Probléme cheval de troie
jerem17_66
Messages postés
25
Statut
Membre
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
Heir soir, j'ai téléchargé les apparences de windows Vista sur mon PC qui lui est un XP Pro, et depuis tous beugue. Au démarrage, aprés avoir taper mon mot de passe, j'ai juste mon fond d'écran (sans icone) et j'ai un message d'erreur comme quoi explorer.exe n'a pas pu s'éxécuter. donc je fais Ctrl+Alt+sup pour aovir le gestionnaire des taches, et je lance explorer.exe manuellement, mais aprés quand je lance avast, il me détecte un cheval de troie dans le system32 et je ne peux pas le supprimer, parce qu'il me mette qu'il est en lecture seul. Comment faire pour virer ce virus? svp aidez moi, c'est urgent, j'ai besoin de mon ordi pour revisé mon exam. merci d'avance
Heir soir, j'ai téléchargé les apparences de windows Vista sur mon PC qui lui est un XP Pro, et depuis tous beugue. Au démarrage, aprés avoir taper mon mot de passe, j'ai juste mon fond d'écran (sans icone) et j'ai un message d'erreur comme quoi explorer.exe n'a pas pu s'éxécuter. donc je fais Ctrl+Alt+sup pour aovir le gestionnaire des taches, et je lance explorer.exe manuellement, mais aprés quand je lance avast, il me détecte un cheval de troie dans le system32 et je ne peux pas le supprimer, parce qu'il me mette qu'il est en lecture seul. Comment faire pour virer ce virus? svp aidez moi, c'est urgent, j'ai besoin de mon ordi pour revisé mon exam. merci d'avance
A voir également:
- Probléme cheval de troie
- Antivirus cheval de troie gratuit - Télécharger - Antivirus & Antimalwares
- Ordinateur bloqué cheval de troie - Accueil - Arnaque
- Qu'est ce que le cheval au poker - Forum Virus
- Comment se débarrasser d'un cheval de troie ✓ - Forum Virus
- Skyrim retrouver son cheval - Forum Jeux PC
8 réponses
jerem17_66
Messages postés
25
Statut
Membre
comme antivur j'ai avast 4.8, et comme anti spywrare j'ai Spyware doctor
Salut,
Redémarre en mode sans echecs et lance Avast, en attendant des experts dans ce domaine...
Juste un truc, prends Antivir plutôt qu'Avast...
Volt
Redémarre en mode sans echecs et lance Avast, en attendant des experts dans ce domaine...
Juste un truc, prends Antivir plutôt qu'Avast...
Volt
Ok Re alors désinstalle tous tes logiciel de sécurité. Et installe AntiVir,Malwarebytes Anti-Malware,Ccleaner et active le pare-feu XP.
AntiVir: https://www.01net.com/outils/telecharger/windows/Securite/antivirus-antitrojan/fiches/tele13198.html
Tutoriel AntiVir: https://www.malekal.com/avira-free-security-antivirus-gratuit/
Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe
Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
Ccleaner: https://www.01net.com/outils/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/tele32599.html
Tutoriel Ccleaner: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php (Tu l'installe sans la bare d'outil Yahoo)
PS: TU LES INSTALLES SEULEMENT ET TU NE FAIS PAS D'ANALYSE. TU FAIS UNE MISE A JOUR A ANTIVIR ET MALWAREBYTES ANTI-MALWARE.
AntiVir: https://www.01net.com/outils/telecharger/windows/Securite/antivirus-antitrojan/fiches/tele13198.html
Tutoriel AntiVir: https://www.malekal.com/avira-free-security-antivirus-gratuit/
Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe
Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
Ccleaner: https://www.01net.com/outils/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/tele32599.html
Tutoriel Ccleaner: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php (Tu l'installe sans la bare d'outil Yahoo)
PS: TU LES INSTALLES SEULEMENT ET TU NE FAIS PAS D'ANALYSE. TU FAIS UNE MISE A JOUR A ANTIVIR ET MALWAREBYTES ANTI-MALWARE.
Tu fais un scan en mode sans échec avec AntiVir. Tu lances le scan et si il détecte un virus (normalement oui) tu cliques sur "delete" et "apply sélection to all following détections. (pour qu'il le supprimes automatiquement). A la fin du scan tu cliques sur "report" tu redémarre en mode normal puis tu me postes le rapport.
Mode sans Echec:
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
PS: JE TE CONSEILLE D'ENREGISTRER CE MESSAGE DANS TON BUREAU OU CAS OU.
Mode sans Echec:
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
PS: JE TE CONSEILLE D'ENREGISTRER CE MESSAGE DANS TON BUREAU OU CAS OU.
