08-05-2009, 01:12 AM
máy tính nhà em nhiễm virut ,em quết nó ra thế này nhưng vẫn hcầm chậm .ai biết chỉ bảo giúp em em xin cám ơn
Avira AntiVir Personal
Report file date: Friday, May 08, 2009 00:58
Scanning for 1382452 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 2) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : PAC
Version information:
BUILD.DAT : 17962 Bytes 4/17/2009 11:20:00
AVSCAN.EXE : 466689 Bytes 4/27/2009 16:57:28
AVSCAN.DLL : 40705 Bytes 2/27/2009 03:58:26
LUKE.DLL : 209665 Bytes 2/20/2009 04:35:50
LUKERES.DLL : 12033 Bytes 2/27/2009 03:58:54
ANTIVIR0.VDF : 15603712 Bytes 10/27/2008 05:30:38
ANTIVIR1.VDF : 3336192 Bytes 2/11/2009 13:33:28
ANTIVIR2.VDF : 1810944 Bytes 4/30/2009 10:00:34
ANTIVIR3.VDF : 154112 Bytes 5/7/2009 10:38:26
Engineversion :
AEVDF.DLL : 106868 Bytes 5/5/2009 10:00:42
AESCRIPT.DLL : 385403 Bytes 5/5/2009 10:00:40
AESCN.DLL : 127348 Bytes 4/13/2009 00:48:24
AERDL.DLL : 438645 Bytes 10/29/2008 11:24:42
AEPACK.DLL : 397685 Bytes 4/19/2009 11:45:00
AEOFFICE.DLL : 196987 Bytes 2/26/2009 13:01:58
AEHEUR.DLL : 1737080 Bytes 4/25/2009 16:56:50
AEHELP.DLL : 119158 Bytes 2/26/2009 13:01:58
AEGEN.DLL : 348532 Bytes 4/23/2009 15:18:46
AEEMU.DLL : 393588 Bytes 10/9/2008 07:32:40
AECORE.DLL : 176500 Bytes 4/14/2009 14:35:08
AEBB.DLL : 53618 Bytes 10/9/2008 07:32:40
AVWINLL.DLL : 18177 Bytes 12/12/2008 01:48:00
AVPREF.DLL : 43777 Bytes 12/5/2008 03:32:16
AVREP.DLL : 155905 Bytes 1/20/2009 07:34:30
AVREG.DLL : 36609 Bytes 12/5/2008 03:32:10
AVARKT.DLL : 292609 Bytes 4/27/2009 16:57:28
AVEVTLOG.DLL : 167169 Bytes 1/30/2009 03:37:10
SQLITE3.DLL : 326401 Bytes 1/28/2009 08:03:50
SMTPLIB.DLL : 28417 Bytes 2/2/2009 01:21:34
NETNT.DLL : 11521 Bytes 12/5/2008 03:32:12
RCIMAGE.DLL : 2438401 Bytes 2/9/2009 04:45:46
RCTEXT.DLL : 86785 Bytes 4/27/2009 16:57:28
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:, E:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+SPR,
Start of the scan: Friday, May 08, 2009 00:58
Starting search for hidden objects.
[INFO] The file is not visible.
'28574' objects were checked, '1' hidden objects were found.
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'IEMonitor.exe' - '1' Module(s) have been scanned
Scan process 'WMIPRVSE.EXE' - '1' Module(s) have been scanned
Scan process 'IDMan.exe' - '1' Module(s) have been scanned
Scan process 'YahooMessenger.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'AVGNT.EXE' - '1' Module(s) have been scanned
Scan process 'IGFXSRVC.EXE' - '1' Module(s) have been scanned
Scan process 'VKNT.EXE' - '1' Module(s) have been scanned
Scan process 'IGFXPERS.EXE' - '1' Module(s) have been scanned
Scan process 'HKCMD.EXE' - '1' Module(s) have been scanned
Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned
Scan process 'JUSCHED.EXE' - '1' Module(s) have been scanned
Scan process 'USBGuard.exe' - '1' Module(s) have been scanned
Scan process 'EXPLORER.EXE' - '1' Module(s) have been scanned
Scan process 'ALG.EXE' - '1' Module(s) have been scanned
Scan process 'WDFMGR.EXE' - '1' Module(s) have been scanned
Scan process 'scsiaccess.exe' - '1' Module(s) have been scanned
Scan process 'AVGUARD.EXE' - '1' Module(s) have been scanned
Scan process 'SCHED.EXE' - '1' Module(s) have been scanned
Scan process 'SPOOLSV.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
33 processes with 33 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'E:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '56' files ).
