
25/12/2007 22:40:53 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:40:53 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\ps2m.exe" file.
25/12/2007 22:40:53 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\repcale.exe\[MoleBox]" file.
25/12/2007 22:40:53 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\repcale.exe\[Embedded#0f338]" file.
25/12/2007 22:40:53 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\repcale.exe" file.
25/12/2007 22:40:52 Propriétaire 3000 Sign of "Win32:Trojan-gen {UPX}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\F1NTXXXK.exe" file.
25/12/2007 22:40:52 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:40:52 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\hd.exe" file.
25/12/2007 22:40:52 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\lovelyx.sys" file.
25/12/2007 22:40:51 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe\aliases.ini" file.
25/12/2007 22:40:50 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006380.exe\kiss.exe" file.
25/12/2007 22:40:49 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006380.exe\hd.exe" file.
25/12/2007 22:40:49 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006380.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:40:48 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006380.exe\aliases.ini" file.
25/12/2007 22:40:44 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\repcale.exe\[MoleBox]" file.
25/12/2007 22:40:44 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\q8guys.exe" file.
25/12/2007 22:40:44 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\repcale.exe\[Embedded#0f338]" file.
25/12/2007 22:40:44 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\repcale.exe" file.
25/12/2007 22:40:43 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\ps2m.exe" file.
25/12/2007 22:40:42 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:40:42 Propriétaire 3000 Sign of "Win32:Trojan-gen {UPX}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\ms04.exe" file.
25/12/2007 22:40:42 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\lovelyx.sys" file.
25/12/2007 22:40:42 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\hd.exe" file.
25/12/2007 22:40:42 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:40:42 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe\aliases.ini" file.
25/12/2007 22:40:39 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\ps2m.exe" file.
25/12/2007 22:40:39 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:40:39 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\repcale.exe\[MoleBox]" file.
25/12/2007 22:40:39 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\repcale.exe\[Embedded#0f338]" file.
25/12/2007 22:40:39 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\repcale.exe" file.
25/12/2007 22:40:39 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\kiss.exe" file.
25/12/2007 22:40:39 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\lovely.sys" file.
25/12/2007 22:40:37 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\aliases.ini" file.
25/12/2007 22:40:37 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:40:37 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif\hd.exe" file.
25/12/2007 22:40:34 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\repcale.exe" file.
25/12/2007 22:40:34 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\repcale.exe\[Embedded#0f338]" file.
25/12/2007 22:40:33 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:40:33 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\ps2m.exe" file.
25/12/2007 22:40:33 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\repcale.exe\[MoleBox]" file.
25/12/2007 22:40:33 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\lovely.sys" file.
25/12/2007 22:40:33 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\kiss.exe" file.
25/12/2007 22:40:31 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\aliases.ini" file.
25/12/2007 22:40:31 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:40:31 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe\hd.exe" file.
25/12/2007 22:40:28 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\lovely.sys" file.
25/12/2007 22:40:28 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\kiss.exe" file.
25/12/2007 22:40:28 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\ps2m.exe" file.
