Se connecter / S'enregistrer
Votre question

virus serwab et plein de pop up

Tags :
  • Hijackthis
  • Sécurité
Dernière réponse : dans Sécurité et virus
10 Août 2006 17:09:17

bon alors j'ai le virus serwab et j'arrive pas a l'enlever et a cause de celui ci j'ai plein de pop up(anti virus ,scanvirus ,error staff,doctor anti virus qui vienne tt les 30s et c'est inssuportable donc si quelqu'un peut m'aider je lui serai tres reconnaissant .


merci d'avance

Autres pages sur : virus serwab plein pop

10 Août 2006 17:14:03

Bonjour,

ça sent le look2me et alcan

- Télécharge HijackThis sur ton bureau.
- Renomme le fichier HijackThis.exe en Scanner.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste
- Tape Scanner.exe et Appuye sur la touche Entrée.
- Génère un rapport en suivant ces indications :
- Double-clic sur Scanner.exe
- Exécute le et clique sur Do a scan and save log file.
- Le rapport s'ouvre sur leBloc-Note
- Colle le rapport ici, pour cela :
- Menu Edition / Selectionner Tout
- Menu Edition / copier
- Ici dans un nouveau message : clic droit / coller
- N'hésite pas à consulter l'aide HijackThis -
10 Août 2006 17:18:43

Logfile of HijackThis v1.99.1
Scan saved at 17:17:32, on 10/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Messager Wanadoo\Demon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\dfndrff_8.exe
C:\kybrdff_8.exe
C:\nwnmff_8.exe
C:\Program Files\ipwins\ipwins.exe
C:\Program Files\Blubster\Blubster.exe
C:\Program Files\Fichiers communs\{B8F53687-06C3-1036-1216-020218040001}\Update.exe
C:\PROGRA~1\FICHIE~1\zfro\zfrom.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\FICHIE~1\zfro\zfroa.exe
C:\Program Files\TClock\TClock.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USDR6V_0001_D18M3107NetInstaller.exe
C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\KNG1Y3WB\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {EA0D26BD-9029-431A-86E0-83152D67828A} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O3 - Toolbar: Blubster Toolbar - {7EFBC57C-CD57-481F-B794-648FCE9C9116} - C:\Program Files\Blubster Toolbar\v3.0.0.0\Blubster_Toolbar.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\Dealio.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [Demon] C:\PROGRA~1\Messager Wanadoo\Demon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_8.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_8.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_8.exe
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [WinLogon] C:\WINDOWS\logon.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [au] "C:\Program Files\Dealio\DealioAu.exe"
O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [WinFixer2005] "C:\Program Files\WinFixer 2005\uwfx5.exe" /scan
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [zfro] C:\PROGRA~1\FICHIE~1\zfro\zfrom.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Program Files\Dealio\res\DealioSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\Dealio.dll
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {00000000-0000-0000-0000-000020050660} - http://207.234.185.217/ABoxInst_int15.exe
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://fr.systemdoctor.com/download/2006/cab/SystemDoct...
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdriveclean...
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/activex/promocache/34342...
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/sp3.12r/spysp...
O17 - HKLM\System\CCS\Services\Tcpip\..\{B76CAE64-09B1-46E2-83A8-B277F4AD9294}: NameServer = 80.10.246.1 80.10.246.132
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: repairs303169590.dll
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\wLvemsp.dll (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Qm9vbXNjdWQ\command.exe (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

Contenus similaires
10 Août 2006 17:20:13

bingo :) 

Dans ajout/suppression de programmes du panneau de configuration, désinstalle si présent : SurfSideKick

Si cela a fonctionné, copie/colle un nouveau rapport.
Si cela n'a pas fonctionné, dis le moi.
10 Août 2006 17:33:20

Logfile of HijackThis v1.99.1
Scan saved at 17:34:59, on 10/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Messager Wanadoo\Demon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\dfndrff_8.exe
C:\kybrdff_8.exe
C:\nwnmff_8.exe
C:\Program Files\ipwins\ipwins.exe
C:\Program Files\Blubster\Blubster.exe
C:\Program Files\Fichiers communs\{B8F53687-06C3-1036-1216-020218040001}\Update.exe
C:\PROGRA~1\FICHIE~1\zfro\zfrom.exe
C:\PROGRA~1\FICHIE~1\zfro\zfroa.exe
C:\Program Files\TClock\TClock.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\KNG1Y3WB\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {EA0D26BD-9029-431A-86E0-83152D67828A} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O3 - Toolbar: Blubster Toolbar - {7EFBC57C-CD57-481F-B794-648FCE9C9116} - C:\Program Files\Blubster Toolbar\v3.0.0.0\Blubster_Toolbar.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\Dealio.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [Demon] C:\PROGRA~1\Messager Wanadoo\Demon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_8.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_8.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_8.exe
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [WinLogon] C:\WINDOWS\logon.exe
O4 - HKLM\..\Run: [au] "C:\Program Files\Dealio\DealioAu.exe"
O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [WinFixer2005] "C:\Program Files\WinFixer 2005\uwfx5.exe" /scan
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKCU\..\Run: [zfro] C:\PROGRA~1\FICHIE~1\zfro\zfrom.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Program Files\Dealio\res\DealioSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\Dealio.dll
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {00000000-0000-0000-0000-000020050660} - http://207.234.185.217/ABoxInst_int15.exe
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://fr.systemdoctor.com/download/2006/cab/SystemDoct...
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdriveclean...
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/activex/promocache/34342...
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/sp3.12r/spysp...
O17 - HKLM\System\CCS\Services\Tcpip\..\{B76CAE64-09B1-46E2-83A8-B277F4AD9294}: NameServer = 80.10.246.130 80.10.246.3
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\wLvemsp.dll (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Qm9vbXNjdWQ\command.exe (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

10 Août 2006 17:39:32

Bonjour, je n'ai jamais vu quelqun d'aussi infécté que toi!

Tu es infécété par un dialer, cool search, tango 888:

Alors Voici les cases à cocher avec hijackthis:

Citation :
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll


CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O3 - Toolbar: Blubster Toolbar - {7EFBC57C-CD57-481F-B794-

O3 - Toolbar: Blubster Toolbar - {7EFBC57C-CD57-481F-B794-648FCE9C9116} - C:\Program Files\Blubster Toolbar\v3.0.0.0\Blubster_Toolbar.dll


O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\Dealio.dll

O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe


O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM

O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO

O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\Dealio.dll

O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB

Télécharge Brute Force Uninstaller (BFU) 1.0.9 http://www.softpedia.com/get/Tweak/Uninstallers/Brute-Force-Uninstaller.shtml

Pour son utillisation tu dois le mettre dans ton disque dur (C:\).
Éxécute le. Fais open script file (le petit dossier) va dans le rérépertoire de BFU assure toi que dans type de fichier se soit:**All Files**, ensuite clique sur "media gateway_bfu", OK et finnalemant execute. Ensuite télécharge Lopremover http://forum.zebulon.fr/lofiversion/index.php/t85149.html

Mais le sur ton bureau et execute le ensuite poste un rapport Hijackthis!;)



10 Août 2006 17:41:03

Voici la manipulation à effectuer en entier
Si certains éléments ne sont pas trouvés, merci de le signaler mais de poursuivre les manipulations jusqu'au bout.