Salut en logiciel je te conseil aussi ad-aware https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/11643.html
tu fait une mise a jour et un scan complet du system (tu peu le métre en français apré la mise a jour dans le menu de gauche tt en bas settings apré ULL é tu choisi ;)
tu fait une mise a jour et un scan complet du system (tu peu le métre en français apré la mise a jour dans le menu de gauche tt en bas settings apré ULL é tu choisi ;)
re Boy94450, tu veux vraiment mon report d'antivir en mode sans échec? ok le voila:
Avira AntiVir Personal
Report file date: samedi 10 mai 2008 15:41
Scanning for 1165085 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Save mode
Username: Jerem
Computer name: G50
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
ANTIVIR2.VDF : 7.0.3.62 337408 Bytes 21/03/2008 19:12:34
ANTIVIR3.VDF : 7.0.3.68 57856 Bytes 25/03/2008 08:27:50
Engineversion : 8.1.0.28
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.19 229754 Bytes 07/04/2008 15:34:44
AESCN.DLL : 8.1.0.12 115060 Bytes 07/04/2008 15:34:44
AERDL.DLL : 8.1.0.19 418164 Bytes 07/04/2008 15:34:44
AEPACK.DLL : 8.1.1.0 364918 Bytes 18/03/2008 11:20:42
AEOFFICE.DLL : 8.1.0.15 192889 Bytes 07/04/2008 15:34:44
AEHEUR.DLL : 8.1.0.15 1147253 Bytes 07/04/2008 15:34:44
AEHELP.DLL : 8.1.0.11 115061 Bytes 07/04/2008 15:34:43
AEGEN.DLL : 8.1.0.15 299379 Bytes 07/04/2008 15:34:43
AEEMU.DLL : 8.1.0.5 430450 Bytes 07/04/2008 15:34:43
AECORE.DLL : 8.1.0.25 168309 Bytes 08/04/2008 09:58:32
AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 10 mai 2008 15:41
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
12 processes with 12 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '47' files ).
Starting the file scan:
Begin scan in 'C:\' <HDD>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112148.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112174.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112198.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112199.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP479\A0112227.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0112269.exe
[DETECTION] Is the Trojan horse TR/MailSkinner.A
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0112270.dll
[DETECTION] Is the Trojan horse TR/MailSkinner.DLL.2
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0113226.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP481\A0113256.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113297.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113318.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113319.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP484\A0113360.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP484\A0113370.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP485\A0113436.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113454.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113465.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113496.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113497.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113518.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113522.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113526.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114533.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114534.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114535.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114536.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114583.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114625.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114630.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114639.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114649.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP489\A0114676.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP490\A0114695.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP490\A0115693.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP491\A0115728.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115742.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115757.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115773.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115784.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115821.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115831.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP494\A0115922.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP494\A0115956.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP496\A0116035.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP496\A0116072.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP497\A0116113.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP498\A0116156.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP498\A0116165.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116178.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116206.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116215.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116257.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116260.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116271.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0117275.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP501\A0117321.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP501\A0117357.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP502\A0117396.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP502\A0117428.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP503\A0117500.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP504\A0117508.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP504\A0117520.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP505\A0117534.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP506\A0117558.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP506\A0117577.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117655.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117670.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117732.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP508\A0118735.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118776.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118817.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118822.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP510\A0118835.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP510\A0118846.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP511\A0119837.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP511\A0119848.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP512\A0119863.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP513\A0120928.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP513\A0120957.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP514\A0121976.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP515\A0122011.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP515\A0122031.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122064.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122083.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122125.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122157.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122209.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122258.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122274.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP518\A0122320.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0122417.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0122438.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0123435.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0123452.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0123514.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0124514.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0124527.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0124568.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0125565.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125613.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125617.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125641.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125651.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125657.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP524\A0125671.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP524\A0125683.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP525\A0125692.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP525\A0125706.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0125716.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126706.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126726.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126737.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0126799.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0126839.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0127842.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0127909.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0127925.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0128925.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP529\A0129929.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP529\A0129942.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP530\A0130003.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP530\A0130050.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0131052.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0131055.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0132047.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0133047.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP532\A0133063.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP532\A0133070.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133080.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133088.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133099.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0133105.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0133124.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0134128.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP535\A0134194.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP535\A0134200.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP539\A0135208.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP539\A0135210.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0135313.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0136332.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0136345.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP542\A0137337.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP543\A0137355.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140855.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140856.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140857.exe
[DETECTION] Is the Trojan horse TR/Agent.154032
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140858.exe
[DETECTION] Is the Trojan horse TR/Agent.154032
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140859.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\es.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\browser.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll
[WARNING] The file could not be opened!
C:\WINDOWS\system32\TFTP3272
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[NOTE] The file was deleted!
C:\WINDOWS\system32\TFTP3676
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[NOTE] The file was deleted!
C:\WINDOWS1\suajrjld.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
End of the scan: samedi 10 mai 2008 17:57
Used time: 2:15:39 min
The scan has been done completely.