25/12/2007 22:40:28 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\repcale.exe\[Embedded#0f338]" file.
25/12/2007 22:40:28 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\repcale.exe" file.
25/12/2007 22:40:28 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\repcale.exe\[MoleBox]" file.
25/12/2007 22:40:28 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:40:26 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\aliases.ini" file.
25/12/2007 22:40:26 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:40:26 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe\hd.exe" file.
25/12/2007 22:40:22 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006375.ini" file.
25/12/2007 22:10:52 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\sdsdfsdf.exe\virgin.exe" file.
25/12/2007 22:10:50 Propriétaire 3000 Sign of "Win32:Trojan-gen {UPX}" has been found in "C:\sdsdfsdf.exe\ms04.exe" file.
25/12/2007 22:10:50 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\sdsdfsdf.exe\nass3r.exe" file.
25/12/2007 22:10:50 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\sdsdfsdf.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:10:50 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\sdsdfsdf.exe\ps2m.exe" file.
25/12/2007 22:10:49 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\sdsdfsdf.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 22:00:04 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\killSh\orrl.exe\[Embedded#13738]" file.
25/12/2007 22:00:04 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\killSh\hd.exe" file.
25/12/2007 21:59:58 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\killSh\cult.exe\[Embedded#10d38]" file.
25/12/2007 21:50:32 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\lol1.exe\Swfwin32.dll" file.
25/12/2007 21:50:30 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\klertf.exe\jinso.exe" file.
25/12/2007 21:22:03 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\hjuing.exe\jinso.exe" file.
25/12/2007 21:21:59 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\hidfdfdffdz.pif\th7yax.exe" file.
25/12/2007 21:21:54 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\gezzxa.exe\ps2m.exe" file.
25/12/2007 21:21:54 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gezzxa.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 21:21:54 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\gezzxa.exe\lovely.sys" file.
25/12/2007 21:21:54 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\gezzxa.exe\aliases.ini" file.
25/12/2007 21:21:54 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\gezzxa.exe\repcale.exe" file.
25/12/2007 21:21:54 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gezzxa.exe\repcale.exe\[Embedded#0f338]" file.
25/12/2007 21:21:54 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\gezzxa.exe\repcale.exe\[MoleBox]" file.
25/12/2007 21:21:53 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gezzxa.exe\kiss.exe" file.
25/12/2007 21:21:52 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gezzxa.exe\hd.exe" file.
25/12/2007 21:21:52 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gezzxa.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 21:21:49 Propriétaire 3000 Sign of "Win32:Generic-V [Wrm]" has been found in "C:\gexa.exe\aliases.ini" file.
25/12/2007 21:21:49 Propriétaire 3000 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\gexa.exe\ps2m.exe" file.
25/12/2007 21:21:49 Propriétaire 3000 Sign of "Win32:HideWindows-B [Tool]" has been found in "C:\gexa.exe\repcale.exe\[MoleBox]" file.
25/12/2007 21:21:49 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gexa.exe\repcale.exe\[Embedded#0f338]" file.
25/12/2007 21:21:49 Propriétaire 3000 Sign of "Win32:HideWindows-I [Tool]" has been found in "C:\gexa.exe\repcale.exe" file.
25/12/2007 21:21:48 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gexa.exe\kiss.exe" file.
25/12/2007 21:21:48 Propriétaire 3000 Sign of "Win32:Generic-W [Wrm]" has been found in "C:\gexa.exe\lovely.sys" file.
25/12/2007 21:21:48 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gexa.exe\orrl.exe\[Embedded#13738]" file.
25/12/2007 21:21:47 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gexa.exe\hd.exe" file.
25/12/2007 21:21:46 Propriétaire 3000 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\gexa.exe\cult.exe\[Embedded#10d38]" file.
25/12/2007 21:21:06 Propriétaire 3000 Sign of "IRC:Flood-B [Trj]" has been found in "C:\essd.exe\nick.txt" file.
0
scoubidou78
 