-- Menu Démarrer puis executer, dans le champs tape : SC delete cmdService

- Demarrer / executer / tape services.msc
- Cherche Network Monitor dans la liste
- Double clic dessus, positionne le type de démarrage sur désactiver
- Cherche Command Service dans la liste
- Double clic dessus, positionne le type de démarrage sur désactiver

Sur HijackThis, refais un scan et coches les lignes suivantes :

O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O3 - Toolbar: Blubster Toolbar - {7EFBC57C-CD57-481F-B794-648FCE9C9116} - C:\Program Files\Blubster Toolbar\v3.0.0.0\Blubster_Toolbar.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\Dealio.dll
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_8.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_8.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_8.exe
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [WinLogon] C:\WINDOWS\logon.exe
O4 - HKLM\..\Run: [au] "C:\Program Files\Dealio\DealioAu.exe"
O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [WinFixer2005] "C:\Program Files\WinFixer 2005\uwfx5.exe" /scan
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKCU\..\Run: [zfro] C:\PROGRA~1\FICHIE~1\zfro\zfrom.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Program Files\Dealio\res\DealioSearch.html
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\Dealio.dll
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://fr.systemdoctor.com/downloa [...] all_fr.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freew [...] rstart.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/act [...] 2D2D2D.exe
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spy [...] nstall.cab


---> puis clic sur le bouton "Fix Checked"
n'hésite pas à consulter l'aide HijackThis


Télécharge Look2Me-Destroyer.exe sur ton Bureau.
---> Télécharger Look2Me-Destroyer.exe

- Ferme toutes les fenêtres et programmes actifs avant de passer à l'étape suivante.
- Double-clique Look2Me-Destroyer.exe afin de lancer l'outil.
- Coche Run this program as a task
- Un message s'affichera, te disant ceci : "Look2Me-Destroyer will close and re-open in approximately 10 seconds". Clique OK
- Il se relancera après les 10 secondes, puis clique sur le bouton Scan for L2M; les icônes de ton Bureau vont disparaître : c'est normal.
- Lorsque le scan termine, clique sur le bouton Remove L2M
- Un message Done Scanning apparaîtra, clique OK.
- Un nouveau message s'affichera : Done removing infected files! Look2Me-Destroyer will now shutdown your computer; clique OK.
- Ton PC va maintenant s'éteindre.
- Démarre ton PC normalement.

** Si Look2Me-Destroyer ne se relance pas automatiquement après les 10 secondes, redémarre et essaie à nouveau.

** Si tu reçois un message de ton parefeu que l'outil tente d'accéder à l'internet : Accepte.

** Si un message runtime error '339' s'affiche : télécharge MSWINSCK.OCX, et place-le dans le dossier C:\Windows\System32.

_________


Télécharge Brute Force Uninstaller (de Merijn).
Créé un nouveau dossier directement sur le C:\ et nomme-le BFU. Pour cela :
-- Ouvre le poste de travail
-- Double-clic sur le disque C
-- Menu Fichier en haut puis Nouveau et nouveau dossier
-- Tapez BFU dans le nom du nouveau dossier

Décompresser le fichier téléchargé dans ce nouveau dossier (C:\BFU)

Ensuite :
FAIS UN CLIC-DROIT ICI et choisis "Enregistrer la cible sous..." afin de télécharger alcanshorty.bfu (de Metallica). Sauvegarde dans le dossier créé (C:\BFU). **Note : si tu utilises Internet Explorer; lors de la sauvegarde, assure-toi que le champs "Type :" affiche "Tous les fichiers".

Important : Tu dois maintenant avoir deux fichiers dans le dossier C:\BFU : alcanshorty.bfu et BFU.exe.

- Télécharge et installe ewido
- Mets le à jour à partir du menu update en haut, n'hésite pas à consulter l'Aide ewido pour tout problème.
- Télécharge clean.zip, décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.

__________

-- Redémarre en mode en mode sans échec, si tu sais pas comment on fait lis ceci
-- Ouvre le dossier clean qui se trouve sur ton bureau, et double-clic sur clean.cmd, une fenêtre noire va apparaître pendant un instant, laisse la ouverte.

Démarre le "Brute Force Uninstaller" en double-cliquant BFU.exe (du dossier C:\BFU)
- Clique sur le petit dossier jaune, à la droite de la boîte Scriptline to execute, et double-clique sur :

alcanshorty.bfu

- Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\alcanshorty.bfu
Clique sur Execute et laisse-le faire son travail.
Attendre que Complete script execution apparaîsse et clique sur OK.
Clique Exit pour fermer le programme BFU.

- Ouvre ewido et clic sur l'onglet Settings, pour How to Act sélèctionne Quarantine.
Reviens a l'onglet Scan cliques Complete system Scan.
Le scan démarre.
A la fin cliquer sur Apply all actions
Puis sur Save report et pour finir Save report as enregistrer sur le Bureau.
N'hésite pas à consulter l'Aide ewido pour tout problème.

Nettoye ton ordinateur avec CCleaner : http://www.malekal.com/tutorial_CCleaner.html

__________

-- Redémarre en mode normal : Menu Démarrer / Arreter / Redémarre l'ordinateur
Attention : dans le cas où l'ordinateur redémarre en boucle en mode sans échec, faire la manipulation inverse en décochant l'option /SAFEBOOT à l'aide de msconfig : voir à nouveau cette page : cliquez-ici

-- Fais un scan en ligne avec Internet Explorer : Scan Kaspersky et colle le rapport ici. Si tu es perdu, tu peux suivre cette aide pour les scans en ligne
-- Copie/Colle ici les rapports :
- Colle le rapport généré, situé ici : C:\Look2Me-Destroyer.txt
- ewido
- le rapport clean : Poste de travail / double clic sur disque C / double-clic sur rapport_clean.txt et copier/coller le contenu ici C:\rapport_clean.txt
- ainsi qu'un nouveau log HijackThis
10 Août 2006 21:12:38

avec kaspersky j'analyse le poste de travail????
10 Août 2006 21:14:26

deja le rapport clean.txt

Script clean par Malekal_morte - http://www.malekal.com

Microsoft Windows XP [version 5.1.2600]
Script execute en mode sans echec

*** Suppression de fichiers sur C:
C:\dfndr??_?.exe FOUND
C:\drsmartload*.exe FOUND
C:\kybrd??_?.exe FOUND
C:\nwnm??_?.exe FOUND
C:\ucmoreiex.exe FOUND

