Trojan?(rapport antivir,hijackthis,navipromo)
toietmoipourtjs
Messages postés
28
Statut
Membre
-
toietmoipourtjs Messages postés 28 Statut Membre -
toietmoipourtjs Messages postés 28 Statut Membre -
Bonjour,
J' ai eu pas mal d'erreurs cette semaine du style "Firefox ne répond pas...", erreur explorer, pc plante,ect...Pourtant pas moyen de trouver le/les fameux virus/trojan/......
Donc voila je m'en remet à vous.....
HiJackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:48:07, on 26/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
c:\program files\avira\antivir desktop\avcenter.exe
C:\Documents and Settings\Valentin\Bureau\hijackthis-2.0.2.75917.exe
C:\DOCUME~1\Valentin\LOCALS~1\Temp\hijackthis-2.0.2.75917.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ED292990-ADCC-451C-978D-70979CE510FF}: NameServer = 193.74.208.135,194.119.228.67
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF184789-5ACB-4190-A533-5F836178973B}: NameServer = 193.74.208.135,194.119.228.67
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O20 - AppInit_DLLs:
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LVSrvLauncher - Labtec Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 7790 bytes
+-+--+-+-++-*+-*+-*+*-+-+-*+-*+-*+-*+-*+-*+-*+-*+-*+-*+-*
------------------------------------------------------------------------------------------
Avira AntiVir Personal
Report file date: mardi 26 janvier 2010 07:43
Scanning for 1640913 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : ACER-4DD805585B
Version information:
BUILD.DAT : 9.0.0.418 21723 Bytes 02/12/2009 16:28:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 19/11/2009 17:18:17
AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 09:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 09:58:52
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 17:18:17
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 17:16:15
VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 16:49:09
VBASE003.VDF : 7.10.3.2 2048 Bytes 20/01/2010 16:49:09
VBASE004.VDF : 7.10.3.3 2048 Bytes 20/01/2010 16:49:10
VBASE005.VDF : 7.10.3.4 2048 Bytes 20/01/2010 16:49:10
VBASE006.VDF : 7.10.3.5 2048 Bytes 20/01/2010 16:49:10
VBASE007.VDF : 7.10.3.6 2048 Bytes 20/01/2010 16:49:10
VBASE008.VDF : 7.10.3.7 2048 Bytes 20/01/2010 16:49:10
VBASE009.VDF : 7.10.3.8 2048 Bytes 20/01/2010 16:49:10
VBASE010.VDF : 7.10.3.9 2048 Bytes 20/01/2010 16:49:11
VBASE011.VDF : 7.10.3.10 2048 Bytes 20/01/2010 16:49:11
VBASE012.VDF : 7.10.3.11 2048 Bytes 20/01/2010 16:49:11
VBASE013.VDF : 7.10.3.12 2048 Bytes 20/01/2010 16:49:12
VBASE014.VDF : 7.10.3.45 173568 Bytes 22/01/2010 16:19:54
VBASE015.VDF : 7.10.3.46 2048 Bytes 22/01/2010 16:19:55
VBASE016.VDF : 7.10.3.47 2048 Bytes 22/01/2010 16:19:55
VBASE017.VDF : 7.10.3.48 2048 Bytes 22/01/2010 16:19:55
VBASE018.VDF : 7.10.3.49 2048 Bytes 22/01/2010 16:19:55
VBASE019.VDF : 7.10.3.50 2048 Bytes 22/01/2010 16:19:55
VBASE020.VDF : 7.10.3.51 2048 Bytes 22/01/2010 16:19:55
VBASE021.VDF : 7.10.3.52 2048 Bytes 22/01/2010 16:19:55
VBASE022.VDF : 7.10.3.53 2048 Bytes 22/01/2010 16:19:55
VBASE023.VDF : 7.10.3.54 2048 Bytes 22/01/2010 16:19:55
VBASE024.VDF : 7.10.3.55 2048 Bytes 22/01/2010 16:19:55
VBASE025.VDF : 7.10.3.56 2048 Bytes 22/01/2010 16:19:55
VBASE026.VDF : 7.10.3.57 2048 Bytes 22/01/2010 16:19:55
VBASE027.VDF : 7.10.3.58 2048 Bytes 22/01/2010 16:19:55
VBASE028.VDF : 7.10.3.59 2048 Bytes 22/01/2010 16:19:55
VBASE029.VDF : 7.10.3.60 2048 Bytes 22/01/2010 16:19:55
VBASE030.VDF : 7.10.3.61 2048 Bytes 22/01/2010 16:19:56
VBASE031.VDF : 7.10.3.67 131584 Bytes 25/01/2010 16:17:27
Engineversion : 8.2.1.150
AEVDF.DLL : 8.1.1.3 106868 Bytes 23/01/2010 16:19:59
AESCRIPT.DLL : 8.1.3.12 823675 Bytes 23/01/2010 16:19:59
AESCN.DLL : 8.1.3.1 127348 Bytes 17/01/2010 12:07:47
AESBX.DLL : 8.1.1.1 246132 Bytes 19/11/2009 17:18:17
AERDL.DLL : 8.1.3.4 479605 Bytes 02/12/2009 11:53:39
