Accès au Site
 FAQFAQ   RechercherCharte   RechercherRechercher   MembresMembres   UtilisateursUtilisateurs   S'enregistrerS'enregistrer   ProfilProfil   Vérifier ses messages privésVérifier ses messages privés   ConnexionConnexion
 
infection

 
Répondre au sujet Le site -> Assiste PC Index du Forum -> Désinfection des virus & analyses de logs HijackThisCréer un flux RSS 2.0
Auteur Message
steeve
Newbie
Newbie


Inscrit le: 29 Fév 2008
Message(s): 2

MessagePosté le: 29 Fév 2008 16:57    Sujet du message: infection Répondre en citant

Citation:
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 15:43:27 29/02/2008

+ Résultat de l'analyse:



:mozilla.61:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.60:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.15:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.37:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.38:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.39:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.26:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.27:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.28:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.29:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.18:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.19:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.20:C:\Documents and Settings\STEEVE&MARGOT\Application Data\Mozilla\Firefox\Profiles\jjsa3qp6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.


Fin du rapport

Revenir en haut de page
Voir le profil de l'utilisateur Envoyer un message privé Envoyer un e-mail
jjcojax
Helper
Helper


Inscrit le: 18 Juin 2006
Message(s): 263
Localisation: Belgique

MessagePosté le: 29 Fév 2008 21:24    Sujet du message: Répondre en citant

Bonsoir,

Ton message est formidable Pas sûr


Comme tu n'as pas mis la moindre explication, on ne sait pas si tu as un problème, ni si c'est Windows 98, 2000, XP ou vista.

Pour ce que tu montres, c'est quelques cookies qui sont inoffensives! (des traces d'avoir visité un site)


Voilà
Revenir en haut de page
Voir le profil de l'utilisateur Envoyer un message privé Envoyer un e-mail
jjcojax
Helper
Helper


Inscrit le: 18 Juin 2006
Message(s): 263
Localisation: Belgique

MessagePosté le: 02 Mar 2008 0:36    Sujet du message: Répondre en citant

Bonsoir,

Je recolle ton message ici puisqu'un forum permet parfois à ceux qui on le même problème de se dépanner