et ossi le rapport hijackthis

tu as vu au dessu mon rapport avast???

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:44:46, on 29/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\pctspk.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Live\Contrôle parental\fssui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr3.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr3.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr3.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr3.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr3.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Contrôle parental\fssui.exe" -autorun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

oui, j'ai vu. On va voir si un autre AV confirme.

Scanne ensuite ton PC avec BitDefender en ligne (uniquement sous Internet Explorer).

ouvre ce lien :

www.bitdefender.com/scan8/ie.html

Utilisation :
Cliquer sur "J'accepte" puis accepter également l'ActiveX bloqué par la barre anti-popup du SP2 qui clignotera en haut et l'installer.
Ensuite, cliquer sur "Cliquez ici pour scanner".
Patienter jusqu'à la fin du scan qui peut durer assez longtemps...

Copier/coller le rapport entier sur le forum.

Tutoriel en images ici : http://pageperso.aol.fr/rginformatique/mapage/defender.htm (merci à Balltrap34 pour cette réalisation)

Ensuite, il faut que tu surfes avec Firefox et non IE, sauf pour les MAJ de Windows.

Ouvre ce lien pour télécharger le logiciel.

http://www.commentcamarche.net/telecharger/logiciels firefox?search2_x=16&search2_y=13
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
scoubidou78
 
ok,

j ai dja firefoxgoogle je crois

je telecharge quand meme?

o faite sa sert a quoi firefox???

desole je m y connais pas du tout.

merci
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Re,

fais les choses dans l'ordre demandé.

Scan puis téléchargement.
0
scoubidou78
 
re,

ok je t envoie le scan a toute
0
scoubidou78
 
re,

BitDefender Online Scanner

Scan report generated at: Sun, Dec 30, 2007 - 19:48:23

Scan path: A:\;C:\;D:\;

Statistics

Time
10:07:49

Files
169354

Folders
4277

Boot Sectors
3

Archives
15974

Packed Files
9834

Results

Identified Viruses
19

Infected Files
160

Suspect Files
0

Warnings
0

Disinfected
2

Deleted Files
158

Engines Info

Virus Definitions
884755

Engine build
AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

Scan plugins
14

Archive plugins
38

Unpack plugins
7

E-mail plugins
6

System plugins
1

Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions

Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes

Scanned File
Status

C:\esd.exe=>(ZIP Sfx o)=>Mirc.ini
Infected with: Backdoor.Zapchast.F

C:\esd.exe=>(ZIP Sfx o)=>Mirc.ini
Disinfection failed

C:\esd.exe=>(ZIP Sfx o)=>Mirc.ini
Deleted

C:\esd.exe=>(ZIP Sfx o)
Updated

C:\esd.exe
Update failed

C:\essd.exe=>(ZIP Sfx o)=>Mirc.ini
Infected with: Backdoor.Zapchast.F

C:\essd.exe=>(ZIP Sfx o)=>Mirc.ini
Disinfection failed

C:\essd.exe=>(ZIP Sfx o)=>Mirc.ini
Deleted

C:\essd.exe=>(ZIP Sfx o)
Updated

C:\essd.exe
Update failed

C:\gexa.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\gexa.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\gexa.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\gexa.exe=>(RAR Sfx o)
Update failed

C:\gexa.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\gexa.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\gexa.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\gexa.exe=>(RAR Sfx o)
Update failed

C:\gezzxa.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\gezzxa.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\gezzxa.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\gezzxa.exe=>(RAR Sfx o)
Update failed

C:\gezzxa.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\gezzxa.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\gezzxa.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\gezzxa.exe=>(RAR Sfx o)
Update failed

C:\hp\bin\ProcessLogger.exe
Infected with: DeepScan:Generic.Malware.P!.5F1AEB08

C:\hp\bin\ProcessLogger.exe
Disinfection failed

C:\hp\bin\ProcessLogger.exe
Deleted

C:\lol1.exe=>(RAR Sfx o)=>window.com
Infected with: Backdoor.Mirc.580999.A

C:\lol1.exe=>(RAR Sfx o)=>window.com
Disinfection failed

C:\lol1.exe=>(RAR Sfx o)=>window.com
Deleted

C:\lol1.exe=>(RAR Sfx o)
Update failed

C:\Program Files\killSh\cult.exe
Infected with: Win32.Worm.Rbot.AA

C:\Program Files\killSh\cult.exe
Disinfection failed

C:\Program Files\killSh\cult.exe
Deleted

C:\Program Files\killSh\hd.exe
Detected with: Application.HideWindow.B

C:\Program Files\killSh\hd.exe
Disinfection failed

C:\Program Files\killSh\hd.exe
Deleted

C:\Program Files\killSh\orrl.exe
Infected with: Win32.Worm.Rbot.AY

C:\Program Files\killSh\orrl.exe
Disinfection failed

C:\Program Files\killSh\orrl.exe
Deleted

C:\Program Files\killSh\pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\Program Files\killSh\pingy.exe
Disinfection failed