AEPACK.DLL : 8.2.0.5 422262 Bytes 17/01/2010 12:07:47
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 26/06/2009 07:56:27
AEHEUR.DLL : 8.1.0.195 2232695 Bytes 17/01/2010 12:07:46
AEHELP.DLL : 8.1.10.0 237942 Bytes 17/01/2010 12:07:43
AEGEN.DLL : 8.1.1.83 369014 Bytes 05/01/2010 15:39:09
AEEMU.DLL : 8.1.1.0 393587 Bytes 04/10/2009 01:14:36
AECORE.DLL : 8.1.9.5 184693 Bytes 17/01/2010 12:07:43
AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 08/09/2009 15:01:17
AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 09:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 09:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/05/2009 14:39:58
RCTEXT.DLL : 9.0.73.0 86785 Bytes 19/11/2009 17:18:15
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+SPR,
Start of the scan: mardi 26 janvier 2010 07:43
Starting search for hidden objects.
'51528' objects were checked, '0' hidden objects were found.
The scan of running processes will be started
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'dwwin.exe' - '1' Module(s) have been scanned
Scan process 'dumprep.exe' - '1' Module(s) have been scanned
Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
Scan process 'dllhost.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'CCC.exe' - '1' Module(s) have been scanned
Scan process 'MOM.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
35 processes with 35 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Master boot sector HD3
[INFO] No virus was found!
Master boot sector HD4
[INFO] No virus was found!
Master boot sector HD5
[INFO] No virus was found!
Master boot sector HD6
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '62' files ).
Starting the file scan:
Begin scan in 'C:\' <ACER>
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\'
D:\VeohWebPlayerSetup_eng.exe
[0] Archive type: NSIS
--> ProgramFilesDir/init.js
[DETECTION] Contains suspicious code HEUR/HTML.Malware
D:\Jeux\Fuel\FUEL_CLONEDVD-PLATiN.part20.rar
[0] Archive type: RAR
--> FUEL_CLONEDVD-PLATiN\ptn-fuel.079
[1] Archive type: RAR
--> ptn-fuel.mds
[WARNING] No further files can be extracted from this archive. The archive will be closed
Beginning disinfection:
D:\VeohWebPlayerSetup_eng.exe
[NOTE] The file was moved to '4bce05f7.qua'!
End of the scan: mardi 26 janvier 2010 16:09
Used time: 1:02:31 Hour(s)
The scan has been done completely.
12848 Scanned directories
446905 Files were scanned
0 Viruses and/or unwanted programs were found
1 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
3 Files cannot be scanned
446901 Files not concerned
9490 Archives were scanned
4 Warnings
3 Notes
51528 Objects were scanned with rootkit scan
0 Hidden objects were found
-*-*-*-*-*-*********************+*+-*+-*+-*
-+-+-+-*-*+-*+-*+*-+*-+-+*-+*++*-+++-+*+*+*-
Dernier trojan trouvé(Antivir):
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\Program Files\Steam\steamapps\t***********\counter-strike\valve\cl_dlls\particleman.dll.
Action performed: Deny access
+-*-+*-*+-*+-*+*+-*+-*+*+-*+-*+-*+*+-*+*+*+-*-++*-+*-+*-+*-+*-
-------------------------------------------------------------------------------------
Fix Navipromo version 4.0.6 commencé le mar. 26/01/2010 18:35:28,59
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 03.01.2010 à 11h00 par IL-MAFIOSO
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Valentin ( Administrator )
BOOT : Normal boot
Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
Firewall : COMODO Firewall Pro 3.0 (Activated)
C:\ (Local Disk) - NTFS - Total:298 Go (Free:205 Go)
D:\ (Local Disk) - NTFS - Total:298 Go (Free:231 Go)
E:\ (CD or DVD)
F:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
L:\ (CD or DVD)
N:\ (USB) - FAT32 - Total:7654 Mo (Free:4 Go)
Recherche executée en mode normal
Nettoyage exécuté au redémarrage de l'ordinateur
C:\WINDOWS\prefetch\GAMEOVERLAYUI.EXE-1A46F21E.pf supprimé !
