Win 32 et autres soucis je crois...
koolas
-
noctambule28 Messages postés 33382 Date d'inscription Statut Webmaster Dernière intervention -
noctambule28 Messages postés 33382 Date d'inscription Statut Webmaster Dernière intervention -
bonjour à tous!
Je suis désespérée depuis quelques jour avec mon ordinateur qui a l'air tres malade en ce moment...
tout a commencé il y a à peu pres 1semaine. Les ordinateurs des mon ecole avaient tous un virus "win32 autorun"; et je n'ai pas été vigilante car je l'ai eu chez moi à mon tour. J'ai suivit quelques manip' decrites sur un forum, que je n'aurais peut etre pas du faire car il fallait toucher au systeme, et je ne suis pas du tout familiere avec tous ca, alors j'ai peur d'avoir fait des betises. Bon j'ai finit par appliquer un patch que j'ai trouvé sur ce ce forum,qui ma permis de retrouver l'acces des mes differents disques, donc j'ai juste fait un scan avec avast et j'ai laissé. Mais voila depuis quelques jour je n'arrive plus à etteindre mon ordinateur, avast ouvre une fenetre en disant qu'il ne peut pas eteindre parcequ'il y a un cd dans le lecteur ( mais il yen a pas..) et je suis obligée d'eteindre manuellement ( c po bien). Et plus chiant encore, mes fenetres( ma souris plutôt) se met à bouger( trembler) et rendre quasi impossible ma navigation ( de temps en temps mais de plus en plus frequemment)
Je ne sais pas quoi faire, jai telechargé hitman pro, mais il s'arrete au bout de 5min en affichant un message d'erreur ( probleme de memoire?)
Si quelqu'un pourrait me donner quelques pistes sa serait vraiment cool, j'ai un memoire à rendre dans quelques jours et j'ai peur que mon pc me plante!!!
merci d'avance
( ps: jai relancé un scan ce soir avec avast : il a detecté 2 virus : win32 mailskinner etWin32:Agent-ROU )
Je suis désespérée depuis quelques jour avec mon ordinateur qui a l'air tres malade en ce moment...
tout a commencé il y a à peu pres 1semaine. Les ordinateurs des mon ecole avaient tous un virus "win32 autorun"; et je n'ai pas été vigilante car je l'ai eu chez moi à mon tour. J'ai suivit quelques manip' decrites sur un forum, que je n'aurais peut etre pas du faire car il fallait toucher au systeme, et je ne suis pas du tout familiere avec tous ca, alors j'ai peur d'avoir fait des betises. Bon j'ai finit par appliquer un patch que j'ai trouvé sur ce ce forum,qui ma permis de retrouver l'acces des mes differents disques, donc j'ai juste fait un scan avec avast et j'ai laissé. Mais voila depuis quelques jour je n'arrive plus à etteindre mon ordinateur, avast ouvre une fenetre en disant qu'il ne peut pas eteindre parcequ'il y a un cd dans le lecteur ( mais il yen a pas..) et je suis obligée d'eteindre manuellement ( c po bien). Et plus chiant encore, mes fenetres( ma souris plutôt) se met à bouger( trembler) et rendre quasi impossible ma navigation ( de temps en temps mais de plus en plus frequemment)
Je ne sais pas quoi faire, jai telechargé hitman pro, mais il s'arrete au bout de 5min en affichant un message d'erreur ( probleme de memoire?)
Si quelqu'un pourrait me donner quelques pistes sa serait vraiment cool, j'ai un memoire à rendre dans quelques jours et j'ai peur que mon pc me plante!!!
merci d'avance
( ps: jai relancé un scan ce soir avec avast : il a detecté 2 virus : win32 mailskinner etWin32:Agent-ROU )
A voir également:
- Win 32 et autres soucis je crois...
- 32 bits - Guide
- Power iso 32 bit - Télécharger - Gravure
- Win rar - Télécharger - Compression & Décompression
- Télécharger windows 7 32 bits usb - Télécharger - Systèmes d'exploitation
- Clé de produit windows 7 professionnel 32 bits gratuit - Guide
52 réponses
salut
pour commencer
Clique sur ce lien
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
pour télécharger le fichier d'installation d'HijackThis.
Enregistre HJTInstall.exe sur ton bureau.