*** Suppression des fichiers dans C:\WINDOWS\
C:\WINDOWS\keyboard*.dat FOUND
C:\WINDOWS\newname.dat FOUND
C:\WINDOWS\smdat32m.sys FOUND
C:\WINDOWS\unvise32qt.exe FOUND

*** Suppression des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system32\stera.job FOUND
"C:\WINDOWS\Downloaded Program Files\UERSV_*_N*NetInstaller.exe" FOUND

"C:\Program Files\fichiers communs\InetGet\" FOUND
"C:\Program Files\common files\misc001\" FOUND
"C:\Program Files\common Files\simtest\" FOUND
"C:\Program Files\common files\svchostsys\" FOUND
"C:\Program Files\Altnet\" FOUND
"C:\Program Files\Blubster Toolbar\" FOUND
"C:\Program Files\InetGet2\" FOUND
"C:\Program Files\ipwins\" FOUND
"C:\Program Files\Need2Find\" FOUND
"C:\Program Files\outlook\" FOUND
"C:\Program Files\TClock\" FOUND
"C:\Program Files\TheSearchAccelerator\" FOUND
"C:\Program Files\Toolbar888\" FOUND
"C:\Program Files\Windows\" FOUND
"C:\Program Files\winupdates\" FOUND

*** Suppression des clefs du registre effectuee..
10 Août 2006 21:15:47

Look2Me-Destroyer V1.0.12

Scanning for infected files.....
Scan started at 10/08/2006 17:58:03

Infected! C:\WINDOWS\system32\wLvemsp.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257737.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257760.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257794.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257811.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0260809.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0261805.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0261821.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0261822.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP162\A0262821.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP162\A0263821.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP163\A0263848.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP163\A0263849.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0264862.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0264867.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0264875.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0265874.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0267874.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0267887.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0267909.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0268893.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269893.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269895.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269903.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269918.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP168\A0271918.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP169\A0271939.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP170\A0273948.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP170\A0274946.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP172\A0274957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0275975.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0276964.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0277964.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0278968.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0279964.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0280957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP174\A0281957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP174\A0282957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP175\A0283957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP175\A0284957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP175\A0285969.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP176\A0286969.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP177\A0287965.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP180\A0290957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP181\A0291957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP181\A0292957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP182\A0293957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP183\A0294957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP184\A0295957.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309073.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309074.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309075.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309076.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309077.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309078.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309079.dll
Infected! C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0310056.dll
Infected! C:\WINDOWS\system32\d2j0lc1m1f.dll
Infected! C:\WINDOWS\system32\d6j00g1me6.dll
Infected! C:\WINDOWS\system32\dhserial.dll
Infected! C:\WINDOWS\system32\djns0157e.dll
Infected! C:\WINDOWS\system32\dn4601hse.dll
Infected! C:\WINDOWS\system32\dn8s01l7e.dll
Infected! C:\WINDOWS\system32\dnjm0111e.dll
Infected! C:\WINDOWS\system32\dnns0157e.dll
Infected! C:\WINDOWS\system32\fn0021dmg.dll
Infected! C:\WINDOWS\system32\fp4003hme.dll
Infected! C:\WINDOWS\system32\fp4803hue.dll
Infected! C:\WINDOWS\system32\fp6q03j5e.dll
Infected! C:\WINDOWS\system32\gp2ml3f11.dll
Infected! C:\WINDOWS\system32\gp46l3hs1.dll
Infected! C:\WINDOWS\system32\gp8sl3l71.dll
Infected! C:\WINDOWS\system32\gprol3931.dll
Infected! C:\WINDOWS\system32\h0l20a3oed.dll
Infected! C:\WINDOWS\system32\hr0605dse.dll
Infected! C:\WINDOWS\system32\hr4805hue.dll
Infected! C:\WINDOWS\system32\i424lefq1h2e.dll
Infected! C:\WINDOWS\system32\i4420ehoeh4c0.dll
Infected! C:\WINDOWS\system32\i624lgfq162e.dll
Infected! C:\WINDOWS\system32\i6jqlg1516.dll
Infected! C:\WINDOWS\system32\ir02l5do1.dll
Infected! C:\WINDOWS\system32\ir8ul5l91.dll
Infected! C:\WINDOWS\system32\j44o0eh3eh4.dll
Infected! C:\WINDOWS\system32\j60s0gd7e60.dll
Infected! C:\WINDOWS\system32\jtlm0731e.dll
Infected! C:\WINDOWS\system32\jtnm0751e.dll
Infected! C:\WINDOWS\system32\k262lcjo1foc.dll
Infected! C:\WINDOWS\system32\k2pm0c71ef.dll
Infected! C:\WINDOWS\system32\k426lefs1h26.dll
Infected! C:\WINDOWS\system32\k4pmle711h.dll
Infected! C:\WINDOWS\system32\kjrnel32.dll
Infected! C:\WINDOWS\system32\kprberos.dll
Infected! C:\WINDOWS\system32\krdkaz.dll
Infected! C:\WINDOWS\system32\kt06l7ds1.dll
Infected! C:\WINDOWS\system32\l4r0le9m1h.dll
Infected! C:\WINDOWS\system32\l62slgf7162.dll
Infected! C:\WINDOWS\system32\lv8m09l1e.dll
Infected! C:\WINDOWS\system32\m2460chsef460.dll
Infected! C:\WINDOWS\system32\m2820cloefqc0.dll
Infected! C:\WINDOWS\system32\m6640gjqe6oe0.dll
Infected! C:\WINDOWS\system32\m6lslg3716.dll
Infected! C:\WINDOWS\system32\mfdtcuiu.dll
Infected! C:\WINDOWS\system32\mv26l9fs1.dll
Infected! C:\WINDOWS\system32\mv8ml9l11.dll
Infected! C:\WINDOWS\system32\mvp6l97s1.dll
Infected! C:\WINDOWS\system32\myvbvm60.dll
Infected! C:\WINDOWS\system32\mzc42loc.dll
Infected! C:\WINDOWS\system32\n42u0ef9eh2.dll
Infected! C:\WINDOWS\system32\n4l8le3u1h.dll
Infected! C:\WINDOWS\system32\n82ulif9182.dll
Infected! C:\WINDOWS\system32\o2ro0c93ef.dll
Infected! C:\WINDOWS\system32\p2p6lc7s1f.dll
Infected! C:\WINDOWS\system32\q486lels1hq6.dll
Infected! C:\WINDOWS\system32\r2p80c7uef.dll
Infected! C:\WINDOWS\system32\r88slil718q.dll
Infected! C:\WINDOWS\system32\uyrcntra.dll

Attempting to delete infected files...