9782 Scanning directories
442874 Files were scanned
153 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
153 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
28 Files cannot be scanned
442721 Files not concerned
8534 Archives were scanned
29 Warnings
153 Notes
par contre je sais pas si mon cheval de troie est parti, mais j'ai toujours mon probléme d'explorer.exe au début, obligé de le lancé manuellement
Avira AntiVir Personal
Report file date: samedi 10 mai 2008 15:41
Scanning for 1165085 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Save mode
Username: Jerem
Computer name: G50
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
ANTIVIR2.VDF : 7.0.3.62 337408 Bytes 21/03/2008 19:12:34
ANTIVIR3.VDF : 7.0.3.68 57856 Bytes 25/03/2008 08:27:50
Engineversion : 8.1.0.28
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.19 229754 Bytes 07/04/2008 15:34:44
AESCN.DLL : 8.1.0.12 115060 Bytes 07/04/2008 15:34:44
AERDL.DLL : 8.1.0.19 418164 Bytes 07/04/2008 15:34:44
AEPACK.DLL : 8.1.1.0 364918 Bytes 18/03/2008 11:20:42
AEOFFICE.DLL : 8.1.0.15 192889 Bytes 07/04/2008 15:34:44
AEHEUR.DLL : 8.1.0.15 1147253 Bytes 07/04/2008 15:34:44
AEHELP.DLL : 8.1.0.11 115061 Bytes 07/04/2008 15:34:43
AEGEN.DLL : 8.1.0.15 299379 Bytes 07/04/2008 15:34:43
AEEMU.DLL : 8.1.0.5 430450 Bytes 07/04/2008 15:34:43
AECORE.DLL : 8.1.0.25 168309 Bytes 08/04/2008 09:58:32
AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 10 mai 2008 15:41
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
12 processes with 12 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '47' files ).
Starting the file scan:
Begin scan in 'C:\' <HDD>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112148.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112174.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112198.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112199.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP479\A0112227.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0112269.exe
[DETECTION] Is the Trojan horse TR/MailSkinner.A
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0112270.dll
[DETECTION] Is the Trojan horse TR/MailSkinner.DLL.2
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0113226.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP481\A0113256.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113297.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113318.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113319.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP484\A0113360.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP484\A0113370.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP485\A0113436.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113454.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113465.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113496.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113497.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113518.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113522.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113526.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114533.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114534.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114535.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114536.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114583.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114625.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114630.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114639.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114649.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP489\A0114676.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP490\A0114695.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP490\A0115693.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP491\A0115728.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115742.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115757.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115773.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115784.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115821.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115831.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP494\A0115922.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP494\A0115956.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP496\A0116035.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP496\A0116072.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP497\A0116113.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP498\A0116156.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP498\A0116165.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116178.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116206.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116215.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116257.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116260.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116271.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0117275.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP501\A0117321.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP501\A0117357.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP502\A0117396.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP502\A0117428.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP503\A0117500.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP504\A0117508.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP504\A0117520.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP505\A0117534.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP506\A0117558.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP506\A0117577.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117655.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117670.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117732.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP508\A0118735.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118776.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118817.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118822.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP510\A0118835.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP510\A0118846.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP511\A0119837.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP511\A0119848.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP512\A0119863.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP513\A0120928.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP513\A0120957.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP514\A0121976.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP515\A0122011.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP515\A0122031.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122064.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122083.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122125.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122157.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122209.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122258.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122274.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP518\A0122320.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0122417.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0122438.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0123435.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0123452.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0123514.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0124514.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0124527.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0124568.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0125565.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125613.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125617.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125641.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125651.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125657.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP524\A0125671.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP524\A0125683.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP525\A0125692.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP525\A0125706.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0125716.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126706.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126726.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126737.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0126799.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0126839.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0127842.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0127909.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0127925.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0128925.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP529\A0129929.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP529\A0129942.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP530\A0130003.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP530\A0130050.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0131052.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0131055.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0132047.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0133047.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP532\A0133063.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP532\A0133070.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133080.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133088.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133099.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0133105.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0133124.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0134128.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP535\A0134194.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP535\A0134200.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP539\A0135208.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP539\A0135210.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0135313.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0136332.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0136345.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP542\A0137337.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP543\A0137355.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140855.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140856.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140857.exe
[DETECTION] Is the Trojan horse TR/Agent.154032
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140858.exe
[DETECTION] Is the Trojan horse TR/Agent.154032
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140859.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\es.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\browser.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll
[WARNING] The file could not be opened!
C:\WINDOWS\system32\TFTP3272
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[NOTE] The file was deleted!
C:\WINDOWS\system32\TFTP3676
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[NOTE] The file was deleted!
C:\WINDOWS1\suajrjld.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
End of the scan: samedi 10 mai 2008 17:57
Used time: 2:15:39 min
The scan has been done completely.