Double-clique sur HJTInstall.exe pour lancer le programme
Par défaut, il s'installera là :
C:\Program Files\Trend Micro\HijackThis
Accepte la license en cliquant sur le bouton "I Accept"
Choisis l'option "Do a system scan and save a log file"
Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
Colle le rapport que tu viens de copier sur ce forum
Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement
Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm
a+
pour commencer
Clique sur ce lien
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
pour télécharger le fichier d'installation d'HijackThis.
Enregistre HJTInstall.exe sur ton bureau.
Double-clique sur HJTInstall.exe pour lancer le programme
Par défaut, il s'installera là :
C:\Program Files\Trend Micro\HijackThis
Accepte la license en cliquant sur le bouton "I Accept"
Choisis l'option "Do a system scan and save a log file"
Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
Colle le rapport que tu viens de copier sur ce forum
Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement
Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm
a+
alors voila le rapport, mais fixer des lignes sa veut dire quoi? ( j'ai rien fait...)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:47:08, on 06/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Conversions Plus\FORMATM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Conversions Plus\MacName.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://fwalerts.zonelabs.com/fwanalyze.jsp?record=ZLN00550166299650-1025/40f3ca7016f3673528f0017d5&tab=overview
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\Conversions Plus\MacLic.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [McaFee virus detect program.] c:\Program Files\Network Associates\VirusScan\McaUpdate.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart17.exe
O4 - Global Startup: MacName.lnk = C:\Program Files\Conversions Plus\MacName.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%20Files/AutoCAD%202002/AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/AutoCAD%202002/InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file:///C:/Program%20Files/AutoCAD%202002/InstFred.ocx
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photoways.com/clients/uploader_v2.2.0.6.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%20Files/AutoCAD%202002/AcPreview.ocx
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MacFormatService - DataViz Inc. - C:\Program Files\Conversions Plus\FORMATM.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Qisqmxyaacf - Sonic Solutions - (no file)
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:47:08, on 06/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Conversions Plus\FORMATM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Conversions Plus\MacName.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://fwalerts.zonelabs.com/fwanalyze.jsp?record=ZLN00550166299650-1025/40f3ca7016f3673528f0017d5&tab=overview
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\Conversions Plus\MacLic.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [McaFee virus detect program.] c:\Program Files\Network Associates\VirusScan\McaUpdate.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart17.exe
O4 - Global Startup: MacName.lnk = C:\Program Files\Conversions Plus\MacName.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%20Files/AutoCAD%202002/AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/AutoCAD%202002/InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file:///C:/Program%20Files/AutoCAD%202002/InstFred.ocx
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photoways.com/clients/uploader_v2.2.0.6.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%20Files/AutoCAD%202002/AcPreview.ocx
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MacFormatService - DataViz Inc. - C:\Program Files\Conversions Plus\FORMATM.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Qisqmxyaacf - Sonic Solutions - (no file)
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
PPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFppppppppppppppppppppppppppppppppppppppppppfffffffffffffffffffffffffffffffffffffffff ben té pas dans la merde toi !!
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
merci......... je crois que je l'avais remarqué... mais la tu me fais peur... il y a une solution pour moi ? peux tu me dire ce qu'il se passe steplé?
tu n'a pas de pare feu, il faut en mettre un, et je te conseillerais antivir plutot que avast
antivir plutot que avast, en anglais mais tres simple
AntiVir
AntiVir
un tuto
https://www.malekal.com/avira-free-security-antivirus-gratuit/
--------------
installes un pare feu, celui de windows n'est pas suffisant
ZoneAlarm
http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm
un tuto pour le configurer
https://www.pcastuces.com/pratique/securite/firewall2/firewall.htm
ou
Kerio
http://www.commentcamarche.net/telecharger/telecharger 206 kerio
plus leger que zone alarm
un tuto
http://www.malekal.com/kerio_firewall.php
--------------------------------------
de plus il te reste des trace de Mcaffe, donc pour le desintaller proprement
regarde ce qui est ici
http://www.commentcamarche.net/forum/affich 4729260 comment desinstaller proprement mcafee#3
--------------------------------
une fois tout cela fait, et apres seulement
relance hijackthis
fait "do system scan only"
coche devant ces lignes et clic sur fix checked
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
---------------------
Télécharge BTFix 1.017 (de bibi26)
http://cluster1.easy-hebergement.net/
* Décompresse l'archive sur ton Bureau
* Ouvre le dossier BTFix
* Double clique sur BTFix.exe
* Clique sur Rechercher
* Un rapport va apparaître, copie/colle-le dans ta prochaine réponse
Si tu vois une infection tu continues( là......)