Citation:
Message qui vous a été envoyé:
~~~~~~~~~~~~~~~~~~~~~~~~~~~

Bonjour jjcojax,

Excuse moi pour les formule de politesse. En fait vu que c'étais ma première visite, je ne savais pas trop comment faire.

voici mon problème, depuis plusieurs jour je n'arrive plus à acceder par double clique à mes disque depuis mon poste de travail. il me renvoie à une fenêtre "Ouvrir avec". Quelqu'un saurait-il quoi faire?


Merci et bon weekend à toi!!



Logiquement, tu ouvres un disque avec explorer (il fait partie des programmes), mais cela devrais se faire tout seul.

Essaye si ce n'est pas mieux via un démarrage en mode sans échec.
Essaye de créer un autre utilisateur pour voir si c'est pareil avec un autre utilisateur.

Ce qui peut remettre ton système en ordre, c'est d'utiliser la restauration du système à une date ou tout fonctionnais, (tu dois simplement cliquer sur une date affichée en gras)

-> tu as cette fonction dans outil systèmes ou tu cliques c:\Windows\system32\Restore\rstrui.exe ( mode sans échec si nécessaire)

Bonne chance et fait savoir ce qui fonctionne (et 2000, XP, ou vista ?)

Content
Revenir en haut de page
Voir le profil de l'utilisateur Envoyer un message privé Envoyer un e-mail
steeve
Newbie
Newbie


Inscrit le: 29 Fév 2008
Message(s): 2

MessagePosté le: 05 Mar 2008 20:37    Sujet du message: Répondre en citant

Salut à tous,

voici ci dessous le rapport après un scan complet de mon ordinateur avec activir. j'aimerais savoir comment supprimer plus facilement les virus.
merci d'avance!!

Citation:


AntiVir PersonalEdition Classic
Report file date: mercredi 5 mars 2008 06:59

Scanning for 1132684 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: SYSTEM
Computer name: TONJONKO-DF5D23

Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 23:09:15
ANTIVIR2.VDF : 7.0.2.181 1993728 Bytes 24/02/2008 23:09:15
ANTIVIR3.VDF : 7.0.2.231 167424 Bytes 04/03/2008 23:02:34
AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 03/03/2008 23:09:15
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 03/03/2008 23:09:15
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: E:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: mercredi 5 mars 2008 06:59

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'soffice.bin' - '1' Module(s) have been scanned
Scan process 'soffice.exe' - '1' Module(s) have been scanned
Scan process 'BlueSoleil.exe' - '1' Module(s) have been scanned
Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
Scan process 'WMP54GSv1_1.exe' - '1' Module(s) have been scanned
Scan process 'WLService.exe' - '1' Module(s) have been scanned
Scan process 'SuperCopier2.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'StarWindService.exe' - '1' Module(s) have been scanned
Scan process 'zlclient.exe' - '0' Module(s) have been scanned
Scan process 'opwareSE2.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'BTNtService.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'vsmon.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
37 processes with 37 modules were scanned

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Boot sector 'E:\'
[NOTE] No virus was found!

Starting to scan the registry.
The registry was scanned ( '37' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\'
D:\Program Files\WinTV\Relnotes.htm
[DETECTION] Contains detection pattern of the HTML script virus HTML/Dldr.Iframe.K
[INFO] The file was moved to '483a46b9.qua'!
D:\RECYCLER\S-1-5-21-57989841-261478967-839522115-500\Dd44.5-win\manual.html
[DETECTION] Contains detection pattern of the HTML script virus HTML/Dldr.Iframe.K
[INFO] The file was moved to '483c475e.qua'!
D:\RECYCLER\S-1-5-21-57989841-261478967-839522115-500\Dd45.5-win\manual.html
[DETECTION] Contains detection pattern of the HTML script virus HTML/Dldr.Iframe.K
[INFO] The file was moved to '483c475f.qua'!
D:\RECYCLER\S-1-5-21-57989841-261478967-839522115-500\Dd47\readme.htm
[DETECTION] Contains detection pattern of the HTML script virus HTML/Dldr.Iframe.K
[INFO] The file was moved to '482f4763.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000542.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4738.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000543.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4739.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000582.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe473a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000593.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe473b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000594.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1f4.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000606.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe473c.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000650.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe473e.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000652.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1f7.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000733.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4743.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000734.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c18c.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000747.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4744.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000751.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4745.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000758.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c18e.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000763.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4746.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000768.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c18f.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000775.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4747.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000787.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4748.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000788.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c181.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000819.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4749.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000822.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c182.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000843.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe474a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000913.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe474b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000925.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe474c.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000932.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c185.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0000937.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe474d.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001004.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe474f.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001005.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c198.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001008.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4750.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001010.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c199.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001019.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4751.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001021.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c19a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001026.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4753.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001029.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4752.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001044.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c19b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001046.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c19c.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001077.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4755.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001083.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4754.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001131.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c19e.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001135.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4756.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001141.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c19f.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001142.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4757.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001143.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c190.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001155.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4758.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001159.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c191.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001162.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4759.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001172.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c192.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001174.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe475a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001178.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c193.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001185.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe475c.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001232.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c195.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001251.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe475e.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001259.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c197.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001331.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4760.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001333.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1a9.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001338.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4761.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001339.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1aa.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001340.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4763.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001342.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4762.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001345.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1ab.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001346.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1ac.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001347.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4765.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001348.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1ae.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001349.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4767.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001356.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4764.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001357.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1ad.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001358.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1a0.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001359.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4769.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001449.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1a2.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001465.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe476b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001475.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1a4.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001476.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4768.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001477.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1a1.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001482.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe476a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0001726.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4770.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002134.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe477b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002135.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe477c.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002138.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1b5.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002148.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe477d.