Here you go, Virut everywhere!
userinit log:
VirSCAN.org Scanned Report :
Scanned time : 2009/11/08 21:26:59 (CST)
Scanner results: 54% Scanner(s) (20/37) found malware!
File Name : userinit.exe
File Size : 46080 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 9e8e0c31457b19c79ed2e0251a7c5f45
SHA1 : 20099fa5e65b9ce5ac4bc7eb29a1c514fda45d87
Online report :
http://virscan.org/report/433f0e558a...86b54a0d0.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091108053125 2009-11-08 4.14 Gen.Malware!IK
AhnLab V3 2009.11.07.00 2009.11.07 2009-11-07 1.01 Win32/Virut.E
AntiVir 8.2.1.61 7.1.6.204 2009-11-08 0.12 W32/Virut.Gen
Antiy 2.0.18 20091105.3216324 2009-11-05 0.02 -
Arcavir 2009 200911070243 2009-11-07 0.05 -
Authentium 5.1.1 200911081739 2009-11-08 1.21 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 091108-1 2009-11-08 0.01 -
AVG 8.5.288 270.14.55/2490 2009-11-09 1.60 -
BitDefender 7.81008.4482434 7.28827 2009-11-09 3.89 -
CA (VET) 35.1.0 7107 2009-11-05 6.13 -
ClamAV 0.95.2 10000 2009-11-08 0.01 -
Comodo 3.12 2890 2009-11-08 0.72 -
CP Secure 1.3.0.5 2009.11.09 2009-11-09 0.06 -
Dr.Web 4.44.0.9170 2009.11.08 2009-11-08 6.45 Win32.Virut.56
F-Prot 4.4.4.56 20091108 2009-11-08 1.20 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.11.09.02 2009-11-09 0.09 Virus.Win32.Virut.ce [AVP]
Fortinet 2.81-3.120 11.39 2009-11-08 0.19 -
GData 19.8777/19.546 20091109 2009-11-09 6.13 Virus.Win32.Virut.ce [Engine:A]
ViRobot 20091106 2009.11.06 2009-11-06 0.43 -
Ikarus T3.1.01.74 2009.11.09.74488 2009-11-09 4.04 Gen.Malware
JiangMin 11.0.800 2009.11.08 2009-11-08 4.36 Win32/Virut.bq
Kaspersky 5.5.10 2009.11.09 2009-11-09 0.06 Virus.Win32.Virut.ce
KingSoft 2009.2.5.15 2009.11.8.15 2009-11-08 0.51 Win32.Virut.cr.61440
McAfee 5.3.00 5796 2009-11-08 3.44 W32/Virut.n.gen
Microsoft 1.5202 2009.11.08 2009-11-08 6.70 Virus:Win32/Virut.gen!O
Norman 6.01.09 6.01.00 2009-11-06 4.01 -
Panda 9.05.01 2009.11.08 2009-11-08 1.83 -
Trend Micro 8.700-1004 6.612.07 2009-11-08 0.05 PE_VIRUX.GEN-2
Quick Heal 10.00 2009.11.07 2009-11-07 1.21 W32.Virut.G
Rising 20.0 21.55.00.00 2009-11-09 0.96 Win32.Virut.cl
Sophos 3.00.1 4.46 2009-11-09 2.97 -
Sunbelt 5498 5498 2009-11-08 1.74 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20091108.002 2009-11-08 0.09 W32.Virut.CF
nProtect 20091108.01 6121832 2009-11-08 7.46 Trojan/W32.Agent2.46080.D
The Hacker 6.5.0.2 v00063 2009-11-06 0.71 -
VBA32 3.12.10.11 20091108.2047 2009-11-08 2.00 -
VirusBuster 4.5.11.10 10.113.11/2003707 2009-11-09 3.16 -
svchost.exe log: Nothing found
explorer.exe:
VirSCAN.org Scanned Report :
Scanned time : 2009/11/08 21:37:20 (CST)
Scanner results: 51% Scanner(s) (19/37) found malware!