9782 Scanning directories
442874 Files were scanned
153 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
153 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
28 Files cannot be scanned
442721 Files not concerned
8534 Archives were scanned
29 Warnings
153 Notes
par contre je sais pas si mon cheval de troie est parti, mais j'ai toujours mon probléme d'explorer.exe au début, obligé de le lancé manuellement
salut boy94450 pourquoi dit tu que ad aware ne sert a rien a chaque foi que je suis infesté je fait un scan et sa repart (avast a l'époque ou je lavais ne trouvé rien mais sa c'est normal^^)
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Moi personnelement je te conseille de kaspersky 7 .
il est geniale
il est geniale
re Boy94450, tu veux vraiment mon report d'antivir en mode sans échec? ok le voila: par contre je sais pas si mon cheval de troie est parti, mais j'ai toujours mon probléme d'explorer.exe au début, obligé de le lancé manuellement
Avira AntiVir Personal
Report file date: samedi 10 mai 2008 15:41
Scanning for 1165085 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Save mode
Username: Jerem
Computer name: G50
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
ANTIVIR2.VDF : 7.0.3.62 337408 Bytes 21/03/2008 19:12:34
ANTIVIR3.VDF : 7.0.3.68 57856 Bytes 25/03/2008 08:27:50
Engineversion : 8.1.0.28
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.19 229754 Bytes 07/04/2008 15:34:44
AESCN.DLL : 8.1.0.12 115060 Bytes 07/04/2008 15:34:44
AERDL.DLL : 8.1.0.19 418164 Bytes 07/04/2008 15:34:44
AEPACK.DLL : 8.1.1.0 364918 Bytes 18/03/2008 11:20:42
AEOFFICE.DLL : 8.1.0.15 192889 Bytes 07/04/2008 15:34:44
AEHEUR.DLL : 8.1.0.15 1147253 Bytes 07/04/2008 15:34:44
AEHELP.DLL : 8.1.0.11 115061 Bytes 07/04/2008 15:34:43
AEGEN.DLL : 8.1.0.15 299379 Bytes 07/04/2008 15:34:43
AEEMU.DLL : 8.1.0.5 430450 Bytes 07/04/2008 15:34:43
AECORE.DLL : 8.1.0.25 168309 Bytes 08/04/2008 09:58:32
AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 10 mai 2008 15:41
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
12 processes with 12 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '47' files ).
Starting the file scan:
Begin scan in 'C:\' <HDD>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112148.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112174.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112198.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112199.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP479\A0112227.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0112269.exe
[DETECTION] Is the Trojan horse TR/MailSkinner.A
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0112270.dll
[DETECTION] Is the Trojan horse TR/MailSkinner.DLL.2
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0113226.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP481\A0113256.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113297.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113318.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113319.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP484\A0113360.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP484\A0113370.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP485\A0113436.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113454.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113465.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113496.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113497.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113518.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113522.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113526.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114533.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114534.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114535.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114536.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114583.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114625.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114630.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114639.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114649.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP489\A0114676.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP490\A0114695.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP490\A0115693.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP491\A0115728.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115742.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115757.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115773.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115784.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115821.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115831.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP494\A0115922.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP494\A0115956.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP496\A0116035.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP496\A0116072.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP497\A0116113.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP498\A0116156.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP498\A0116165.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116178.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116206.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116215.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116257.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116260.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116271.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0117275.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP501\A0117321.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP501\A0117357.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP502\A0117396.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP502\A0117428.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP503\A0117500.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP504\A0117508.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP504\A0117520.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP505\A0117534.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP506\A0117558.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP506\A0117577.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117655.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117670.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117732.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP508\A0118735.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118776.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118817.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118822.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP510\A0118835.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP510\A0118846.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP511\A0119837.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP511\A0119848.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP512\A0119863.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP513\A0120928.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP513\A0120957.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP514\A0121976.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP515\A0122011.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP515\A0122031.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122064.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122083.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122125.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122157.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122209.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122258.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122274.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP518\A0122320.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0122417.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0122438.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0123435.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0123452.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0123514.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0124514.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0124527.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0124568.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0125565.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125613.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125617.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125641.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125651.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125657.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP524\A0125671.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP524\A0125683.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP525\A0125692.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP525\A0125706.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0125716.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126706.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126726.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126737.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0126799.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0126839.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0127842.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0127909.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0127925.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0128925.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP529\A0129929.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP529\A0129942.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP530\A0130003.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP530\A0130050.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0131052.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0131055.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0132047.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0133047.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP532\A0133063.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP532\A0133070.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133080.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133088.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133099.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0133105.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0133124.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0134128.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP535\A0134194.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP535\A0134200.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP539\A0135208.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP539\A0135210.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0135313.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0136332.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0136345.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP542\A0137337.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP543\A0137355.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140855.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140856.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140857.exe
[DETECTION] Is the Trojan horse TR/Agent.154032
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140858.exe
[DETECTION] Is the Trojan horse TR/Agent.154032
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140859.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\es.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\browser.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll
[WARNING] The file could not be opened!
C:\WINDOWS\system32\TFTP3272
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[NOTE] The file was deleted!
C:\WINDOWS\system32\TFTP3676
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[NOTE] The file was deleted!
C:\WINDOWS1\suajrjld.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
End of the scan: samedi 10 mai 2008 17:57
Used time: 2:15:39 min
The scan has been done completely.