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002162.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c1b6.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002170.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe477e.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002177.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe477f.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002233.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4780.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002347.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4784.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002371.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4785.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002372.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c14e.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002387.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4786.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002394.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4787.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002398.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4788.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002401.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c141.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002410.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe478a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002481.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe478b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002508.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe478c.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002509.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c145.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002511.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe478d.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002512.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c146.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002531.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe478f.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002533.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c158.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002538.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4793.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002539.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4794.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002541.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c15d.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002543.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4795.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002546.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4796.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002548.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c15f.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002555.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe479a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002556.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c153.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002557.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe479c.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002560.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe479b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002562.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c154.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002564.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe479d.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002565.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c155.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002569.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe479e.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002572.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c157.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002576.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c156.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002583.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47a5.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002590.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47a7.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002591.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47a8.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002594.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c161.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002595.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47a9.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002596.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c162.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002597.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ab.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002598.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47aa.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002599.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c163.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002600.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c164.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002601.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ad.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002604.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c166.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002605.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ac.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002624.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47af.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP10\A0002650.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ae.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP12\A0002673.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47b0.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP13\A0003708.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47b2.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003717.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47b3.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003794.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47b6.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003809.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47b7.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003832.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47b8.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003834.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c171.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003835.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ba.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003836.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c173.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003857.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47b9.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003931.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47bc.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0003976.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47bd.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0004014.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47bf.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0004018.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47c0.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0004019.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c109.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0004022.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47c2.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0004030.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47c1.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0004031.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c10a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0004035.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c10b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP14\A0004041.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47c4.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP16\A0004091.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47c5.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP16\A0004092.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c10e.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP16\A0004106.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47c6.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP16\A0004110.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47c7.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP16\A0004145.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c100.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP18\A0004228.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ca.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP18\A0004305.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47cd.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP19\A0004310.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ce.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP19\A0004329.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47d0.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP19\A0004355.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c119.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP19\A0004357.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47d1.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP19\A0004358.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c11a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP19\A0004359.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47d3.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP19\A0004382.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47d2.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP19\A0004459.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47d4.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP19\A0004504.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47d5.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004532.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47d8.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004535.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c111.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004536.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47d9.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004541.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c112.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004542.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47da.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004543.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c113.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004544.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47dc.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004557.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47db.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004578.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c115.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004581.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47de.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004584.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47dd.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004596.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c116.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004599.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c117.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004603.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c11b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004606.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47df.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004608.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c128.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004609.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47e1.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004622.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47e0.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004623.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c129.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004626.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47e2.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP20\A0004643.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c12a.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP21\A0005646.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c12b.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP21\A0005650.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47e4.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005757.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47e7.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005760.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47e8.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005761.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c121.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005763.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ea.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005767.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47eb.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005769.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c124.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005794.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ec.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005795.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ed.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005797.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c126.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005798.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ee.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005799.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47ef.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0005811.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47f0.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0006858.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47f2.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0006895.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47f3.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0006903.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c13c.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0006928.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47f4.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0006934.EXE