Starting the file scan:
Begin scan in 'C:\' <ATT>
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Documents and Settings\hung\My Documents\Downloads\Programs\gbviet2009_caidat_54. exe
[0] Archive type: RAR SFX (self extracting)
--> GbLogin.exe
[DETECTION] Is the TR/Crypt.CFI.Gen Trojan
C:\Documents and Settings\hung\My Documents\Patch\PatchAllVerSion.rar
[0] Archive type: RAR
--> Patch\IDM 5.16 b x.x Patch.EXE
[DETECTION] Is the TR/Agent.20480.LP Trojan
C:\Documents and Settings\hung\Application Data\IDM\DwnlData\hung\20090507-130327-d41026b9_107\20090507-130327-d41026b9
[0] Archive type: RAR
--> ENGiNE\PhotoShopCS4_X64_Crk.exe
[DETECTION] Is the TR/Spy.280064.A Trojan
C:\Documents and Settings\hung\Application Data\IDM\DwnlData\hung\20090507-132714-e15fb741_113\20090507-132714-e15fb741
[0] Archive type: RAR
--> payloads\AdobeBridge3All\
[1] Archive type: CAB (Microsoft)
--> _2_2637f797479e833e1fbfb39f87a80bb3
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\Program Files\Internet Download Manager\Internet Download Manager Patch By Pharaohs Team For V 5.xx Build xx.exe
[DETECTION] Is the TR/Virtl.22445 Trojan
C:\Program Files\Internet Download Manager\IDM 5.16 b x.x Patch.EXE
[DETECTION] Is the TR/Agent.20480.LP Trojan
[0] Archive type: RAR SFX (self extracting)
--> GbLogin.exe
[DETECTION] Is the TR/Crypt.CFI.Gen Trojan
Begin scan in 'D:\' <ATT>
Begin scan in 'E:\' <DISK1_VOL3>
[0] Archive type: RAR SFX (self extracting)
--> MapHack\C3POv1_1_.06.exe
[DETECTION] Contains recognition pattern of the ADSPY/DealHelper.AH.8 adware or spyware
[DETECTION] Contains recognition pattern of the ADSPY/DealHelper.AH.8 adware or spyware
Beginning disinfection:
C:\Documents and Settings\hung\My Documents\Downloads\Programs\gbviet2009_caidat_54. exe
[NOTE] The file was moved to '4a79240f.qua'!
C:\Documents and Settings\hung\My Documents\Patch\PatchAllVerSion.rar
[NOTE] The file was moved to '4a772413.qua'!
C:\Documents and Settings\hung\Application Data\IDM\DwnlData\hung\20090507-130327-d41026b9_107\20090507-130327-d41026b9
[NOTE] The file was moved to '4a3323e2.qua'!
C:\Program Files\Internet Download Manager\Internet Download Manager Patch By Pharaohs Team For V 5.xx Build xx.exe
[DETECTION] Is the TR/Virtl.22445 Trojan
[NOTE] The file was moved to '4a772423.qua'!
C:\Program Files\Internet Download Manager\IDM 5.16 b x.x Patch.EXE
[DETECTION] Is the TR/Agent.20480.LP Trojan
[NOTE] The file was moved to '4a5023f9.qua'!
[NOTE] The file was moved to '4a71242a.qua'!
[NOTE] The file was moved to '4a722424.qua'!
[DETECTION] Contains recognition pattern of the ADSPY/DealHelper.AH.8 adware or spyware
[NOTE] The file was moved to '4a5323e8.qua'!
End of the scan: Friday, May 08, 2009 01:08
Used time: 09:06 Minute(s)
The scan has been done completely.