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257737.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257737.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257760.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257760.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257794.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257794.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257811.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0257811.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0260809.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0260809.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0261805.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0261805.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0261821.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0261821.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0261822.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP161\A0261822.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP162\A0262821.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP162\A0262821.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP162\A0263821.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP162\A0263821.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP163\A0263848.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP163\A0263848.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP163\A0263849.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP163\A0263849.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0264862.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0264862.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0264867.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0264867.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0264875.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0264875.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0265874.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0265874.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0267874.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0267874.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0267887.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0267887.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0267909.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0267909.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0268893.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP165\A0268893.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269893.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269893.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269895.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269895.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269903.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269903.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269918.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP166\A0269918.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP168\A0271918.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP168\A0271918.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP169\A0271939.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP169\A0271939.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP170\A0273948.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP170\A0273948.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP170\A0274946.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP170\A0274946.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP172\A0274957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP172\A0274957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0275975.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0275975.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0276964.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0276964.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0277964.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0277964.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0278968.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0278968.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0279964.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0279964.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0280957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP173\A0280957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP174\A0281957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP174\A0281957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP174\A0282957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP174\A0282957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP175\A0283957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP175\A0283957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP175\A0284957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP175\A0284957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP175\A0285969.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP175\A0285969.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP176\A0286969.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP176\A0286969.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP177\A0287965.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP177\A0287965.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP180\A0290957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP180\A0290957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP181\A0291957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP181\A0291957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP181\A0292957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP181\A0292957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP182\A0293957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP182\A0293957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP183\A0294957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP183\A0294957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP184\A0295957.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP184\A0295957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309073.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309073.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309074.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309074.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309075.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309075.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309076.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309076.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309077.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309077.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309078.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309078.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309079.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0309079.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0310056.dll
C:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0310056.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\d2j0lc1m1f.dll
C:\WINDOWS\system32\d2j0lc1m1f.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\d6j00g1me6.dll
C:\WINDOWS\system32\d6j00g1me6.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\dhserial.dll
C:\WINDOWS\system32\dhserial.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\djns0157e.dll
C:\WINDOWS\system32\djns0157e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\dn4601hse.dll
C:\WINDOWS\system32\dn4601hse.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\dn8s01l7e.dll
C:\WINDOWS\system32\dn8s01l7e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\dnjm0111e.dll
C:\WINDOWS\system32\dnjm0111e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\dnns0157e.dll
C:\WINDOWS\system32\dnns0157e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\fn0021dmg.dll
C:\WINDOWS\system32\fn0021dmg.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\fp4003hme.dll
C:\WINDOWS\system32\fp4003hme.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\fp4803hue.dll
C:\WINDOWS\system32\fp4803hue.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\fp6q03j5e.dll
C:\WINDOWS\system32\fp6q03j5e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\gp2ml3f11.dll
C:\WINDOWS\system32\gp2ml3f11.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\gp46l3hs1.dll
C:\WINDOWS\system32\gp46l3hs1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\gp8sl3l71.dll
C:\WINDOWS\system32\gp8sl3l71.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\gprol3931.dll
C:\WINDOWS\system32\gprol3931.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\h0l20a3oed.dll
C:\WINDOWS\system32\h0l20a3oed.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\hr0605dse.dll
C:\WINDOWS\system32\hr0605dse.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\hr4805hue.dll
C:\WINDOWS\system32\hr4805hue.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\i424lefq1h2e.dll
C:\WINDOWS\system32\i424lefq1h2e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\i4420ehoeh4c0.dll
C:\WINDOWS\system32\i4420ehoeh4c0.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\i624lgfq162e.dll
C:\WINDOWS\system32\i624lgfq162e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\i6jqlg1516.dll
C:\WINDOWS\system32\i6jqlg1516.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\ir02l5do1.dll
C:\WINDOWS\system32\ir02l5do1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\ir8ul5l91.dll
C:\WINDOWS\system32\ir8ul5l91.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\j44o0eh3eh4.dll
C:\WINDOWS\system32\j44o0eh3eh4.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\j60s0gd7e60.dll
C:\WINDOWS\system32\j60s0gd7e60.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\jtlm0731e.dll
C:\WINDOWS\system32\jtlm0731e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\jtnm0751e.dll
C:\WINDOWS\system32\jtnm0751e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\k262lcjo1foc.dll
C:\WINDOWS\system32\k262lcjo1foc.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\k2pm0c71ef.dll
C:\WINDOWS\system32\k2pm0c71ef.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\k426lefs1h26.dll
C:\WINDOWS\system32\k426lefs1h26.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\k4pmle711h.dll
C:\WINDOWS\system32\k4pmle711h.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\kjrnel32.dll
C:\WINDOWS\system32\kjrnel32.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\kprberos.dll
C:\WINDOWS\system32\kprberos.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\krdkaz.dll
C:\WINDOWS\system32\krdkaz.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\kt06l7ds1.dll
C:\WINDOWS\system32\kt06l7ds1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\l4r0le9m1h.dll
C:\WINDOWS\system32\l4r0le9m1h.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\l62slgf7162.dll
C:\WINDOWS\system32\l62slgf7162.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\lv8m09l1e.dll
C:\WINDOWS\system32\lv8m09l1e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\m2460chsef460.dll
C:\WINDOWS\system32\m2460chsef460.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\m2820cloefqc0.dll
C:\WINDOWS\system32\m2820cloefqc0.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\m6640gjqe6oe0.dll
C:\WINDOWS\system32\m6640gjqe6oe0.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\m6lslg3716.dll
C:\WINDOWS\system32\m6lslg3716.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\mfdtcuiu.dll
C:\WINDOWS\system32\mfdtcuiu.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\mv26l9fs1.dll
C:\WINDOWS\system32\mv26l9fs1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\mv8ml9l11.dll
C:\WINDOWS\system32\mv8ml9l11.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\mvp6l97s1.dll
C:\WINDOWS\system32\mvp6l97s1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\myvbvm60.dll
C:\WINDOWS\system32\myvbvm60.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\mzc42loc.dll
C:\WINDOWS\system32\mzc42loc.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\n42u0ef9eh2.dll
C:\WINDOWS\system32\n42u0ef9eh2.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\n4l8le3u1h.dll
C:\WINDOWS\system32\n4l8le3u1h.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\n82ulif9182.dll
C:\WINDOWS\system32\n82ulif9182.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\o2ro0c93ef.dll
C:\WINDOWS\system32\o2ro0c93ef.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\p2p6lc7s1f.dll
C:\WINDOWS\system32\p2p6lc7s1f.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\q486lels1hq6.dll
C:\WINDOWS\system32\q486lels1hq6.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\r2p80c7uef.dll
C:\WINDOWS\system32\r2p80c7uef.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\r88slil718q.dll
C:\WINDOWS\system32\r88slil718q.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\uyrcntra.dll
C:\WINDOWS\system32\uyrcntra.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Uninstall