9782 Scanning directories
442874 Files were scanned
153 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
153 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
28 Files cannot be scanned
442721 Files not concerned
8534 Archives were scanned
29 Warnings
153 Notes
par contre je sais pas si mon cheval de troie est parti, mais j'ai toujours mon probléme d'explorer.exe au début, obligé de le lancé manuellement
Avira AntiVir Personal
Report file date: samedi 10 mai 2008 15:41
Scanning for 1165085 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Save mode
Username: Jerem
Computer name: G50
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
ANTIVIR2.VDF : 7.0.3.62 337408 Bytes 21/03/2008 19:12:34
ANTIVIR3.VDF : 7.0.3.68 57856 Bytes 25/03/2008 08:27:50
Engineversion : 8.1.0.28
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.19 229754 Bytes 07/04/2008 15:34:44
AESCN.DLL : 8.1.0.12 115060 Bytes 07/04/2008 15:34:44
AERDL.DLL : 8.1.0.19 418164 Bytes 07/04/2008 15:34:44
AEPACK.DLL : 8.1.1.0 364918 Bytes 18/03/2008 11:20:42
AEOFFICE.DLL : 8.1.0.15 192889 Bytes 07/04/2008 15:34:44
AEHEUR.DLL : 8.1.0.15 1147253 Bytes 07/04/2008 15:34:44
AEHELP.DLL : 8.1.0.11 115061 Bytes 07/04/2008 15:34:43
AEGEN.DLL : 8.1.0.15 299379 Bytes 07/04/2008 15:34:43
AEEMU.DLL : 8.1.0.5 430450 Bytes 07/04/2008 15:34:43
AECORE.DLL : 8.1.0.25 168309 Bytes 08/04/2008 09:58:32
AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 10 mai 2008 15:41
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
12 processes with 12 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '47' files ).
Starting the file scan:
Begin scan in 'C:\' <HDD>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112148.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112174.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112198.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP478\A0112199.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP479\A0112227.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0112269.exe
[DETECTION] Is the Trojan horse TR/MailSkinner.A
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0112270.dll
[DETECTION] Is the Trojan horse TR/MailSkinner.DLL.2
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP480\A0113226.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP481\A0113256.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113297.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113318.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP482\A0113319.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP484\A0113360.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP484\A0113370.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP485\A0113436.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113454.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113465.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113496.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113497.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113518.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113522.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP486\A0113526.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114533.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114534.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114535.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114536.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114583.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114625.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114630.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114639.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP488\A0114649.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP489\A0114676.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP490\A0114695.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP490\A0115693.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP491\A0115728.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115742.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115757.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP492\A0115773.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115784.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115821.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP493\A0115831.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP494\A0115922.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP494\A0115956.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP496\A0116035.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP496\A0116072.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP497\A0116113.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP498\A0116156.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP498\A0116165.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116178.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116192.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP499\A0116206.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116215.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116257.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116260.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0116271.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP500\A0117275.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP501\A0117321.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP501\A0117357.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP502\A0117396.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP502\A0117428.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP503\A0117500.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP504\A0117508.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP504\A0117520.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP505\A0117534.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP506\A0117558.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP506\A0117577.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117655.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117670.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP507\A0117732.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP508\A0118735.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118776.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118817.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP509\A0118822.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP510\A0118835.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP510\A0118846.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP511\A0119837.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP511\A0119848.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP512\A0119863.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP513\A0120928.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP513\A0120957.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP514\A0121976.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP515\A0122011.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP515\A0122031.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122064.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122083.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122125.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP516\A0122157.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122209.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122258.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP517\A0122274.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP518\A0122320.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0122417.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0122438.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP520\A0123435.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0123452.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0123514.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP521\A0124514.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0124527.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0124568.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP522\A0125565.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125613.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125617.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125641.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125651.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP523\A0125657.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP524\A0125671.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP524\A0125683.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP525\A0125692.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP525\A0125706.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0125716.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126706.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126726.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP526\A0126737.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0126799.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0126839.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP527\A0127842.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0127909.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0127925.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP528\A0128925.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP529\A0129929.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP529\A0129942.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP530\A0130003.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP530\A0130050.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0131052.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0131055.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0132047.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP531\A0133047.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP532\A0133063.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP532\A0133070.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133080.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133088.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP533\A0133099.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0133105.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0133124.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP534\A0134128.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP535\A0134194.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP535\A0134200.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP539\A0135208.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP539\A0135210.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0135313.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0136332.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP541\A0136345.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP542\A0137337.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP543\A0137355.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140855.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140856.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140857.exe
[DETECTION] Is the Trojan horse TR/Agent.154032
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140858.exe
[DETECTION] Is the Trojan horse TR/Agent.154032
[NOTE] The file was deleted!
C:\System Volume Information\_restore{1A680F37-6BC5-4A81-834D-12A747BD5247}\RP546\A0140859.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\es.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\browser.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll
[WARNING] The file could not be opened!
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll
[WARNING] The file could not be opened!
C:\WINDOWS\system32\TFTP3272
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[NOTE] The file was deleted!
C:\WINDOWS\system32\TFTP3676
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[NOTE] The file was deleted!
C:\WINDOWS1\suajrjld.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
End of the scan: samedi 10 mai 2008 17:57
Used time: 2:15:39 min
The scan has been done completely.