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Valentin\locals~1\Temp effectué !
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Scan terminé mar. 26/01/2010 18:38:25,04 ***
+-+-+-+-+--++++++++-+-+-+-+--+-+-++--+-++--++-+-+-+--++--+
*-+++++++++++++++-+*+-*-*-*****************************
Je suis entrain de faire un scan http://www.eset-nod32.fr, j'ai déjà passe spybot et SpywareTerminator
Voila, si je n'ai pas été assez complet, veuillez m'indiquer ce que je peux faire d'autre.....
Merci de toute aide.
J' ai eu pas mal d'erreurs cette semaine du style "Firefox ne répond pas...", erreur explorer, pc plante,ect...Pourtant pas moyen de trouver le/les fameux virus/trojan/......
Donc voila je m'en remet à vous.....
HiJackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:48:07, on 26/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
c:\program files\avira\antivir desktop\avcenter.exe
C:\Documents and Settings\Valentin\Bureau\hijackthis-2.0.2.75917.exe
C:\DOCUME~1\Valentin\LOCALS~1\Temp\hijackthis-2.0.2.75917.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ED292990-ADCC-451C-978D-70979CE510FF}: NameServer = 193.74.208.135,194.119.228.67
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF184789-5ACB-4190-A533-5F836178973B}: NameServer = 193.74.208.135,194.119.228.67
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O20 - AppInit_DLLs:
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LVSrvLauncher - Labtec Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 7790 bytes
+-+--+-+-++-*+-*+-*+*-+-+-*+-*+-*+-*+-*+-*+-*+-*+-*+-*+-*
------------------------------------------------------------------------------------------
Avira AntiVir Personal
Report file date: mardi 26 janvier 2010 07:43
Scanning for 1640913 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : ACER-4DD805585B
Version information:
BUILD.DAT : 9.0.0.418 21723 Bytes 02/12/2009 16:28:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 19/11/2009 17:18:17
AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 09:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 09:58:52
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 17:18:17
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 17:16:15
VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 16:49:09
VBASE003.VDF : 7.10.3.2 2048 Bytes 20/01/2010 16:49:09
VBASE004.VDF : 7.10.3.3 2048 Bytes 20/01/2010 16:49:10
VBASE005.VDF : 7.10.3.4 2048 Bytes 20/01/2010 16:49:10
VBASE006.VDF : 7.10.3.5 2048 Bytes 20/01/2010 16:49:10
VBASE007.VDF : 7.10.3.6 2048 Bytes 20/01/2010 16:49:10
VBASE008.VDF : 7.10.3.7 2048 Bytes 20/01/2010 16:49:10
VBASE009.VDF : 7.10.3.8 2048 Bytes 20/01/2010 16:49:10
VBASE010.VDF : 7.10.3.9 2048 Bytes 20/01/2010 16:49:11
VBASE011.VDF : 7.10.3.10 2048 Bytes 20/01/2010 16:49:11
VBASE012.VDF : 7.10.3.11 2048 Bytes 20/01/2010 16:49:11
VBASE013.VDF : 7.10.3.12 2048 Bytes 20/01/2010 16:49:12
VBASE014.VDF : 7.10.3.45 173568 Bytes 22/01/2010 16:19:54
VBASE015.VDF : 7.10.3.46 2048 Bytes 22/01/2010 16:19:55
VBASE016.VDF : 7.10.3.47 2048 Bytes 22/01/2010 16:19:55
VBASE017.VDF : 7.10.3.48 2048 Bytes 22/01/2010 16:19:55
VBASE018.VDF : 7.10.3.49 2048 Bytes 22/01/2010 16:19:55
VBASE019.VDF : 7.10.3.50 2048 Bytes 22/01/2010 16:19:55
VBASE020.VDF : 7.10.3.51 2048 Bytes 22/01/2010 16:19:55
VBASE021.VDF : 7.10.3.52 2048 Bytes 22/01/2010 16:19:55
VBASE022.VDF : 7.10.3.53 2048 Bytes 22/01/2010 16:19:55
VBASE023.VDF : 7.10.3.54 2048 Bytes 22/01/2010 16:19:55
VBASE024.VDF : 7.10.3.55 2048 Bytes 22/01/2010 16:19:55
VBASE025.VDF : 7.10.3.56 2048 Bytes 22/01/2010 16:19:55