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{FDF8CCCF-8C96-48F5-9FBA-54F7FF2E8A0B}"
HKCR\Clsid\{FDF8CCCF-8C96-48F5-9FBA-54F7FF2E8A0B}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{66480408-9F7A-4714-8126-65B3F776DC02}"
HKCR\Clsid\{66480408-9F7A-4714-8126-65B3F776DC02}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrateurs - Succeeded
a b 8 Sécurité
10 Août 2006 21:22:47

avec kaspersky j'analyse le poste de travail????
-> Oui
10 Août 2006 21:26:22

ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 20:18:06 10/08/2006

+ Scan result:



D:\WINDOWS\RGJWOYFH.dll -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EA0D26BD-9029-431A-86E0-83152D67828A} -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\S-1-5-21-57989841-1770027372-725345543-500\Software\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\S-1-5-21-57989841-1770027372-725345543-500\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\S-1-5-21-57989841-1770027372-725345543-500\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
C:\warebundlenewer.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll -> Adware.PeerNet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-21-57989841-1770027372-725345543-500\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-21-57989841-1770027372-725345543-500\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{2178F3FB-2560-458f-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
HKU\S-1-5-21-57989841-1770027372-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
D:\mé doc\fr.exe -> Dialer.Agent.a : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6PV_0001_N86M0507NetInstaller.exe -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWA6PV_0001_N86M0507NetInstaller.exe -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UWA6PV_0001_N86M0507NetInstaller.exe -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UWA6PV_0001_N86M0507NetInstaller.exe -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\Program Files\Fichiers communs\zfro\zfrop.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\Program Files\Fichiers communs\zfro\zfroa.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\Program Files\Fichiers communs\zfro\zfrom.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\Program Files\Fichiers communs\zfro\zfrol.exe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\setup.exe -> Downloader.VB.afb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\setup.exe.tmp -> Downloader.VB.afb : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UWFX5V_0001_N57M1412NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.10\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.11\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.12\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.13\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.14\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.15\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USDR6V_0001_D13M1007NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.6\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.7\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.8\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.9\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\USDR6V_0001_D08M1005NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\USDR6V_0001_D13M1007NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6PV_0001_N91M2107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWA6PV_0001_N91M2107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UWA6PV_0001_N91M2107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UWA6PV_0001_N91M2107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
:mozilla.293:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.311:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.324:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.166:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.215:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.297:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.298:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.57:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.58:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.59:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.15:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.181:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.182:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.65:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.306:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.322:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.120:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.275:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.278:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
:mozilla.27:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
:mozilla.274:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup (quarantined).
:mozilla.149:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.55:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.56:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.31:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Comclick : Cleaned with backup (quarantined).
:mozilla.32:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Comclick : Cleaned with backup (quarantined).
:mozilla.212:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Counted : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.173:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.53:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.6:D :\Documents and Settings2\Maria\Application Data\Phoenix\Profiles\default\8p9msgaz.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.39:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Estat : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Estat : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Estat : Cleaned with backup (quarantined).
:mozilla.326:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.327:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.328:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.329:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.330:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.185:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.49:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.50:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned with backup (quarantined).
:mozilla.316:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.317:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.115:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.116:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.117:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.79:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@counter.hitslink[2].txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned with backup (quarantined).
:mozilla.172:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.157:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Need2find : Cleaned with backup (quarantined).
:mozilla.158:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Need2find : Cleaned with backup (quarantined).
:mozilla.220:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.100:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.159:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.160:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.99:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.299:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.303:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.304:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.305:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@project2.realtracker[1].txt -> TrackingCookie.Realtracker : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.135:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.155:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.156:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.106:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined).
:mozilla.107:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined).
:mozilla.108:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined).
:mozilla.28:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined).
:mozilla.29:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined).
:mozilla.30:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.51:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.53:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.186:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.120:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
:mozilla.121:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.41:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.42:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.43:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.6:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.7:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.8:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.9:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@weborama[2].txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.188:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.189:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.190:D :\Documents and Settings2\Serge\Application Data\Phoenix\Profiles\default\usdgozob.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.313:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.320:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\48el1i4m.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Cookies\administrateur@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UDC6_0001_D10M2905NetInstaller.exe -> Trojan.Fakealert : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UDC6_0001_D10M2905NetInstaller.exe -> Trojan.Fakealert : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UDC6_0001_D10M2905NetInstaller.exe -> Trojan.Fakealert : Cleaned with backup (quarantined).
C:\Program Files\Fichiers communs\{B8F53687-06C3-1036-1216-020218040001}\Update.exe -> Trojan.Starter.65 : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ Games.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ Music.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ Software.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\(ebook) Fundamentals of Thermodynamics [Sonntag-Borgnakke-Van Wylen] - Resolutions.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\(ebook-pdf) - Mathematics - Tom M Apostol - Calculus vol 2 rar.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\6600 7650 Software Symbian 60 Series - LRO.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\About CNET Networks.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Advanced search.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ahead Nero Premium 7 ISO Ultratorrent.net.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Air America Radio - The Al Franken Show 063006 [mp3].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\All RSS feeds.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\All Software.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\An American haunting DVDRip Xvid www.torrentsrock.org.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Audio & Video Software.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Basic Instinct 2[2006][Unrated Edition]DvDrip[Eng]-aXXo 3499522 TPB.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Bible Black Second Scripture.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Bigmouthfuls episode Venus POV style.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Billy Joel-The Complete Hits Collection 1973-1997 4CDs(Darkside RG).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Browse categories.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Business & Productivity.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\CNET Channel.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\CNET Download.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\CNET News.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\CNET Reviews.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\CNET Shopper.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Cannonball Adderley - Cannonball's Bossa Nova -jazz.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Chat & E-mail.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Chet Baker Quartet Plays Standards -jazz.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Click-XViD Adam Sandler.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\CodeFinder - Bible Code Software.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Compare Prices.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Copyright policy.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\DTM - Round 4 - Brands Hatch - 02 07 06 - german.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Deadwood S03E04 HDTV XviD-LOL [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Deadwood S03E04 HR HDTV AC3 5 1 XviD-DIMENSION [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Derek and Clive - Come Again.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Design Tools.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Desktop Enhancements.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Developer Tools.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Devil May Cry 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Dexter Gordon - The Other Side of Round Midnight -jazz.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Dictionary of Networking.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Digital Photography.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Discipline Ep 1-6 Uncensored + Subs (Xvid).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Dj Tatana - Summer Parade 2006 [Mp3@VBR].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Drop Dead Gorgeous S01E04 WS PDTV XviD-RiVER [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EASYSQL 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EAuthentix Outlook Plug-in 1.2.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EBAS 1.0.0.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EBM (Evidence Based Medicine) Reports 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EBP Business Plan Designer 3.0.12.23.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EBRcart 4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EBRclock 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EBgo Sniper 1.4.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EBgo Windows CD Key Extractor 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EBook Maestro Free 1.50.