Démarrer en Mode sans échec. Attention, tu n'as pas accès à Internet dans ce mode, note bien ce que tu as à faire.
(Pour cela : démarrer le PC en tapotant sur la touche F8 du clavier jusqu'à ce que le menu des options avancées de Windows apparaisse puis avec les touches fléchées du clavier, sélectionner Mode sans échec puis appuyer sur la touche Entrée...)
Attention tu n'as pas accès à Internet dans ce mode donc note ou imprime les consignes qui suivent.
* Démarre l'ordinateur.
* Une fois le chargement du BIOS terminé, il y a un écran noir.
* Appuie sur la touche F8 ou F5, à répétition jusqu'à l'affichage du menu des options avancées de Windows.
* En utilisant les touches du curseur, sélectionne le mode sans échec approprié et appuie sur Entrée.
* Choisis ton compte usuel et non Administrateur.
* Ouvre BTFix
* Clique sur "Nettoyer"
* Un rapport va apparaître, copie/colle-le dans ta prochaine réponse
et un nouvel hijackthis
antivir plutot que avast, en anglais mais tres simple
AntiVir
AntiVir
un tuto
https://www.malekal.com/avira-free-security-antivirus-gratuit/
--------------
installes un pare feu, celui de windows n'est pas suffisant
ZoneAlarm
http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm
un tuto pour le configurer
https://www.pcastuces.com/pratique/securite/firewall2/firewall.htm
ou
Kerio
http://www.commentcamarche.net/telecharger/telecharger 206 kerio
plus leger que zone alarm
un tuto
http://www.malekal.com/kerio_firewall.php
--------------------------------------
de plus il te reste des trace de Mcaffe, donc pour le desintaller proprement
regarde ce qui est ici
http://www.commentcamarche.net/forum/affich 4729260 comment desinstaller proprement mcafee#3
--------------------------------
une fois tout cela fait, et apres seulement
relance hijackthis
fait "do system scan only"
coche devant ces lignes et clic sur fix checked
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
---------------------
Télécharge BTFix 1.017 (de bibi26)
http://cluster1.easy-hebergement.net/
* Décompresse l'archive sur ton Bureau
* Ouvre le dossier BTFix
* Double clique sur BTFix.exe
* Clique sur Rechercher
* Un rapport va apparaître, copie/colle-le dans ta prochaine réponse
Si tu vois une infection tu continues( là......)
Démarrer en Mode sans échec. Attention, tu n'as pas accès à Internet dans ce mode, note bien ce que tu as à faire.
(Pour cela : démarrer le PC en tapotant sur la touche F8 du clavier jusqu'à ce que le menu des options avancées de Windows apparaisse puis avec les touches fléchées du clavier, sélectionner Mode sans échec puis appuyer sur la touche Entrée...)
Attention tu n'as pas accès à Internet dans ce mode donc note ou imprime les consignes qui suivent.
* Démarre l'ordinateur.
* Une fois le chargement du BIOS terminé, il y a un écran noir.
* Appuie sur la touche F8 ou F5, à répétition jusqu'à l'affichage du menu des options avancées de Windows.
* En utilisant les touches du curseur, sélectionne le mode sans échec approprié et appuie sur Entrée.
* Choisis ton compte usuel et non Administrateur.
* Ouvre BTFix
* Clique sur "Nettoyer"
* Un rapport va apparaître, copie/colle-le dans ta prochaine réponse
et un nouvel hijackthis
ok je te remercie je vais faire tous ca, et on va voir... j'avais installé zone alarm avant mais sa m'empechait de naviguer sur le net donc je l'avais enlevé, je vais installer kerio et je vous tiens au courant!
a tte
a tte
euh.. pourquoi nicolas? lol!! (je suis une fille en plus... hum)
Je suis sur un pc... et je n'ai pas n'utilise pas emule...
Je commence par ta manip ou celle de noctambule?
Je suis sur un pc... et je n'ai pas n'utilise pas emule...