9782 Scanning directories
442874 Files were scanned
153 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
153 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
28 Files cannot be scanned
442721 Files not concerned
8534 Archives were scanned
29 Warnings
153 Notes
par contre je sais pas si mon cheval de troie est parti, mais j'ai toujours mon probléme d'explorer.exe au début, obligé de le lancé manuellement
Ok il a detecté et supprimé 153 virus ce qui est bien
1) Redémarre en "Mode sans échec"
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
2) Scan avec Malwarebyte's Anti-Malware
Lance Malwarebyte's Anti-Malware
Onglet "Recherche" >>> coche Executer un exame complet >>> Rechercher sélectionne tes disques durs puis clique sur Lancer l’examen
A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
Suppression des éléments détectés >>>> clique sur Supprimer la sélection
S'il t'es demandé de redémarrer >>> clique sur "Yes"
--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
1) Redémarre en "Mode sans échec"
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
2) Scan avec Malwarebyte's Anti-Malware
Lance Malwarebyte's Anti-Malware
Onglet "Recherche" >>> coche Executer un exame complet >>> Rechercher sélectionne tes disques durs puis clique sur Lancer l’examen
A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
Suppression des éléments détectés >>>> clique sur Supprimer la sélection
S'il t'es demandé de redémarrer >>> clique sur "Yes"
--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
re boy94450 voici le raport, par contre j'ai éteind mon ordi aprés le scan, mais mon probléme d'explorer est toujours là, obligation de passer par le gestionnaire des taches, nouvelle tache, et mettre c:\windows\explorer.exe, et la sa remarche, sa vient d'ou le probléme alors?
Malwarebytes' Anti-Malware 1.12
Version de la base de données: 737
Type de recherche: Examen complet (C:\|)
Eléments examinés: 163306
Temps écoulé: 1 hour(s), 52 minute(s), 23 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 3
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\Helper (Adware.BHO) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\WINDOWS1\Temp\7CF28762C38CA0D4.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS1\Temp\AE8AB41F91F72503.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS1\explorer.exe.tmp (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.12
Version de la base de données: 737
Type de recherche: Examen complet (C:\|)
Eléments examinés: 163306
Temps écoulé: 1 hour(s), 52 minute(s), 23 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 3
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\Helper (Adware.BHO) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\WINDOWS1\Temp\7CF28762C38CA0D4.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS1\Temp\AE8AB41F91F72503.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS1\explorer.exe.tmp (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Ok merci maintenant fais un scan en ligne avec Internet Explorer stp:
BitDefender en ligne: http://www.bitdefender.fr/scan_fr/scan8/ie.html
Tutoriel BitDefender en ligne: http://cybersecurite.xooit.com/t201-Scan-en-ligne-BitDefender.htm
Ps: N'oublies pas de me poster le rapport. Si tu as besoin d'aide aide toi tu tutoriel.
BitDefender en ligne: http://www.bitdefender.fr/scan_fr/scan8/ie.html
Tutoriel BitDefender en ligne: http://cybersecurite.xooit.com/t201-Scan-en-ligne-BitDefender.htm
Ps: N'oublies pas de me poster le rapport. Si tu as besoin d'aide aide toi tu tutoriel.
re boy94450 voici le rapport: BitDefender Online Scanner - Rapport virus en temps réel
Généré à: Sat, May 10, 2008 - 22:53:53
Info d'analyse
Fichiers scannés
92955
Infectés Fichiers
9
Virus Détectés
Backdoor.Rustock.NCB
1
Application.Topsearch.B
3
Trojan.Patched.Dropper.A
4
Application.Remoteadmin.DY
1
Par contre il y a un virus qui n'a pas pu etre supprimé, c'est dans le dossier c::\windows1\system32\rserver3.exe
Généré à: Sat, May 10, 2008 - 22:53:53
Info d'analyse
Fichiers scannés
92955
Infectés Fichiers
9
Virus Détectés
Backdoor.Rustock.NCB
1
Application.Topsearch.B
3
Trojan.Patched.Dropper.A
4
Application.Remoteadmin.DY
1
Par contre il y a un virus qui n'a pas pu etre supprimé, c'est dans le dossier c::\windows1\system32\rserver3.exe
Ok maintenant fais une defragmentation de disque:
Défragmenter le disque dur:
*Pour l'exécuter, cliquez sur le bouton Démarrer, sur Tous les programmes, sur Accessoires, Outils systèmes puis sur Défragmenteur de disque.
*cliquez sur le bouton Analyser. Le logiciel examine alors votre disque dur.
*Cliquez sur le bouton Afficher le rapport. (enregistre le et poste le moi stp)
*cliquez sur le bouton Défragmenter.
Défragmenter le disque dur:
*Pour l'exécuter, cliquez sur le bouton Démarrer, sur Tous les programmes, sur Accessoires, Outils systèmes puis sur Défragmenteur de disque.
*cliquez sur le bouton Analyser. Le logiciel examine alors votre disque dur.
*Cliquez sur le bouton Afficher le rapport. (enregistre le et poste le moi stp)
*cliquez sur le bouton Défragmenter.
voici le rapport boy94450.