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EBook Maestro Pro 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EC Watermark 2.1 build 388.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ECTACO English - Spanish Talking Dictionary 3.0.58.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ECTACO FlashCards English - German 1.1.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ECTACO FlashCards English - German 1.1.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ECTACO FlashCards English - Spanish 1.1.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ECTI 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EClean 1.4.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EClock 3.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EControl Syntax Editor 2.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ECrawl 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ED for Windows 4.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDA 01.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDGE Diagrammer 5.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDI ClinicPro 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDIdEv SEF Reader 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDL AutoSave 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDXOR 1.65.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDictionary English-Russian 4.0.19.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDraw Flowchart ActiveX Control 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDraw Flowchart Software 1.6.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDrill Math Flashcard 3.26.2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EDrill's SpellingBee Flashcard 2.20.2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EEBond 26.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EFGrabber 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EFM--CAD and Image File Manager 2.6.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EFR (Extended Find and Replace) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EFS Key 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EFS Standard 5.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EFT123 2.0.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EFormMaster 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EGems Collector Pro 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EGtray 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EHusBook 2.34.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EIOBoard 1.8.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EIPC Calendar 1.07.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EIPC Free Image2Icon 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EJournal 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ELCAD 7.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ELChart ActiveX DLL 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ELImageCompare 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ELImageCompareNET Mobile Edition DLL 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ELPLA Analysis of Slab Foundation 9.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ELPhotoX ActiveX DLL 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ELSA Victory II Drivers 4.00.00.0104 (12599).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ELVideoCapure ActiveX DLL 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EM Filter 4.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EaZip 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyPicture 4.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyPlanEx 1.32.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyPostCodes 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyProjectDatabase 6.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyProjectPlan 9.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyPrototype 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyPulse (Palm) 1.30 beta.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyPulse (Pocket PC) 2.31.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyQuery.NET 1.4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyRead 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyRecorder 5.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyRecovery Professional 6.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyReminder 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyRetirement 1.1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasySMPP Component 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasySMPP Component 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasySMS NetShell e2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasySMS Outlook e2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasySMS StarLink e2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasySQL 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasySec Firewall SDK 1.10b.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyShare 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyShots 2.1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyStat Web Statistics 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyStockDataGenerator 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyStockDater 1.1.7.5 Rev. 22.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyStockInfo 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyStore Net 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyStruct Enterprise 4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyTable For AutoCAD 2.1.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyTask Manager 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyTaskEmail 4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyTaskSync 5.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyTrader 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyTweak For Pocket PC 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyVersionControl 8.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyView X 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyViewOrcl 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyWMA 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyWMA Converter 1.22a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyWallpaper 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyWare B2B Commerce 4.004.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyWare Shopping Cart 3.004.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyWatch 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyWebSave 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EasyZip 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easyscreen Screen Capture 3.72.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft Data Access for ISAM 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft Data Access for Unisys LINC Developer 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft JDBC-ODBC Bridge 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft ODBC Join Engine 2.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft ODBC for CODA 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft ODBC-Firebird Driver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft ODBC-Interbase Driver 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft ODBC-JDBC Gateway 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft ODBC-ODBC Bridge 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easysoft XML-ODBC Server 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easystats 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easytemplates Flash Website Templates 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Easytools.com URL Checker 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eat My Dust demo, large version .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eat My Dust demo, medium version .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eat My Dust demo, small version .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eatometer 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eaz-Fix Professional 7.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eazi Website Monitor 1.0.2.196.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eazibo Professional Edition 1.3.22.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eazy Backup 3.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EazyBox for Palm 1.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EazyCode 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EazyDraw 1.8.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EazySQL 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ebay Bargin Hunter 2.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ebay Item Watcher 2.4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ebay Powerseller Articles 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ebay Tycoon--Play the Ebay.com Online MarketPlace Game 1.25.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ebay Typo Auction Locator 3.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ebay and Paypal Calculator 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EbayMinder 5.0.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ebced 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EboBar 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EbookMaker 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ebstra Imperial 2BI.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ebstra-1 2BM.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EcGraph 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecamm Austin Powers Video Phone Sound .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecamm Babylon 5 Doorbell .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecamm Hitchhiker's Guide Beep .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecamm LongBell .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecamm Power Rangers Watch Sound .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecamm R2D2 Droid Chirp .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecamm R2D2 Droid Computing Sound .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecard Magic 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eccentris Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echelon Instant Action patch (non-Pentium, non-AMD) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echelon P11K6 processor patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echelon Wind Warriors E3 trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echelon Wind Warriors Instant Action patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echelon Wind Warriors demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echelon Wind Warriors v1.10 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echelon demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echive Lease Planner 2.1.57.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echo Password Manager 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EchoForum InvisionBoard LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EchoForum PhpBB LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EchoForum Simple Machines LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EchoForum UBB LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EchoForum XMB LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EchoForum vBulletin LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EchoServer for Windows 1.41.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EchoVNC 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Echolink Chat 1.31.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eclarsys PopGrabber 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eclipse 4.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eclipse 5.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eclipse SDK 3.1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eclipse Service Management Software 4.16.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EclipseCrossword 1.2.54.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EcoEuroMillions 1.26.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EcoKeno 3.74.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EcoLotofoot 3.64.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EcoThunderball 1.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecolotosystemes 4.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Econ NetVert 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EconomiZation 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Economic Investment Amount 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Economics Terms Dictionary 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecosuper7 1.16.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecotonoha Screensaver .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecstatica II demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecto 1.7.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecto 2.3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EctoSet Modeller 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ecyware GreenBlue Inspector 1.1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ed Michael Reggie Series - Time Value of Money 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EdPAD 1.1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EdWin 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EdataSOS 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EdenGUI 2.0.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EdenSoft My Logo 1.0.0.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edgar Allan Poe e-Book Introduction 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edge 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edge Of Chaos 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edge2004 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EdgeDesk 4.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edges 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edgeworks 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edgeworks 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EdiTunes 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edit Buddy 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edit Digi Pictures 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edit JFIF Comment 1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edit Prep 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditCNC 3.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditEx 2006.0.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditLive for Java 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Docum
10 Août 2006 21:32:52

Désinstalle ewido.