File Name : explorer.exe
File Size : 1053696 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : e3a56ffec2f92ca037a98145b5c607cd
SHA1 : 91759e30451dc991c22d64bd36eddcd317d470e5
Online report :
http://virscan.org/report/4afcb85bed...18c3e8af3.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091108053125 2009-11-08 4.03 Trojan.Win32.Patched!IK
AhnLab V3 2009.11.07.00 2009.11.07 2009-11-07 0.92 Win32/Virut.E
AntiVir 8.2.1.61 7.1.6.204 2009-11-08 0.07 W32/Virut.Gen
Antiy 2.0.18 20091105.3216324 2009-11-05 0.02 -
Arcavir 2009 200911070243 2009-11-07 0.09 -
Authentium 5.1.1 200911081739 2009-11-08 1.28 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 091108-1 2009-11-08 0.05 -
AVG 8.5.288 270.14.55/2490 2009-11-09 1.42 -
BitDefender 7.81008.4482434 7.28827 2009-11-09 3.97 -
CA (VET) 35.1.0 7107 2009-11-05 5.17 -
ClamAV 0.95.2 10000 2009-11-08 0.17 -
Comodo 3.12 2890 2009-11-08 1.20 -
CP Secure 1.3.0.5 2009.11.09 2009-11-09 0.41 -
Dr.Web 4.44.0.9170 2009.11.08 2009-11-08 6.47 Win32.Virut.56
F-Prot 4.4.4.56 20091108 2009-11-08 1.26 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.11.09.02 2009-11-09 0.17 Virus.Win32.Virut.ce [AVP]
Fortinet 2.81-3.120 11.39 2009-11-08 0.27 -
GData 19.8777/19.546 20091109 2009-11-09 5.49 Virus.Win32.Virut.ce [Engine:A]
ViRobot 20091106 2009.11.06 2009-11-06 0.42 -
Ikarus T3.1.01.74 2009.11.09.74488 2009-11-09 4.09 Trojan.Win32.Patched
JiangMin 11.0.800 2009.11.08 2009-11-08 4.05 Win32/Virut.bq
Kaspersky 5.5.10 2009.11.09 2009-11-09 0.07 Virus.Win32.Virut.ce
KingSoft 2009.2.5.15 2009.11.8.15 2009-11-08 0.52 Win32.Virut.cr.61440
McAfee 5.3.00 5796 2009-11-08 3.47 W32/Virut.n.gen
Microsoft 1.5202 2009.11.08 2009-11-08 7.28 Virus:Win32/Virut.gen!O
Norman 6.01.09 6.01.00 2009-11-06 4.01 -
Panda 9.05.01 2009.11.08 2009-11-08 3.61 -
Trend Micro 8.700-1004 6.612.07 2009-11-08 0.10 PE_VIRUX.GEN-2
Quick Heal 10.00 2009.11.07 2009-11-07 1.55 W32.Virut.G
Rising 20.0 21.55.00.00 2009-11-09 1.22 Win32.Virut.cl
Sophos 3.00.1 4.46 2009-11-09 3.03 -
Sunbelt 5498 5498 2009-11-08 2.19 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20091108.002 2009-11-08 0.09 W32.Virut.CF
nProtect 20091108.01 6121832 2009-11-08 8.93 -
The Hacker 6.5.0.2 v00063 2009-11-06 0.74 -
VBA32 3.12.10.11 20091108.2047 2009-11-08 2.10 -
VirusBuster 4.5.11.10 10.113.11/2003707 2009-11-09 3.60 -
spoolsv.exe log:
VirSCAN.org Scanned Report :
Scanned time : 2009/11/08 21:40:18 (CST)
Scanner results: 49% Scanner(s) (18/37) found malware!
File Name : spoolsv.exe
File Size : 77824 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : d1e73dff7192d7a12b9e729fd7248c0c
SHA1 : a60f1ee22051ed92835907ce40b08016c501705f
Online report :
http://virscan.org/report/0575e7fd3e...88cad0a4d.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091108053125 2009-11-08 3.96 -
AhnLab V3 2009.11.07.00 2009.11.07 2009-11-07 0.92 Win32/Virut.E
AntiVir 8.2.1.61 7.1.6.204 2009-11-08 0.12 W32/Virut.Gen
Antiy 2.0.18 20091105.3216324 2009-11-05 0.02 -
Arcavir 2009 200911070243 2009-11-07 0.06 -
Authentium 5.1.1 200911081739 2009-11-08 1.23 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 091108-1 2009-11-08 0.01 -
AVG 8.5.288 270.14.55/2490 2009-11-09 1.61 -
BitDefender 7.81008.4482434 7.28827 2009-11-09 3.91 -
CA (VET) 35.1.0 7107 2009-11-05 6.39 -
ClamAV 0.95.2 10000 2009-11-08 0.02 -
Comodo 3.12 2890 2009-11-08 0.73 -
CP Secure 1.3.0.5 2009.11.09 2009-11-09 0.06 -
Dr.Web 4.44.0.9170 2009.11.08 2009-11-08 6.62 Win32.Virut.56
F-Prot 4.4.4.56 20091108 2009-11-08 1.25 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.11.09.02 2009-11-09 0.10 Virus.Win32.Virut.ce [AVP]
Fortinet 2.81-3.120 11.39 2009-11-08 0.25 -
GData 19.8777/19.546 20091109 2009-11-09 4.68 Virus.Win32.Virut.ce [Engine:A]
ViRobot 20091106 2009.11.06 2009-11-06 0.44 -
Ikarus T3.1.01.74 2009.11.09.74488 2009-11-09 4.11 -
JiangMin 11.0.800 2009.11.08 2009-11-08 8.87 Win32/Virut.bq
Kaspersky 5.5.10 2009.11.09 2009-11-09 0.06 Virus.Win32.Virut.ce
KingSoft 2009.2.5.15 2009.11.8.15 2009-11-08 0.57 Win32.Virut.cr.61440
McAfee 5.3.00 5796 2009-11-08 3.48 W32/Virut.n.gen
Microsoft 1.5202 2009.11.08 2009-11-08 8.24 Virus:Win32/Virut.gen!O
Norman 6.01.09 6.01.00 2009-11-06 2.01 -
Panda 9.05.01 2009.11.08 2009-11-08 2.00 Suspicious file
Trend Micro 8.700-1004 6.612.07 2009-11-08 0.07 Cryp_Xed-21
Quick Heal 10.00 2009.11.07 2009-11-07 1.34 W32.Virut.G
Rising 20.0 21.55.00.00 2009-11-09 0.99 Win32.Virut.cl
Sophos 3.00.1 4.46 2009-11-09 2.99 -
Sunbelt 5498 5498 2009-11-08 2.73 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20091108.002 2009-11-08 0.06 W32.Virut.CF
nProtect 20091108.01 6121832 2009-11-08 9.20 -
The Hacker 6.5.0.2 v00063 2009-11-06 0.73 -
VBA32 3.12.10.11 20091108.2047 2009-11-08 2.03 -
VirusBuster 4.5.11.10 10.113.11/2003707 2009-11-09 3.24 -