VBASE026.VDF : 7.10.3.57 2048 Bytes 22/01/2010 16:19:55
VBASE027.VDF : 7.10.3.58 2048 Bytes 22/01/2010 16:19:55
VBASE028.VDF : 7.10.3.59 2048 Bytes 22/01/2010 16:19:55
VBASE029.VDF : 7.10.3.60 2048 Bytes 22/01/2010 16:19:55
VBASE030.VDF : 7.10.3.61 2048 Bytes 22/01/2010 16:19:56
VBASE031.VDF : 7.10.3.67 131584 Bytes 25/01/2010 16:17:27
Engineversion : 8.2.1.150
AEVDF.DLL : 8.1.1.3 106868 Bytes 23/01/2010 16:19:59
AESCRIPT.DLL : 8.1.3.12 823675 Bytes 23/01/2010 16:19:59
AESCN.DLL : 8.1.3.1 127348 Bytes 17/01/2010 12:07:47
AESBX.DLL : 8.1.1.1 246132 Bytes 19/11/2009 17:18:17
AERDL.DLL : 8.1.3.4 479605 Bytes 02/12/2009 11:53:39
AEPACK.DLL : 8.2.0.5 422262 Bytes 17/01/2010 12:07:47
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 26/06/2009 07:56:27
AEHEUR.DLL : 8.1.0.195 2232695 Bytes 17/01/2010 12:07:46
AEHELP.DLL : 8.1.10.0 237942 Bytes 17/01/2010 12:07:43
AEGEN.DLL : 8.1.1.83 369014 Bytes 05/01/2010 15:39:09
AEEMU.DLL : 8.1.1.0 393587 Bytes 04/10/2009 01:14:36
AECORE.DLL : 8.1.9.5 184693 Bytes 17/01/2010 12:07:43
AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 08/09/2009 15:01:17
AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 09:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 09:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/05/2009 14:39:58
RCTEXT.DLL : 9.0.73.0 86785 Bytes 19/11/2009 17:18:15
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+SPR,
Start of the scan: mardi 26 janvier 2010 07:43
Starting search for hidden objects.
'51528' objects were checked, '0' hidden objects were found.
The scan of running processes will be started
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'dwwin.exe' - '1' Module(s) have been scanned
Scan process 'dumprep.exe' - '1' Module(s) have been scanned
Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
Scan process 'dllhost.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'CCC.exe' - '1' Module(s) have been scanned
Scan process 'MOM.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
35 processes with 35 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Master boot sector HD3
[INFO] No virus was found!
Master boot sector HD4
[INFO] No virus was found!
Master boot sector HD5
[INFO] No virus was found!
Master boot sector HD6
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '62' files ).
Starting the file scan:
Begin scan in 'C:\' <ACER>
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\'
D:\VeohWebPlayerSetup_eng.exe
[0] Archive type: NSIS
--> ProgramFilesDir/init.js
[DETECTION] Contains suspicious code HEUR/HTML.Malware
D:\Jeux\Fuel\FUEL_CLONEDVD-PLATiN.part20.rar
[0] Archive type: RAR
--> FUEL_CLONEDVD-PLATiN\ptn-fuel.079
[1] Archive type: RAR
--> ptn-fuel.mds
[WARNING] No further files can be extracted from this archive. The archive will be closed
Beginning disinfection:
D:\VeohWebPlayerSetup_eng.exe
[NOTE] The file was moved to '4bce05f7.qua'!
End of the scan: mardi 26 janvier 2010 16:09
Used time: 1:02:31 Hour(s)
The scan has been done completely.
12848 Scanned directories
446905 Files were scanned
0 Viruses and/or unwanted programs were found
1 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
3 Files cannot be scanned
446901 Files not concerned
9490 Archives were scanned
4 Warnings
3 Notes
51528 Objects were scanned with rootkit scan
0 Hidden objects were found
-*-*-*-*-*-*********************+*+-*+-*+-*
-+-+-+-*-*+-*+-*+*-+*-+-+*-+*++*-+++-+*+*+*-
Dernier trojan trouvé(Antivir):
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\Program Files\Steam\steamapps\t***********\counter-strike\valve\cl_dlls\particleman.dll.