- Télécharge la version d'évaluation de Kaspersky Antivirus : http://www.kaspersky.com/fr/trials?chapter=186498689 - tutorial : http://www.malekal.com/tutorial_Kaspersky_trial.html
- Après l'installation, lors de la configuration via l'assistant :
- Active la version d'évaluation des licences de 30 jours
- Lance une mise à jour automatique
- Active la protection de base
** Ne lance pas un scan une fois le programme installé et configuré **

- Redémarre en mode sans échec, si tu sais pas comment on fait lis ceci

- Démarre Kaspersky à partir du Menu Démarrer / Tous les programmes / Kaspersky Anti-virus
- Une icone avec un K grisé va apparaître en bas à droite à côté de l'horloge
- Fais un clic droit sur cette icône puis "Analyser le Poste de travail"
- Le scan de l'ordinateur va démarrer
- Une fois le scan terminé, supprime tous les malwares détectés
- Créé un rapport à partir du bouton Enregistrer-sous en bas de la fenêtre, enregistre le fichier sous le nom Kaspersky.txt sur ton bureau

-- Redémarre en mode normal : Menu Démarrer / Arreter / Redémarre l'ordinateur
Attention : dans le cas où l'ordinateur redémarre en boucle en mode sans échec, faire la manipulation inverse en décochant l'option /SAFEBOOT à l'aide de msconfig : voir à nouveau cette page : cliquez-ici

Double-clic sur le fichier Kaspersky.txt qui se trouve sur ton bureau
Copie/colle le rapport ici

Je te conseil de suivre le tutorial ici : http://www.malekal.com/tutorial_Kaspersky_trial.html
10 Août 2006 21:42:08