C:\Program Files\killSh\pingy.exe
Deleted

C:\sdsdfsdf.exe=>(CAB Sfx o)=>l.o.v.e.l.y.x
Infected with: Backdoor.Ircflood.B

C:\sdsdfsdf.exe=>(CAB Sfx o)=>l.o.v.e.l.y.x
Disinfection failed

C:\sdsdfsdf.exe=>(CAB Sfx o)=>l.o.v.e.l.y.x
Deleted

C:\sdsdfsdf.exe=>(CAB Sfx o)
Update failed

C:\sdsdfsdf.exe=>(CAB Sfx o)=>lovely.dll
Infected with: Trojan.Generic.52576

C:\sdsdfsdf.exe=>(CAB Sfx o)=>lovely.dll
Disinfection failed

C:\sdsdfsdf.exe=>(CAB Sfx o)=>lovely.dll
Deleted

C:\sdsdfsdf.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006375.ini
Infected with: Backdoor.IRC.Zapchast.JG

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006375.ini
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006375.ini
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe=>(CAB Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe=>(CAB Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe=>(CAB Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006379.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe=>(CAB Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe=>(CAB Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe=>(CAB Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006381.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006386.exe=>(ZIP Sfx o)=>Mirc.ini
Infected with: Backdoor.Zapchast.F

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006386.exe=>(ZIP Sfx o)=>Mirc.ini
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006386.exe=>(ZIP Sfx o)=>Mirc.ini
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006386.exe=>(ZIP Sfx o)
Updated

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006386.exe
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006392.exe=>(RAR Sfx o)=>window.com
Infected with: Backdoor.Mirc.580999.A

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006392.exe=>(RAR Sfx o)=>window.com
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006392.exe=>(RAR Sfx o)=>window.com
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006392.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006393.exe
Infected with: Win32.Worm.Rbot.AA

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006393.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006393.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006394.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006394.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006394.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006395.exe
Infected with: Win32.Worm.Rbot.AY

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006395.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006395.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe=>(CAB Sfx o)=>l.o.v.e.l.y.x
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe=>(CAB Sfx o)=>l.o.v.e.l.y.x
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe=>(CAB Sfx o)=>l.o.v.e.l.y.x
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe=>(CAB Sfx o)=>lovely.dll
Infected with: Trojan.Generic.52576

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe=>(CAB Sfx o)=>lovely.dll
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe=>(CAB Sfx o)=>lovely.dll
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006396.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rk.exe
Infected with: Win32.Parite.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rk.exe
Disinfected

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[2]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[2]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[2]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[3]
Infected with: Win32.IRC.Kelebek

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[3]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[3]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[4]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[4]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[4]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[5]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[5]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[5]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[6]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[6]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[6]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[7]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[7]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)=>d4rky[7]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006397.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rk.exe
Infected with: Win32.Parite.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rk.exe
Disinfected

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[2]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[2]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[2]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[3]
Infected with: Win32.IRC.Kelebek

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[3]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[3]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[4]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[4]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[4]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[5]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[5]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[5]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[6]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[6]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[6]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[7]
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[7]
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)=>d4rky[7]
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006399.exe=>(CAB Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>orrl.exe
Infected with: Win32.Worm.Rbot.AY

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>orrl.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>orrl.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>ps2m.exe
Detected with: Application.Passview.A

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>ps2m.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>ps2m.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>repcale.exe
Infected with: GenPack:Virtool.HiddenRun.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>repcale.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>repcale.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>aliases.ini
Infected with: Backdoor.IRC.Zapchast.JG

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>aliases.ini
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>aliases.ini
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>cult.exe
Infected with: Win32.Worm.Rbot.AA

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>cult.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>cult.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>hd.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>hd.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>hd.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>kiss.exe
Infected with: Win32.IRC.Kelebek