Je commence par ta manip ou celle de noctambule?
lol je comprend rien...
j'ai vu que j'avais une vingtaine de fichier au demarrage, c'est pas normal c'est ca? faut que je fasse le tri? ok
et enlever les toolbar en 2mots faut faire comment?
j'ai vu que j'avais une vingtaine de fichier au demarrage, c'est pas normal c'est ca? faut que je fasse le tri? ok
et enlever les toolbar en 2mots faut faire comment?
bon koolas
tu as une infection, c'est bien ce qui te preoccupait, alors je vais pas te forcer, à agir
je t'ai envoyé des liens pour que tu telecharges des outils de desinfection, je ne peux pas le faire à ta place, donc les conseils de zone-swap sont peu etre tres interressant, mais aller depoussierer ton disque ne va pas retirer ce que tu as
en plus aller fouiller dans la base de registre, huuummmm
tu as une infection, c'est bien ce qui te preoccupait, alors je vais pas te forcer, à agir
je t'ai envoyé des liens pour que tu telecharges des outils de desinfection, je ne peux pas le faire à ta place, donc les conseils de zone-swap sont peu etre tres interressant, mais aller depoussierer ton disque ne va pas retirer ce que tu as
en plus aller fouiller dans la base de registre, huuummmm
noctambule, lorsque j'essais de telecharger kerio, un message me dit que mes parametres de securité ne me le permettent pas.comment sa se fait?
ok pr les toolbar et fichier de demarrage... reste a installer kerioet antivir, mes parametre de securité ne me permette pas de telcharger... c'est bizard?
arff
peux tu essayé de telecharger antivir ou zone alarm, pour voir si cela se fait avec tous ?
si c'est le cas, alors n'insiste pas et passe à la suite ( hijackthis et BTfix)
tu as peut une verole qui bloque mais ça me surprend,
au fait si tu passe à antivir, il faut desinstaller avast proprement , regarde là
http://www.commentcamarche.net/faq/sujet 8172 desinstaller proprement avast
peux tu essayé de telecharger antivir ou zone alarm, pour voir si cela se fait avec tous ?
si c'est le cas, alors n'insiste pas et passe à la suite ( hijackthis et BTfix)
tu as peut une verole qui bloque mais ça me surprend,
au fait si tu passe à antivir, il faut desinstaller avast proprement , regarde là
http://www.commentcamarche.net/faq/sujet 8172 desinstaller proprement avast
c réglé pr antivir kerio et avast... il me manque mcaffe a bien desastaller
Simplement au redemarrage kerio detecte tentative d'intrusion de c: windows/systeme32/rnrwxpg.exe ; je voulais savoir si ct normal? surtout qu'en voulant fermer la fenetre de kerio , elle se reouvre apres?
Je pose peut etre des questions bête... mais j'y connais rien
Simplement au redemarrage kerio detecte tentative d'intrusion de c: windows/systeme32/rnrwxpg.exe ; je voulais savoir si ct normal? surtout qu'en voulant fermer la fenetre de kerio , elle se reouvre apres?
Je pose peut etre des questions bête... mais j'y connais rien
tes questions ne sont pas bete,
s'il decouvre une tentative d'intrusion, c'est que .... il y en a , en plus ce programme est absolument inconu donc une verole en plus
donc il va falloir regler ça aussi
pour l(instant si kerio ne pose pas de souics pour naviguer et telcharger ce que je t'envoie ne donne pas d'autorisation au programme dans le pare feu
continue, je suis en france , mais je serais là encore une heure environ
s'il decouvre une tentative d'intrusion, c'est que .... il y en a , en plus ce programme est absolument inconu donc une verole en plus
donc il va falloir regler ça aussi
pour l(instant si kerio ne pose pas de souics pour naviguer et telcharger ce que je t'envoie ne donne pas d'autorisation au programme dans le pare feu
continue, je suis en france , mais je serais là encore une heure environ
bon jai lancé antivir et il ma trouvé rapidement un virus : McaUpdate.exe ; je lai mis en quarantaine, je laisse tourner le scan et vs tiens au courant + tard
Merci beaucoup pr votre aide
Merci beaucoup pr votre aide
tu laisse tourner antivir, c'est tres bien
tu ne fait rien d'autre d'ailleurs, il est preferable de ne rien faire et de fermer le maximum d'application pendant les scans ( tous les scans)
il est meme conseiller de le faire en mode sans echec
ne t'inquiète pas , je suis la tous les jours ou presque, et je sais des que tu post sur le topic ou quelqu'un d'autre ( tu le verrais aussi si tu etais inscrite)
donc si ce n'est pas fini ce soir , et bien ça sera pour demain, il est rare de finr en seule soirée
apres pour continuer, tu me post le rapport de antivir, et tu fais ce que je t'ai indiqué au debut avec hijackthis et BTfix
a+
tu ne fait rien d'autre d'ailleurs, il est preferable de ne rien faire et de fermer le maximum d'application pendant les scans ( tous les scans)
il est meme conseiller de le faire en mode sans echec
ne t'inquiète pas , je suis la tous les jours ou presque, et je sais des que tu post sur le topic ou quelqu'un d'autre ( tu le verrais aussi si tu etais inscrite)
donc si ce n'est pas fini ce soir , et bien ça sera pour demain, il est rare de finr en seule soirée
apres pour continuer, tu me post le rapport de antivir, et tu fais ce que je t'ai indiqué au debut avec hijackthis et BTfix
a+
bonjour, voici le resultat du scan antivir pour commencer , sa n'a pas l'air joli tout ca :
AntiVir PersonalEdition Classic
Report file date: mercredi 6 février 2008 04:53
Scanning for 1093948 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: SYSTEM
Computer name: ANANAS
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 03:04:20
ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 25/01/2008 03:04:20
ANTIVIR3.VDF : 7.0.2.96 321024 Bytes 05/02/2008 03:04:20
AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 06/02/2008 03:04:20
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 06/02/2008 03:04:20
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: mercredi 6 février 2008 04:53
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'TabUserW.exe' - '1' Module(s) have been scanned
Scan process 'CLSched.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'FormatM.exe' - '1' Module(s) have been scanned
Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
Scan process 'CLMLServer.exe' - '1' Module(s) have been scanned
Scan process 'CTDevSrv.exe' - '1' Module(s) have been scanned
Scan process 'CTSVCCDA.EXE' - '1' Module(s) have been scanned
Scan process 'CLCapSvc.exe' - '1' Module(s) have been scanned
Scan process 'CDANTSRV.EXE' - '1' Module(s) have been scanned
Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'rnrwxpg.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'LEXPPS.EXE' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'LEXBCES.EXE' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
41 processes with 41 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '35' files ).
Starting the file scan:
Begin scan in 'C:\' <PRESARIO>
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP283\A0068226.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '47d99690.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP297\A0068669.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996d1.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP297\A0068670.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was deleted!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP299\A0068764.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was renamed to 'A0068764.exe.VIR'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP299\A0068765.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f2.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP300\A0068787.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f4.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP300\A0068788.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e15.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP300\A0068806.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f5.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP300\A0068807.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e16.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP301\A0068830.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f7.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP301\A0068831.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e18.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP302\A0068871.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f9.