Action performed: Deny access
+-*-+*-*+-*+-*+*+-*+-*+*+-*+-*+-*+*+-*+*+*+-*-++*-+*-+*-+*-+*-
-------------------------------------------------------------------------------------
Fix Navipromo version 4.0.6 commencé le mar. 26/01/2010 18:35:28,59
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 03.01.2010 à 11h00 par IL-MAFIOSO
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Valentin ( Administrator )
BOOT : Normal boot
Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
Firewall : COMODO Firewall Pro 3.0 (Activated)
C:\ (Local Disk) - NTFS - Total:298 Go (Free:205 Go)
D:\ (Local Disk) - NTFS - Total:298 Go (Free:231 Go)
E:\ (CD or DVD)
F:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
L:\ (CD or DVD)
N:\ (USB) - FAT32 - Total:7654 Mo (Free:4 Go)
Recherche executée en mode normal
Nettoyage exécuté au redémarrage de l'ordinateur
C:\WINDOWS\prefetch\GAMEOVERLAYUI.EXE-1A46F21E.pf supprimé !
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Valentin\locals~1\Temp effectué !
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Scan terminé mar. 26/01/2010 18:38:25,04 ***
+-+-+-+-+--++++++++-+-+-+-+--+-+-++--+-++--++-+-+-+--++--+
*-+++++++++++++++-+*+-*-*-*****************************
Je suis entrain de faire un scan http://www.eset-nod32.fr, j'ai déjà passe spybot et SpywareTerminator
Voila, si je n'ai pas été assez complet, veuillez m'indiquer ce que je peux faire d'autre.....
Merci de toute aide.
Configuration: Windows XP Firefox 3.5.7
A voir également:
- Trojan?(rapport antivir,hijackthis,navipromo)
- Hijackthis - Télécharger - Antivirus & Antimalwares
- Rapport de stage - Guide
- Antivir - Télécharger - Antivirus & Antimalwares
- Rapport de crash windows - Guide
- Trojan sms-par google ✓ - Forum Virus
2 réponses
Lors de mon scan j'ai eu ces alertes:
Exported events:
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP238\A0066895.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP237\A0066832.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP237\A0066799.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP236\A0066665.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP236\A0066583.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP234\A0066463.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP233\A0066415.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP232\A0066371.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP232\A0066300.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP231\A0066219.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP230\A0066143.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP229\A0066078.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP229\A0066025.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP228\A0065981.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP228\A0064985.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP228\A0064922.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP227\A0064901.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP225\A0064741.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP225\A0064676.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP224\A0064636.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP223\A0064513.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP222\A0064426.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP222\A0063369.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP221\A0063265.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0063189.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0063133.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0063077.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0062079.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0061094.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0061017.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP219\A0060948.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP214\A0060766.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP214\A0059694.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP213\A0059648.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP213\A0059598.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP212\A0059532.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP211\A0058448.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP210\A0058400.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP209\A0058349.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP208\A0058320.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP208\A0058265.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP207\A0058236.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP207\A0058160.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP206\A0058129.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP205\A0058061.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP205\A0058022.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP204\A0057991.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP203\A0057933.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP201\A0057802.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP201\A0057676.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP200\A0057646.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP199\A0057546.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP198\A0057515.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP198\A0057448.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP197\A0057321.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP196\A0057256.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP195\A0057161.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP194\A0057072.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP193\A0057006.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP193\A0056970.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP192\A0056921.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP191\A0056877.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP190\A0056812.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP190\A0056775.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP189\A0056748.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP188\A0056699.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP188\A0056643.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP187\A0056607.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP187\A0056535.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP186\A0056485.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP186\A0056418.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP185\A0056309.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP184\A0056240.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP182\A0056140.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP180\A0056089.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP180\A0056011.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP179\A0055975.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP178\A0055878.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP177\A0055804.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP176\A0055737.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP176\A0055708.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP175\A0055656.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP174\A0055612.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP173\A0055539.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP172\A0055474.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP172\A0055433.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP171\A0055351.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP170\A0055269.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP169\A0054809.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP168\A0054728.dll.
Action performed: Move file to quarantine
26/01/2010 19:13 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP168\A0054666.dll.
Action performed: Move file to quarantine
26/01/2010 19:13 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP167\A0054555.dll.
Action performed: Move file to quarantine
26/01/2010 19:13 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP166\A0054473.dll.
Action performed: Move file to quarantine
26/01/2010 18:33 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\Program
Files\Steam\steamapps\toi*******\counter-strike\valve\cl_dlls\particleman.d
ll.
Action performed: Deny access
26/01/2010 18:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\Program
Files\Steam\steamapps\toi********\counter-strike\valve\cl_dlls\particleman.d
ll.