3293 Scanned directories
201224 Files were scanned
8 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
8 Files were moved to quarantine
0 Files were renamed
1 Files cannot be scanned
201215 Files not concerned
1061 Archives were scanned
3 Warnings
9 Notes
28574 Objects were scanned with rootkit scan
1 Hidden objects were found
Avira AntiVir Personal
Report file date: Friday, May 08, 2009 00:58
Scanning for 1382452 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 2) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : PAC
Version information:
BUILD.DAT : 17962 Bytes 4/17/2009 11:20:00
AVSCAN.EXE : 466689 Bytes 4/27/2009 16:57:28
AVSCAN.DLL : 40705 Bytes 2/27/2009 03:58:26
LUKE.DLL : 209665 Bytes 2/20/2009 04:35:50
LUKERES.DLL : 12033 Bytes 2/27/2009 03:58:54
ANTIVIR0.VDF : 15603712 Bytes 10/27/2008 05:30:38
ANTIVIR1.VDF : 3336192 Bytes 2/11/2009 13:33:28
ANTIVIR2.VDF : 1810944 Bytes 4/30/2009 10:00:34
ANTIVIR3.VDF : 154112 Bytes 5/7/2009 10:38:26
Engineversion :
AEVDF.DLL : 106868 Bytes 5/5/2009 10:00:42
AESCRIPT.DLL : 385403 Bytes 5/5/2009 10:00:40
AESCN.DLL : 127348 Bytes 4/13/2009 00:48:24
AERDL.DLL : 438645 Bytes 10/29/2008 11:24:42
AEPACK.DLL : 397685 Bytes 4/19/2009 11:45:00
AEOFFICE.DLL : 196987 Bytes 2/26/2009 13:01:58
AEHEUR.DLL : 1737080 Bytes 4/25/2009 16:56:50
AEHELP.DLL : 119158 Bytes 2/26/2009 13:01:58
AEGEN.DLL : 348532 Bytes 4/23/2009 15:18:46
AEEMU.DLL : 393588 Bytes 10/9/2008 07:32:40
AECORE.DLL : 176500 Bytes 4/14/2009 14:35:08
AEBB.DLL : 53618 Bytes 10/9/2008 07:32:40
AVWINLL.DLL : 18177 Bytes 12/12/2008 01:48:00
AVPREF.DLL : 43777 Bytes 12/5/2008 03:32:16
AVREP.DLL : 155905 Bytes 1/20/2009 07:34:30
AVREG.DLL : 36609 Bytes 12/5/2008 03:32:10
AVARKT.DLL : 292609 Bytes 4/27/2009 16:57:28
AVEVTLOG.DLL : 167169 Bytes 1/30/2009 03:37:10
SQLITE3.DLL : 326401 Bytes 1/28/2009 08:03:50
SMTPLIB.DLL : 28417 Bytes 2/2/2009 01:21:34
NETNT.DLL : 11521 Bytes 12/5/2008 03:32:12
RCIMAGE.DLL : 2438401 Bytes 2/9/2009 04:45:46
RCTEXT.DLL : 86785 Bytes 4/27/2009 16:57:28
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:, E:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+SPR,
Start of the scan: Friday, May 08, 2009 00:58
Starting search for hidden objects.
[INFO] The file is not visible.
'28574' objects were checked, '1' hidden objects were found.
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'IEMonitor.exe' - '1' Module(s) have been scanned
Scan process 'WMIPRVSE.EXE' - '1' Module(s) have been scanned
Scan process 'IDMan.exe' - '1' Module(s) have been scanned
Scan process 'YahooMessenger.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'AVGNT.EXE' - '1' Module(s) have been scanned
Scan process 'IGFXSRVC.EXE' - '1' Module(s) have been scanned
Scan process 'VKNT.EXE' - '1' Module(s) have been scanned
Scan process 'IGFXPERS.EXE' - '1' Module(s) have been scanned
Scan process 'HKCMD.EXE' - '1' Module(s) have been scanned
Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned
Scan process 'JUSCHED.EXE' - '1' Module(s) have been scanned
Scan process 'USBGuard.exe' - '1' Module(s) have been scanned
Scan process 'EXPLORER.EXE' - '1' Module(s) have been scanned
Scan process 'ALG.EXE' - '1' Module(s) have been scanned
Scan process 'WDFMGR.EXE' - '1' Module(s) have been scanned
Scan process 'scsiaccess.exe' - '1' Module(s) have been scanned
Scan process 'AVGUARD.EXE' - '1' Module(s) have been scanned
Scan process 'SCHED.EXE' - '1' Module(s) have been scanned
Scan process 'SPOOLSV.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
33 processes with 33 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'E:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '56' files ).