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP302\A0068872.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e1a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP303\A0068915.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996fb.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP303\A0068916.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e1c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP303\A0068935.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996fc.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP303\A0068936.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e1d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP304\A0068980.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996ff.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP304\A0068981.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fe0.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069096.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99707.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069097.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fe8.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069129.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99709.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069130.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fea.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069182.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9970b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069183.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fec.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP306\A0069214.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9970e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP306\A0069215.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9970f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP307\A0069257.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99711.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP307\A0069258.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99712.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP308\A0069284.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99714.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP308\A0069285.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ff5.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069350.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99718.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069352.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ff9.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069369.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99719.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069370.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffa.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069387.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069388.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffb.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069404.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069405.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069421.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffc.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069422.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069438.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffd.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069439.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069455.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffe.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069456.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069475.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc0.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069476.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99721.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069494.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99720.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069495.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc1.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069512.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc2.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069513.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99723.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069524.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '47d99722.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP312\A0069530.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc4.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP312\A0069532.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99724.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP313\A0069554.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99726.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP313\A0069555.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99727.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP313\A0069573.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc8.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP313\A0069574.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99729.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP314\A0069595.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9972a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP314\A0069597.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fcb.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP314\A0069623.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9972b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP314\A0069624.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fcc.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP316\A0069678.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9972f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP316\A0069679.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99730.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP316\A0070678.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99731.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP316\A0070679.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fd2.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP317\A0070714.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99734.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP317\A0070715.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fd5.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP318\A0070729.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99736.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP318\A0070730.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fd7.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP318\A0070751.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99737.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP318\A0070752.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fd8.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP319\A0070774.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99739.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP319\A0070775.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fda.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070791.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9973b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070792.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fdc.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070817.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9973c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070818.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9973d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070836.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fde.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070837.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9973f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP322\A0071836.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99749.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP322\A0071837.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67faa.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071859.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9974b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071860.