Action performed: Delete file
26/01/2010 17:40 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\Program
Files\Steam\steamapps\toi********\counter-strike\valve\cl_dlls\particleman.d
ll.
Action performed: Delete file
26/01/2010 16:09 [Scanner] Malware found
The file 'D:\VeohWebPlayerSetup_eng.exe'
contained a virus or unwanted program 'HEUR/HTML.Malware' [heuristic]
Action(s) taken:
The file was moved to '4bce05f7.qua'!
Exported events:
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP238\A0066895.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP237\A0066832.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP237\A0066799.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP236\A0066665.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP236\A0066583.dll.
Action performed: Move file to quarantine
26/01/2010 19:22 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP234\A0066463.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP233\A0066415.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP232\A0066371.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP232\A0066300.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP231\A0066219.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP230\A0066143.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP229\A0066078.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP229\A0066025.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP228\A0065981.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP228\A0064985.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP228\A0064922.dll.
Action performed: Move file to quarantine
26/01/2010 19:21 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP227\A0064901.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP225\A0064741.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP225\A0064676.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP224\A0064636.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP223\A0064513.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP222\A0064426.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP222\A0063369.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP221\A0063265.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0063189.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0063133.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0063077.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0062079.dll.
Action performed: Move file to quarantine
26/01/2010 19:20 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0061094.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP220\A0061017.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP219\A0060948.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP214\A0060766.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP214\A0059694.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP213\A0059648.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP213\A0059598.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP212\A0059532.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP211\A0058448.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP210\A0058400.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP209\A0058349.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP208\A0058320.dll.
Action performed: Move file to quarantine
26/01/2010 19:19 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP208\A0058265.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP207\A0058236.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP207\A0058160.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP206\A0058129.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP205\A0058061.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP205\A0058022.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP204\A0057991.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP203\A0057933.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP201\A0057802.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP201\A0057676.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP200\A0057646.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP199\A0057546.dll.
Action performed: Move file to quarantine
26/01/2010 19:18 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP198\A0057515.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP198\A0057448.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP197\A0057321.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP196\A0057256.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP195\A0057161.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP194\A0057072.dll.
Action performed: Move file to quarantine
26/01/2010 19:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP193\A0057006.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP193\A0056970.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP192\A0056921.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP191\A0056877.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP190\A0056812.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP190\A0056775.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP189\A0056748.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP188\A0056699.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP188\A0056643.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP187\A0056607.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP187\A0056535.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP186\A0056485.dll.
Action performed: Move file to quarantine
26/01/2010 19:16 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP186\A0056418.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP185\A0056309.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP184\A0056240.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP182\A0056140.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP180\A0056089.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP180\A0056011.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP179\A0055975.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP178\A0055878.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP177\A0055804.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP176\A0055737.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP176\A0055708.dll.
Action performed: Move file to quarantine
26/01/2010 19:15 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP175\A0055656.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP174\A0055612.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP173\A0055539.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP172\A0055474.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP172\A0055433.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP171\A0055351.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP170\A0055269.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP169\A0054809.dll.
Action performed: Move file to quarantine
26/01/2010 19:14 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP168\A0054728.dll.
Action performed: Move file to quarantine
26/01/2010 19:13 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP168\A0054666.dll.
Action performed: Move file to quarantine
26/01/2010 19:13 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP167\A0054555.dll.
Action performed: Move file to quarantine
26/01/2010 19:13 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\System Volume
Information\_restore{751C4CC0-A799-44C7-AD97-CF9B1E4CA326}\RP166\A0054473.dll.
Action performed: Move file to quarantine
26/01/2010 18:33 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\Program
Files\Steam\steamapps\toi*******\counter-strike\valve\cl_dlls\particleman.d
ll.
Action performed: Deny access
26/01/2010 18:17 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\Program
Files\Steam\steamapps\toi********\counter-strike\valve\cl_dlls\particleman.d
ll.
Action performed: Delete file
26/01/2010 17:40 [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Agent.81920.J [trojan]'
detected in file 'C:\Program
Files\Steam\steamapps\toi********\counter-strike\valve\cl_dlls\particleman.d
ll.
Action performed: Delete file
26/01/2010 16:09 [Scanner] Malware found
The file 'D:\VeohWebPlayerSetup_eng.exe'
contained a virus or unwanted program 'HEUR/HTML.Malware' [heuristic]
Action(s) taken:
The file was moved to '4bce05f7.qua'!