Volume HDD (C:)
Taille du volume = 35,31 Go
Taille de cluster = 4 Ko
Espace utilisé = 23,36 Go
Espace libre = 11,95 Go
Pourcentage d'espace libre = 33 %
Fragmentation du volume
Fragmentation totale = 2 %
Fragmentation de fichiers = 5 %
Fragmentation de l'espace libre = 0 %
Fragmentation de fichiers
Total de fichiers = 118 626
Taille moyenne de fichier = 285 Ko
Total de fichiers fragmentés = 34
Total de fragments en trop = 478
Nombre moyen de fragments par fichier = 1,00
Fragmentation du fichier paginé
Taille du fichier paginé = 1,13 Go
Total de fragments = 2
Fragmentation de dossier
Total de dossiers = 9 775
Dossiers fragmentés = 1
Fragments de dossiers en trop = 0
Fragmentation de la table de fichiers principale (MFT)
Taille totale de la MFT = 251 Mo
Nombre d'enregistrements dans la MFT = 128 956
Pourcentage d'utilisation de la MFT = 50 %
Total de fragments dans la MFT = 3
--------------------------------------------------------------------------------
Fragments Taille du fichierFichiers les plus fragmentés
21 1 Ko \Documents and Settings\Jerem\ntuser.dat.LOG
10 422 Ko \WINDOWS1\Prefetch\Layout.ini
7 160 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Microsoft\Messenger\o_head_in_stars_o@hotmail.fr\SharingMetadata\Logs\Dfsr00005.log
4 63 Ko \WINDOWS1\system32\wbem\Logs\wbemess.log
4 1 Mo \WINDOWS1\WindowsUpdate.log
4 1 Mo \Documents and Settings\Jerem\Local Settings\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\Cache\_CACHE_001_
4 142 Ko \Documents and Settings\Jerem\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\history.dat
4 31 Ko \Documents and Settings\Jerem\Local Settings\Temporary Internet Files\Content.IE5\J7OKSF17\MsgrConfig[1].xml
3 92 Ko \WINDOWS1\Debug\UserMode\userenv.log
3 21 Ko \Documents and Settings\Jerem\Local Settings\Temporary Internet Files\Content.IE5\BG9RC23R\MDRAwards_Gad_Dany_234x60[1].swf
3 25 Ko \Documents and Settings\Jerem\Local Settings\Temporary Internet Files\Content.IE5\J7OKSF17\23460_002[1].swf
3 27 Ko \Documents and Settings\Jerem\Local Settings\Temporary Internet Files\Content.IE5\D5AVS86K\ebay[1].png
2 1 Ko \WINDOWS1\system32\config\software.LOG
2 12 Ko \Documents and Settings\Jerem\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\cookies.txt
2 31 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\Cache\69BF3C50d01
2 128 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Microsoft\Messenger\o_head_in_stars_o@hotmail.fr\SharingMetadata\Working\database_6200_CD5E_CD_39B5\tmp.edb
2 27 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\Cache\F0429502d01
2 19 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\Cache\D40BB790d01
2 47 Ko \WINDOWS1\SoftwareDistribution\SelfUpdate\Default\wsus3setup.cat
2 1 Ko \WINDOWS1\system32\config\SECURITY.LOG
2 16 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Microsoft\Messenger\o_head_in_stars_o@hotmail.fr\SharingMetadata\Logs\Dfsr00004.log.gz
2 1 Ko \WINDOWS1\system32\config\SAM.LOG
2 6 Ko \Documents and Settings\Jerem\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\localstore.rdf
2 64 Ko \WINDOWS1\SoftwareDistribution\DataStore\Logs\tmp.edb
2 5 Ko \Documents and Settings\Jerem\Application Data\Mozilla\Firefox\pluginreg.dat
2 8 Ko \Documents and Settings\All Users.WINDOWS1\Application Data\Avira\AntiVir PersonalEdition Classic\LOGFILES\Upd-2008-05-12-11-01-32.log
2 24 Ko \Documents and Settings\All Users.WINDOWS1\Application Data\Avira\AntiVir PersonalEdition Classic\LOGFILES\avguard.log
2 4 Ko \Documents and Settings\All Users.WINDOWS1\Application Data\Avira\AntiVir PersonalEdition Classic\LOGFILES\sched.log
2 1 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
Volume HDD (C:)
Taille du volume = 35,31 Go
Taille de cluster = 4 Ko
Espace utilisé = 23,36 Go
Espace libre = 11,95 Go
Pourcentage d'espace libre = 33 %
Fragmentation du volume
Fragmentation totale = 2 %
Fragmentation de fichiers = 5 %
Fragmentation de l'espace libre = 0 %
Fragmentation de fichiers
Total de fichiers = 118 626
Taille moyenne de fichier = 285 Ko
Total de fichiers fragmentés = 34
Total de fragments en trop = 478
Nombre moyen de fragments par fichier = 1,00
Fragmentation du fichier paginé