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fac.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071876.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9974c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071877.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fad.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071993.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99751.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071994.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fb2.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072019.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99752.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072020.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fb3.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072036.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99754.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072037.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99753.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072052.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fb4.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072053.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99755.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP324\A0072122.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99757.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP324\A0072123.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fb8.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072254.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9975d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072255.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fbe.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072310.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9975f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072311.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99760.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072328.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f81.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072329.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99762.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP329\A0072463.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99767.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP329\A0072464.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99768.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP329\A0072548.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9976a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP329\A0072549.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9976b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP330\A0072570.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9976d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP330\A0072571.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f8e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP331\A0072708.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99773.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP331\A0072709.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f94.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP333\A0072796.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99777.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP333\A0072797.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f98.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP333\A0072816.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99778.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP333\A0072817.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f99.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP334\A0072851.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9977b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP334\A0072852.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f9c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP335\A0072900.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9977e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP335\A0072901.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f9f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP335\A0073900.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99740.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP335\A0073901.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9977f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074900.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99786.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074901.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f67.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074935.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99788.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074936.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f69.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074956.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9978a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074957.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99789.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP340\A0074994.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9978b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP340\A0074995.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f6c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP341\A0075021.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9978e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP341\A0075022.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f6f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP341\A0075063.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9978f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP348\A0082089.exe
[DETECTION] Contains detection pattern of the worm WORM/Delf.CA
[INFO] The file was moved to '47d997aa.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP350\A0082237.exe
[DETECTION] Is the Trojan horse TR/Agent.AGBR
[INFO] The file was moved to '47d997b4.qua'!
C:\WINDOWS\Config\System.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '481c9865.qua'!
C:\WINDOWS\system32\drivers\dtscsi.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd8429.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\' <PRESARIO_RP>
End of the scan: mercredi 6 février 2008 12:49
Used time: 7:56:10 min
The scan has been done completely.
8856 Scanning directories
532315 Files were scanned
134 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
1 files were deleted
0 files were repaired
132 files were moved to quarantine
1 files were renamed
5 Files cannot be scanned
532181 Files not concerned
16508 Archives were scanned
5 Warnings
54 Notes
AntiVir PersonalEdition Classic
Report file date: mercredi 6 février 2008 04:53
Scanning for 1093948 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: SYSTEM
Computer name: ANANAS
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 03:04:20
ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 25/01/2008 03:04:20
ANTIVIR3.VDF : 7.0.2.96 321024 Bytes 05/02/2008 03:04:20
AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 06/02/2008 03:04:20
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 06/02/2008 03:04:20
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: mercredi 6 février 2008 04:53
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'TabUserW.exe' - '1' Module(s) have been scanned
Scan process 'CLSched.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'FormatM.exe' - '1' Module(s) have been scanned
Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
Scan process 'CLMLServer.exe' - '1' Module(s) have been scanned
Scan process 'CTDevSrv.exe' - '1' Module(s) have been scanned
Scan process 'CTSVCCDA.EXE' - '1' Module(s) have been scanned
Scan process 'CLCapSvc.exe' - '1' Module(s) have been scanned
Scan process 'CDANTSRV.EXE' - '1' Module(s) have been scanned
Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'rnrwxpg.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'LEXPPS.EXE' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'LEXBCES.EXE' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
41 processes with 41 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '35' files ).