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>kiss.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>kiss.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>murdEr.sys
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>murdEr.sys
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)=>murdEr.sys
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006400.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>orrl.exe
Infected with: Win32.Worm.Rbot.AY

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>orrl.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>orrl.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>ps2m.exe
Detected with: Application.Passview.A

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>ps2m.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>ps2m.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>repcale.exe
Infected with: GenPack:Virtool.HiddenRun.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>repcale.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>repcale.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>aliases.ini
Infected with: Backdoor.IRC.Zapchast.JG

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>aliases.ini
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>aliases.ini
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>cult.exe
Infected with: Win32.Worm.Rbot.AA

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>cult.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>cult.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>hd.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>hd.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>hd.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>kiss.exe
Infected with: Win32.IRC.Kelebek

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>kiss.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>kiss.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>murdEr.sys
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>murdEr.sys
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)=>murdEr.sys
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006401.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>cult.exe
Infected with: Win32.Worm.Rbot.AA

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>cult.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>cult.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>hd.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>hd.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>hd.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>kiss.exe
Infected with: Win32.IRC.Kelebek

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>kiss.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>kiss.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>lovely.sys
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>lovely.sys
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>lovely.sys
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>orrl.exe
Infected with: Win32.Worm.Rbot.AY

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>orrl.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>orrl.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>ps2m.exe
Detected with: Application.Passview.A

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>ps2m.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>ps2m.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>repcale.exe
Infected with: GenPack:Virtool.HiddenRun.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>repcale.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>repcale.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>aliases.ini
Infected with: Backdoor.IRC.Zapchast.JG

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>aliases.ini
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)=>aliases.ini
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006402.pif=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006403.exe=>(RAR Sfx o)=>cult.exe
Infected with: Win32.Worm.Rbot.AA

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006403.exe=>(RAR Sfx o)=>cult.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006403.exe=>(RAR Sfx o)=>cult.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006403.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006403.exe=>(RAR Sfx o)=>hd.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006403.exe=>(RAR Sfx o)=>hd.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006403.exe=>(RAR Sfx o)=>hd.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006403.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>cult.exe
Infected with: Win32.Worm.Rbot.AA

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>cult.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>cult.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>hd.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>hd.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>hd.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>kiss.exe
Infected with: Win32.IRC.Kelebek

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>kiss.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>kiss.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>murdEr.sys
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>murdEr.sys
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>murdEr.sys
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>orrl.exe
Infected with: Win32.Worm.Rbot.AY

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>orrl.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>orrl.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>ps2m.exe
Detected with: Application.Passview.A

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>ps2m.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>ps2m.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>repcale.exe
Infected with: GenPack:Virtool.HiddenRun.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>repcale.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>repcale.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>aliases.ini
Infected with: Backdoor.IRC.Zapchast.JG

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>aliases.ini
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)=>aliases.ini
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006404.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>cult.exe
Infected with: Win32.Worm.Rbot.AA

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>cult.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>cult.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>hd.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>hd.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>hd.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>kiss.exe
Infected with: Win32.IRC.Kelebek

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>kiss.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>kiss.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>lovely.sys
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>lovely.sys
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>lovely.sys
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>orrl.exe
Infected with: Win32.Worm.Rbot.AY

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>orrl.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>orrl.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>ps2m.exe
Detected with: Application.Passview.A

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>ps2m.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>ps2m.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>repcale.exe
Infected with: GenPack:Virtool.HiddenRun.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>repcale.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>repcale.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>aliases.ini
Infected with: Backdoor.IRC.Zapchast.JG

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>aliases.ini
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)=>aliases.ini
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006405.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>cult.exe
Infected with: Win32.Worm.Rbot.AA

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>cult.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>cult.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>hd.exe
Detected with: Application.HideWindow.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>hd.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>hd.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>kiss.exe
Infected with: Win32.IRC.Kelebek

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>kiss.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>kiss.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>ksat.bat
Infected with: Trojan.IRC.Gen