Taille du fichier paginé = 1,13 Go
Total de fragments = 2
Fragmentation de dossier
Total de dossiers = 9 775
Dossiers fragmentés = 1
Fragments de dossiers en trop = 0
Fragmentation de la table de fichiers principale (MFT)
Taille totale de la MFT = 251 Mo
Nombre d'enregistrements dans la MFT = 128 956
Pourcentage d'utilisation de la MFT = 50 %
Total de fragments dans la MFT = 3
--------------------------------------------------------------------------------
Fragments Taille du fichierFichiers les plus fragmentés
21 1 Ko \Documents and Settings\Jerem\ntuser.dat.LOG
10 422 Ko \WINDOWS1\Prefetch\Layout.ini
7 160 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Microsoft\Messenger\o_head_in_stars_o@hotmail.fr\SharingMetadata\Logs\Dfsr00005.log
4 63 Ko \WINDOWS1\system32\wbem\Logs\wbemess.log
4 1 Mo \WINDOWS1\WindowsUpdate.log
4 1 Mo \Documents and Settings\Jerem\Local Settings\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\Cache\_CACHE_001_
4 142 Ko \Documents and Settings\Jerem\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\history.dat
4 31 Ko \Documents and Settings\Jerem\Local Settings\Temporary Internet Files\Content.IE5\J7OKSF17\MsgrConfig[1].xml
3 92 Ko \WINDOWS1\Debug\UserMode\userenv.log
3 21 Ko \Documents and Settings\Jerem\Local Settings\Temporary Internet Files\Content.IE5\BG9RC23R\MDRAwards_Gad_Dany_234x60[1].swf
3 25 Ko \Documents and Settings\Jerem\Local Settings\Temporary Internet Files\Content.IE5\J7OKSF17\23460_002[1].swf
3 27 Ko \Documents and Settings\Jerem\Local Settings\Temporary Internet Files\Content.IE5\D5AVS86K\ebay[1].png
2 1 Ko \WINDOWS1\system32\config\software.LOG
2 12 Ko \Documents and Settings\Jerem\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\cookies.txt
2 31 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\Cache\69BF3C50d01
2 128 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Microsoft\Messenger\o_head_in_stars_o@hotmail.fr\SharingMetadata\Working\database_6200_CD5E_CD_39B5\tmp.edb
2 27 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\Cache\F0429502d01
2 19 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\Cache\D40BB790d01
2 47 Ko \WINDOWS1\SoftwareDistribution\SelfUpdate\Default\wsus3setup.cat
2 1 Ko \WINDOWS1\system32\config\SECURITY.LOG
2 16 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Microsoft\Messenger\o_head_in_stars_o@hotmail.fr\SharingMetadata\Logs\Dfsr00004.log.gz
2 1 Ko \WINDOWS1\system32\config\SAM.LOG
2 6 Ko \Documents and Settings\Jerem\Application Data\Mozilla\Firefox\Profiles\6ucpcrkg.default\localstore.rdf
2 64 Ko \WINDOWS1\SoftwareDistribution\DataStore\Logs\tmp.edb
2 5 Ko \Documents and Settings\Jerem\Application Data\Mozilla\Firefox\pluginreg.dat
2 8 Ko \Documents and Settings\All Users.WINDOWS1\Application Data\Avira\AntiVir PersonalEdition Classic\LOGFILES\Upd-2008-05-12-11-01-32.log
2 24 Ko \Documents and Settings\All Users.WINDOWS1\Application Data\Avira\AntiVir PersonalEdition Classic\LOGFILES\avguard.log
2 4 Ko \Documents and Settings\All Users.WINDOWS1\Application Data\Avira\AntiVir PersonalEdition Classic\LOGFILES\sched.log
2 1 Ko \Documents and Settings\Jerem\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
Ok apres avoir fait tu fais:
*Allez sur le poste de travail
*Cliquez sur disque C:\ (c'est le disque ou se trouve votre système d'exploitation)
*Ensuite cliquez sur le dossier Windows C:\Windows
*ouvrez le dossier prefetch C:\Windows\prefetch (Tu fais Edition,Selectionner tout, puis avec ton clavier tu cliques sur Sppr)
*Supprimez tous les fichiers de ce dossier.
*Puis vide la corbeille.
VOILA MAINTENANT TOUT EST FINI TON PC EST CLEANE ET RAPIDE. GARDE QUE ANTIVIRUS,MALWAREBYTES ET CCLEANER.
*Allez sur le poste de travail
*Cliquez sur disque C:\ (c'est le disque ou se trouve votre système d'exploitation)
*Ensuite cliquez sur le dossier Windows C:\Windows
*ouvrez le dossier prefetch C:\Windows\prefetch (Tu fais Edition,Selectionner tout, puis avec ton clavier tu cliques sur Sppr)
*Supprimez tous les fichiers de ce dossier.
*Puis vide la corbeille.
VOILA MAINTENANT TOUT EST FINI TON PC EST CLEANE ET RAPIDE. GARDE QUE ANTIVIRUS,MALWAREBYTES ET CCLEANER.