Starting the file scan:
Begin scan in 'C:\' <PRESARIO>
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP283\A0068226.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '47d99690.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP297\A0068669.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996d1.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP297\A0068670.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was deleted!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP299\A0068764.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was renamed to 'A0068764.exe.VIR'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP299\A0068765.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f2.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP300\A0068787.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f4.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP300\A0068788.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e15.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP300\A0068806.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f5.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP300\A0068807.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e16.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP301\A0068830.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f7.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP301\A0068831.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e18.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP302\A0068871.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996f9.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP302\A0068872.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e1a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP303\A0068915.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996fb.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP303\A0068916.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e1c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP303\A0068935.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996fc.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP303\A0068936.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67e1d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP304\A0068980.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d996ff.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP304\A0068981.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fe0.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069096.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99707.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069097.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fe8.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069129.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99709.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069130.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fea.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069182.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9970b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP305\A0069183.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fec.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP306\A0069214.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9970e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP306\A0069215.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9970f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP307\A0069257.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99711.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP307\A0069258.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99712.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP308\A0069284.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99714.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP308\A0069285.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ff5.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069350.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99718.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069352.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ff9.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069369.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99719.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069370.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffa.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069387.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069388.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffb.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069404.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069405.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069421.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffc.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069422.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069438.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffd.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069439.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069455.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67ffe.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP310\A0069456.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9971f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069475.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc0.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069476.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99721.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069494.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99720.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069495.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc1.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069512.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc2.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069513.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99723.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP311\A0069524.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '47d99722.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP312\A0069530.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc4.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP312\A0069532.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99724.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP313\A0069554.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99726.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP313\A0069555.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99727.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP313\A0069573.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fc8.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP313\A0069574.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99729.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP314\A0069595.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9972a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP314\A0069597.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fcb.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP314\A0069623.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9972b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP314\A0069624.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fcc.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP316\A0069678.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9972f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP316\A0069679.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99730.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP316\A0070678.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99731.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP316\A0070679.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fd2.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP317\A0070714.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99734.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP317\A0070715.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fd5.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP318\A0070729.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99736.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP318\A0070730.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fd7.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP318\A0070751.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99737.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP318\A0070752.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fd8.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP319\A0070774.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99739.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP319\A0070775.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fda.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070791.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9973b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070792.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fdc.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070817.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9973c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070818.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9973d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070836.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fde.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP320\A0070837.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9973f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP322\A0071836.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99749.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP322\A0071837.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67faa.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071859.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9974b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071860.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fac.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071876.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9974c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071877.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fad.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071993.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99751.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0071994.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fb2.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072019.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99752.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072020.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fb3.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072036.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99754.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072037.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99753.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072052.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fb4.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP323\A0072053.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99755.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP324\A0072122.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99757.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP324\A0072123.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fb8.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072254.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9975d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072255.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67fbe.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072310.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9975f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072311.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99760.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072328.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f81.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP326\A0072329.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99762.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP329\A0072463.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99767.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP329\A0072464.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99768.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP329\A0072548.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9976a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP329\A0072549.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9976b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP330\A0072570.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9976d.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP330\A0072571.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f8e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP331\A0072708.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99773.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP331\A0072709.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f94.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP333\A0072796.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99777.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP333\A0072797.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f98.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP333\A0072816.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99778.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP333\A0072817.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f99.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP334\A0072851.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9977b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP334\A0072852.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f9c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP335\A0072900.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9977e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP335\A0072901.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f9f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP335\A0073900.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99740.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP335\A0073901.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9977f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074900.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99786.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074901.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f67.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074935.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99788.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074936.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f69.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074956.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9978a.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP339\A0074957.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d99789.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP340\A0074994.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9978b.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP340\A0074995.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f6c.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP341\A0075021.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9978e.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP341\A0075022.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '46a67f6f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP341\A0075063.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '47d9978f.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP348\A0082089.exe
[DETECTION] Contains detection pattern of the worm WORM/Delf.CA
[INFO] The file was moved to '47d997aa.qua'!
C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP350\A0082237.exe
[DETECTION] Is the Trojan horse TR/Agent.AGBR
[INFO] The file was moved to '47d997b4.qua'!
C:\WINDOWS\Config\System.exe
[DETECTION] Contains detection pattern of the worm WORM/VB.NPM.1
[INFO] The file was moved to '481c9865.qua'!
C:\WINDOWS\system32\drivers\dtscsi.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd8429.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\' <PRESARIO_RP>
End of the scan: mercredi 6 février 2008 12:49
Used time: 7:56:10 min
The scan has been done completely.
8856 Scanning directories
532315 Files were scanned
134 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
1 files were deleted
0 files were repaired
132 files were moved to quarantine
1 files were renamed
5 Files cannot be scanned
532181 Files not concerned
16508 Archives were scanned
5 Warnings
54 Notes