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47f5.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0006935.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c13e.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0006937.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47f7.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0006951.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe47f6.qua'!
D:\System Volume Information\_restore{036DEB61-800B-4FB5-B602-D77B57B32250}\RP25\A0006993.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683c130.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP12\A0000495.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4948.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP13\A0000515.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4949.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP15\A0000566.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe494b.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP16\A0000608.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cf84.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP18\A0000631.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe494d.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP19\A0000679.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe494e.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000692.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4950.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000705.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4951.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000715.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cf9a.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000716.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4953.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000717.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4952.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000718.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cf9b.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000719.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4954.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000720.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cf9c.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000722.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4955.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000723.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cf9e.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000724.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cf9d.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000725.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4956.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP20\A0000726.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cf9f.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP21\A0000769.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4968.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP21\A0000788.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cfa1.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP21\A0000789.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4957.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP21\A0000790.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cf90.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP21\A0000795.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4959.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP21\A0000820.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe495a.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP22\A0000933.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe495c.qua'!
D:\System Volume Information\_restore{5AA6009A-9743-44EE-8398-84925D9E7988}\RP22\A0000936.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cf95.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0001926.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe495f.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0001928.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4960.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0001934.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4963.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0001935.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cfac.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0001936.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4964.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0002052.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4965.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0002190.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4966.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0002250.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cfaf.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0002253.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4967.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0002259.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cfa0.qua'!
D:\System Volume Information\_restore{7FE6C1B9-27F5-4AE1-B960-362B9D03EA92}\RP29\A0002261.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4969.qua'!
D:\System Volume Information\_restore{CD44C1A0-73CB-41CA-BE79-5044F16E4DC4}\RP176\A0049884.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe496b.qua'!
D:\System Volume Information\_restore{CD44C1A0-73CB-41CA-BE79-5044F16E4DC4}\RP176\A0049885.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '4683cfa4.qua'!
D:\System Volume Information\_restore{CD44C1A0-73CB-41CA-BE79-5044F16E4DC4}\RP176\A0060970.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe496f.qua'!
D:\System Volume Information\_restore{CD44C1A0-73CB-41CA-BE79-5044F16E4DC4}\RP176\A0060971.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4971.qua'!
D:\System Volume Information\_restore{CD44C1A0-73CB-41CA-BE79-5044F16E4DC4}\RP176\A0061135.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4973.qua'!
D:\System Volume Information\_restore{CD44C1A0-73CB-41CA-BE79-5044F16E4DC4}\RP176\A0061136.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe4976.qua'!
D:\System Volume Information\_restore{CD44C1A0-73CB-41CA-BE79-5044F16E4DC4}\RP177\A0065158.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
[INFO] The file was moved to '47fe497a.qua'!
D:\System Volume Information\_restore{CD44C1A0-73CB-41CA-BE79-5044F16E4DC4}\RP177\A0065159.exe
[DETECTION] Contains detection pattern of the Windows virus W32/Virut.AS
Revenir en haut de page
Voir le profil de l'utilisateur Envoyer un message privé Envoyer un e-mail
Angeldark
Equipe Sécurité
Equipe Sécurité


Inscrit le: 23 Mai 2007
Message(s): 113

MessagePosté le: 07 Mar 2008 13:50    Sujet du message: Répondre en citant

Bonjour,

Rien de méchant, côté virus.
Revenir en haut de page
Voir le profil de l'utilisateur Envoyer un message privé
toddernst
Newbie
Newbie


Inscrit le: 01 Avr 2008
Message(s): 1

MessagePosté le: 02 Avr 2008 22:39    Sujet du message: infection du fichier svchost Répondre en citant

Bonjour le fichier systeme svchost de ma machine a ete infecte j'ai utilisé l'utilitaire HijackThis pour faire une analyse pour moi. Voici ce que j'ai dans le fichier log

Logfile of HijackThis v1.99.1
Scan saved at 2:10:48 PM, on 4/2/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Apache Group\Apache2\bin\Apache.exe
D:\Alwil Software\Avast4\aswUpdSv.exe
D:\Alwil Software\Avast4\aswServ.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\llssrv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Internet Explorer\Custom\custom.exe
C:\Apache Group\Apache2\bin\Apache.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\locator.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\dns.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Broadcom\BACS\BacsTray.exe
D:\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\FarStone\VirtualDrive\VDTask.exe
D:\ALWILS~1\Avast4\aswDisp.exe
C:\exchsrvr\bin\mad.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\SpybotSearchDestroy\TeaTimer.exe
C:\WINNT\system32\ctfmon.exe
C:\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\exchsrvr\bin\events.exe
C:\exchsrvr\connect\msexcimc\bin\msexcimc.exe
C:\WINNT\System32\svchost.exe
D:\Alwil Software\Avast4\aswWebSv.exe
D:\Alwil Software\Avast4\aswMaiSv.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Administrator.GAMA-WTOLHI6QOL\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: TW_BHO Class - {1E1B2879-88FF-11D2-8D96-FFFFAC95951F} - D:\Perfect Keyboard PRO\mtwbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SpybotSearchDestroy\SDHelper.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [bacstray] C:\Program Files\Broadcom\BACS\BacsTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [VirtualDrive] "C:\Program Files\FarStone\VirtualDrive\VDTask.exe" /AutoRestore
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] D:\ALWILS~1\Avast4\aswDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\SpybotSearchDestroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SpybotSearchDestroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SpybotSearchDestroy\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178733629906
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gama.ht
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D30F543-A74A-4208-A41C-E1D1A42EC87B}: NameServer = 200.80.98.210
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gama.ht
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = gama.ht
O18 - Protocol: intu-res - {9CE7D474-16F9-4889-9BB9-53E2008EAE8A} - C:\Program Files\Common Files\Intuit\intu-res.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Apache2 - Unknown owner - C:\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Alwil Software\Avast4\aswServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Alwil Software\Avast4\aswMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Alwil Software\Avast4\aswWebSv.exe" /service (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: microsoft frontpage - Unknown owner - C:\Program Files\Internet Explorer\Custom\custom.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: PSEXESVC - Sysinternals - C:\WINNT\System32\PSEXESVC.EXE
O23 - Service: Remote - Unknown owner - C:\Documents.exe (file missing)
O23 - Service: ·þÎñÃû (svcname) - Unknown owner - C:\WINNT\system32\Down(0).exe (file missing)

Est-ce que quelq'un peut m'aider interpreter ces lignes S.V.P
Merci
Revenir en haut de page
Voir le profil de l'utilisateur Envoyer un message privé Envoyer un e-mail
Angeldark
Equipe Sécurité
Equipe Sécurité


Inscrit le: 23 Mai 2007
Message(s): 113

MessagePosté le: 03 Avr 2008 19:43    Sujet du message: Répondre en citant

Merci de créer ton propre sujet Smile
Revenir en haut de page
Voir le profil de l'utilisateur Envoyer un message privé
Publicité
Répondre au sujet Le site -> Assiste PC Index du Forum -> Désinfection des virus & analyses de logs HijackThis Toutes les heures sont au format GMT + 2 Heures
Page 1 sur 1

Navigation Autres sujets similaires

Sauter vers :
10 

 


Vous ne pouvez pas poster de nouveaux sujets dans ce forum
Vous ne pouvez pas répondre aux sujets dans ce forum
Vous ne pouvez pas éditer vos messages dans ce forum
Vous ne pouvez pas supprimer vos messages dans ce forum
Vous ne pouvez pas voter dans les sondages de ce forum

| Le Site | Nous contacter | Annuaire | phpBB | phpBB SEO | Informatruc | Forum Map | Site Map |

CrawlTrack: free crawlers and spiders tracking script for webmaster - script gratuit de détection des robots pour webmaster