Starting the file scan:
Begin scan in 'C:\' <ATT>
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Documents and Settings\hung\My Documents\Downloads\Programs\gbviet2009_caidat_54. exe
[0] Archive type: RAR SFX (self extracting)
--> GbLogin.exe
[DETECTION] Is the TR/Crypt.CFI.Gen Trojan
C:\Documents and Settings\hung\My Documents\Patch\PatchAllVerSion.rar
[0] Archive type: RAR
--> Patch\IDM 5.16 b x.x Patch.EXE
[DETECTION] Is the TR/Agent.20480.LP Trojan
C:\Documents and Settings\hung\Application Data\IDM\DwnlData\hung\20090507-130327-d41026b9_107\20090507-130327-d41026b9
[0] Archive type: RAR
--> ENGiNE\PhotoShopCS4_X64_Crk.exe
[DETECTION] Is the TR/Spy.280064.A Trojan
C:\Documents and Settings\hung\Application Data\IDM\DwnlData\hung\20090507-132714-e15fb741_113\20090507-132714-e15fb741
[0] Archive type: RAR
--> payloads\AdobeBridge3All\
[1] Archive type: CAB (Microsoft)
--> _2_2637f797479e833e1fbfb39f87a80bb3
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\Program Files\Internet Download Manager\Internet Download Manager Patch By Pharaohs Team For V 5.xx Build xx.exe
[DETECTION] Is the TR/Virtl.22445 Trojan
C:\Program Files\Internet Download Manager\IDM 5.16 b x.x Patch.EXE
[DETECTION] Is the TR/Agent.20480.LP Trojan
[0] Archive type: RAR SFX (self extracting)
--> GbLogin.exe
[DETECTION] Is the TR/Crypt.CFI.Gen Trojan
Begin scan in 'D:\' <ATT>
Begin scan in 'E:\' <DISK1_VOL3>
[0] Archive type: RAR SFX (self extracting)
--> MapHack\C3POv1_1_.06.exe
[DETECTION] Contains recognition pattern of the ADSPY/DealHelper.AH.8 adware or spyware
[DETECTION] Contains recognition pattern of the ADSPY/DealHelper.AH.8 adware or spyware
Beginning disinfection:
C:\Documents and Settings\hung\My Documents\Downloads\Programs\gbviet2009_caidat_54. exe
[NOTE] The file was moved to '4a79240f.qua'!
C:\Documents and Settings\hung\My Documents\Patch\PatchAllVerSion.rar
[NOTE] The file was moved to '4a772413.qua'!
C:\Documents and Settings\hung\Application Data\IDM\DwnlData\hung\20090507-130327-d41026b9_107\20090507-130327-d41026b9
[NOTE] The file was moved to '4a3323e2.qua'!
C:\Program Files\Internet Download Manager\Internet Download Manager Patch By Pharaohs Team For V 5.xx Build xx.exe
[DETECTION] Is the TR/Virtl.22445 Trojan
[NOTE] The file was moved to '4a772423.qua'!
C:\Program Files\Internet Download Manager\IDM 5.16 b x.x Patch.EXE
[DETECTION] Is the TR/Agent.20480.LP Trojan
[NOTE] The file was moved to '4a5023f9.qua'!
[NOTE] The file was moved to '4a71242a.qua'!
[NOTE] The file was moved to '4a722424.qua'!
[DETECTION] Contains recognition pattern of the ADSPY/DealHelper.AH.8 adware or spyware
[NOTE] The file was moved to '4a5323e8.qua'!
End of the scan: Friday, May 08, 2009 01:08
Used time: 09:06 Minute(s)
The scan has been done completely.
3293 Scanned directories
201224 Files were scanned
8 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
8 Files were moved to quarantine
0 Files were renamed
1 Files cannot be scanned
201215 Files not concerned
1061 Archives were scanned
3 Warnings
9 Notes
28574 Objects were scanned with rootkit scan
1 Hidden objects were found