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>ksat.bat
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>ksat.bat
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>lovely.sys
Infected with: Backdoor.Ircflood.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>lovely.sys
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>lovely.sys
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>orrl.exe
Infected with: Win32.Worm.Rbot.AY

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>orrl.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>orrl.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>pingy.exe
Infected with: Trojan.Downloader.Small.ZJ

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>pingy.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>pingy.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>ps2m.exe
Detected with: Application.Passview.A

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>ps2m.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>ps2m.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)
Update failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>repcale.exe
Infected with: GenPack:Virtool.HiddenRun.B

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>repcale.exe
Disinfection failed

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006406.exe=>(RAR Sfx o)=>repcale.exe
Deleted

C:\System Volume Information\_restore{845A621C-47AF-4FF
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

C:\esd.exe
C:\essd.exe
C:\gexa.exe
C:\gezzxa.exe
C:\lol1.exe
C:\sdsdfsdf.exe

clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

Si OTMoveIt ne l'a pas demandé, redémarre l'ordi ;

remets un rapport HIJACKTHIS;
0
scoubidou78
 
bonjour

voici le rapport otmoveit

C:\esd.exe moved successfully.
C:\essd.exe moved successfully.
C:\gexa.exe moved successfully.
C:\gezzxa.exe moved successfully.
C:\lol1.exe moved successfully.
C:\sdsdfsdf.exe moved successfully.

Created on 12/31/2007 09:31:29

je tenvoie un hijacthis de suite

a +
0
scoubidou78
 
as tu vu le rapport otmoveit juste au dessus?

voici maintenant hijacthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:46:14, on 31/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\pctspk.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Live\Contrôle parental\fssui.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr3.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr3.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr3.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr3.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr3.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Contrôle parental\fssui.exe" -autorun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

coté rapport Hijackthis, ça va bien, un ou 2 truc mineurs

Je te conseillerai 'éliminer BackWeb-137903.exe :

"With the My HP Center, consumers have access directly from the desktop to Internet sites featuring special offers for HP customers ranging from personal finance and shopping to digital imaging and music"

Avec My HP Center, les consommateurs ont accès depuis le Bureau à des sites Internet proposant des ofrres spéciales aux propriétaires d'un HP, allant de la gestion financière à la musique et dessin (traduction libre)

Fais un scan minutieux avec avast de ton Poste d etarvail ainsi qu'un scan aavec AVG AS.

Poste les 2 rapports.
0
scoubidou78
 
je vais faire le scan avast avg

mais comment 'éliminer BackWeb-137903.exe ?

MERCI
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Re,

fais les 2 scans, poste les rapports.

Pour backweb, je te dirai comment faire. Je voulais juste avoir ton accord.
0
scoubidou78
 
bonjour et bonne annee,

VG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 13:28:04 31/12/2007

+ Résultat de l'analyse:

C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006385.exe -> Backdoor.Rbot.eix : Nettoyé.
C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006383.exe -> Backdoor.Rbot.esx : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@bluestreak[2].txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006382.dll -> Trojan.Flood : Nettoyé.
C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006376.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006377.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006378.pif/ksat.bat -> Trojan.Small : Nettoyé.
C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006387.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006388.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\WINDOWS\SYSTEM32\Sx.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\WINDOWS\SYSTEM32\Sxfgfd.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\WINDOWS\SYSTEM32\dfgsdfcxvxs.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\WINDOWS\SYSTEM32\dfgsdfs.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\WINDOWS\SYSTEM32\dsfds.pif/ksat.bat -> Trojan.Small : Nettoyé.
C:\WINDOWS\SYSTEM32\dsgsf.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\WINDOWS\SYSTEM32\eg.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\_OTMoveIt\MovedFiles\gexa.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\_OTMoveIt\MovedFiles\gezzxa.exe/ksat.bat -> Trojan.Small : Nettoyé.
C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP41\A0006384.bat -> Trojan.Starter.o : Nettoyé.

Fin du rapport
0