nts and Settings\Administrateur\Complete\EditLive for XML 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditML Pro 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditOnline 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditPad Lite 6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditPad Pro 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditPlus 2.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditPro 1.57.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditXpert 3.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Editable JavaScript TreeGrid 3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Editable Photo Album (Crocodile Leather Frame) 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Editable Photo Album (Ostrich Leather Cover) 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Editable Photo Album (crocodile leather cover) 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Editable Victoria Photo Album 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edith 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EditiX 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Editor2 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Editor4NAnt 0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Editplus For .NET 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Editstudio 5.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ediware Client 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edmund Spenser, Amoretti & Epithalamion 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edovia Antispam 2005.4.0.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edovia PopShield AntiPopup 1.0.0.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EduProfix 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EduWiz 3.00.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EducLearning 4.2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Educational Compiler ComPas 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Educational Worksheets - Math (Windows XP) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Educational eBooks for Children 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eduinfo InstaM 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Edushield 1.0.62.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EePoker - Free Draw Poker Game 1.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eeppo 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eetee 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Efastar Supply Master 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EffeTech HTTP Sniffer 3.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Effect3D 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Effect3D Studio 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Effective File Search 4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Effective Meetings 1.5.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Effective Site Studio 20043.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Effective Site Studio Photo Edition 20042.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Effects 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Effects Pack (PowerPC) 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EffiValidation 3.0 lite.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EfreeBuy Folder Icon 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EfreeSoft Boss Key 3.30.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EgaImages Screensaver 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egese Business Online System 2006.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egg 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egg Timer Plus 2.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egg vs. Chicken 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egg-stravaganza 1.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EggKey Gateway 1.0.66.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EggOn 0.1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EggRoll 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EggStatic 1.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eggberts Easter Wish 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eggblog 3.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EgoLex 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egochinese 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egold Fee 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egypt Dings 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egypt Tomb Scenes - Papyrus Art 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egypt of David Roberts 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egyptian Addiction 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Egyptian Art Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eiffel API for NeoCore XMS 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EightBall 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eikona 3D 3.2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Einstein 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Einstein 1.54.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Einstein Information Management System 4.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Einstein Quote Generator 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Einstime 4.1a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eisoo AnyBackup CDDVD Edition 1.7 build 1646.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eisoo AnyBackup Home Edition 1.7 build 1646.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EjGSoftwareWeather 1.0.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eject 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ejector 0.7.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ekkeko 1.2.160.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\El Airplane .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\El Scripto 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\El-ixir 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elasto Mania - Elastomaniac.com level pack 1 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elasto Mania - Elastomaniac.com level pack 2 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elasto Mania 1.11a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EldoS KeyLord 1.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EldoS KeyLord 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EldoS PKI Tools 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EldoS TimelyWeb 4.2 build 215.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eldritch Clowns Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ElecKey Express 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elecard DVD Player 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elecard MPEG Player 4.0.4 build 51014.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elecard MPEG-2 Decoder & Streaming Plug-In for WMP 3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elecard MPEG-2 Encoder Pack 4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elecard Mobile Converter 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elecard StreamEye Tools 2 build 50921.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elecard XMuxer Pro 2 build 60502.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ElectionStudio Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electra 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ElectraDrive Sync Engine 4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electrc 2005 1.1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ElectriCalm 3D 2.53.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electric Art Screensaver 1.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electric Bass Companion 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electric Drive Train Simulator 2.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electric Eddie 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ElectricWords Japanese ARM 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ElectricWords Japanese MIPS 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ElectricWords Japanese SH3 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electrical Control Techniques Simulator 1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electrickle .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electrimate 1.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electrist 1.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electro Meridian Analysis System 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electrochemical Simulation POLAROGRAPH.com 4.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\ElectrochemistrySoftware.com 4.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electroguide 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electromechanical Systems Simulator 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electronic Calculator 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electronic Computer Tutor 2004.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electronic Phone Book 1.8.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electronic Reading Planner 2.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electronic Recipe Manager 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electronic Service Control 8.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electronic Stick Notes 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electronics 2.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electronics Genius 1.0.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Electrum Dominoes 1.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elegant Clock 6.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elektron 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elektronika Live 2.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elementec Backup&Compress 1.1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elephant Backup 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elf Bowling - Bocce Style .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elf Bowling 3 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elf Bowling 6 Air Biscuits 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elf Girl Sim Date RPG 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elf Screensaver .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elf Trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elgr 2.33.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elicit 1.1.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eliminad 4.2.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elimination 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elisha Cuthbert Sex-E Screensaver 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elite Jigsaw Puzzle 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elite Keylogger 2.6 build 014.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elite Utilities 9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elite XP Utilities 9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\EliteTyping 2002 4.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ell-Jay 0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ella for Spam Control 1.5.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ella for Spam Free 1.5.6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Ellis Island Database Name Permutation Generator 1.6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elmer (OS X) 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elmer 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elocator 1.4.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elohai Small Business Solutions 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Eloquently Stated 2.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elprime Clock Pro 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elves, Gifts and Cookies Screensaver 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elvis 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elvis Presley Desktop Theme .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elzaris DB Documentor 1.1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Elzed 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Emagic Logic Audio Platinum 6.3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Address Encryptor 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Address Extractor 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Address Theft Blocker 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Announcer 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Archive System 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Caster 2.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Chess 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Cleanser 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Director 5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Effects (OS X) 1.6.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Effects 1.6.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Extraction 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Extractor 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Extractor 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Extractor or Parser by ContentSmartz 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Factory for .NET 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Forwarder 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Magician 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Email Manager 1 revision 4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Entourage S03E04 HDTV XviD-LOL [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\FIFA World Cup Germany 2006 USA 360.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Final Destination 3 DVDSCR ............zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Flight Academy JPN XBOX-RiOT NTSC-J DVD5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Forgot password.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Free MP3s.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\GANTZ Uncut.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HC Image Editor 1.0.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HCFA-1500 Fill & Print 2.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HCmdButtonAttachment 1.2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HD Observer 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HD Projette 2.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HD Tracker 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HD Workbench 1.1.31.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HD-X-Lock 1.20.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDC Monitoring 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDC Pop 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDC Syslog 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDClone Free Edition 3.1.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDD Temperature 1.4.206.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDD Temperature Monitor 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDD Temperature Pro 1.4.206.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDD Temperature SCSI 1.4.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDDlife 2.8.98.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDDlife Pro 2.8.98.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDDlife for Notebooks 2.8.98.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDDlife plug-in for Google Desktop 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDR-Data Harddisk Data Recovery (Admin Package) 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDX4 1.5.1.608.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HDftp 1.3.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HEHE 1.00.18.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HEXPlayer 1.00.0152.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HEXtreme 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HFNetChk.exe 3.86.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HFS - HTTP File Server 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HHReg - HTML Help Registration Utility 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HIDE 1.0.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HIPAA Employee Training Program 1.1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HIPAA Security Rule Assistant 7.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HIPAA Training Program 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HJTHotkey 3.054.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HK Mahjong 5.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HK Telbu 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HLA Adventure 2.32.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HLP to RTF Converter 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HM Basic Unit Converter 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HM Find+Rename 1.1 SP 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HMarqueeCaption 1.1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HarvEX 2.06 build 198.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HashCalc 2.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HashOnClick 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HashParser 0.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HashPass 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HashPic 0.41.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hashgen 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HatchKit 2.5.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hattrick Forever 4.3.0.82.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haunted Forest 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haunted House .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haunted House Echo Sound Effects 1.22.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haunted House Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haunted Woods Screensaver 01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HauteCapture 1.1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HavChat 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hawaii Screensaver 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hawaii Screensaver 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hawaii Screensaver 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hawaii With Bible Verses 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hawaiian WB 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hawaiian Waterfall 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hawke InWeb 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hawker Siddeley Trident Card Model 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haxial Calculator 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haxial DiskCatalog 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haxial KDX Client 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haxial KDX Client 1.32.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haxial KDX Server 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haxial NetFone 1.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haxial Organizer 1.07.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haxial TextEdit 1.61.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Haxial WorldClock 1.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HddLed 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Head Over Heels 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HeadCase SmartAce 2.3.1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HeadRush demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Headache Diary 5.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Headline Fonts 3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Headline Studio 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Headline Typer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Headline Viewer 0.9.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Healing Waves Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Health Boosters & Longevity 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Health Tracker (OS X) 2.1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Health Tracker 2.1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Health and Safety Manager Personal Edition 2006.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Health, Recipes and You E-book 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Health.zip 2.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HealthChecK 1.51.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HealthEngage Diabetes 3.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HealthEngage Diabetes for Mac 3.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HealthFile Plus 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HealthFile Plus 3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HealthFrame Explorer 2.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HealthMonitor 2.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HealthWatch 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Healthy Body Weight 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Healthy Meal Designer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Healthy Weight Diet DSPP 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heard It through the Grapevine Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heart 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heart Doctor 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heart Healing Meditation MP3 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heart Rate Calculator 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heart Sounds Pocket Guide 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heart of Darkness MS Reader e-Book 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heart of Darkness demo 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heart of Iron patch 1.05 patch (Europe) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts 4.1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts Screen Saver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts for Palm OS 1.13.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts of Iron 1.03 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts of Iron 1.04 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts of Iron 1.05 patch (Asian) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts of Iron 1.05 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts of Iron II demo.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts of Iron patch 1.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hearts of Iron patch 1.06c.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heatsoft Automatic Synchronizer 1.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heatsoft Clone Cleaner Lite 1.03 build 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heaven & Hell demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heaven Theme 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heaven or Hell Its Your Choice Ebook 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavenly Blessings Christmas Screensaver 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Gear II demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Gear demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal - FAKK 2 1.02a patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal F.A.K.K. 2 (OS X) 1.02c beta 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal F.A.K.K. 2 demo 1.02 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal F.A.K.K. 2 editing tools 1.02 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal F.A.K.K. 2 patch (UK version) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal F.A.K.K. 2 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal F.A.K.K. 2 updated demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal F.A.K.K.2 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal FAKK 2 1.01 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavy Metal FAKK 2 1.02 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heavyload 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hebbian Recall 1.0.45.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hebrew Alphabet Quizzer 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hebrew Schedule 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HeckleWorks Pro 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hector James 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hegemonia Legions of Iron 1.07 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hegemonia Xmas add-on .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heist demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hekko Kid-Safe Browser 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HeldUp 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heli Heroes Speech update .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heli Heroes demo music add-on .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heli Heroes video update .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heli Rescue 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HeliCOPS demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HeliMaster Elite 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helicon Filter 4.25.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helicon Filter 4.26.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helicon Focus 3.20.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helicon Focus Mac 3.20.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helicon Translator 6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helicopter Race 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelioBar XP 2.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helios Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helium Music Manager 2006 build 5058.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helix 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helix 1.31.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helix 5.2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hell's Gate ScreenSaver 6.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hell-Copter demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HellChess 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hellbender demo 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hellcarrier 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hellhog XP 1.52.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hello Engines Professional 5.1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hello wURLd (Classic) 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hello wURLd 3.5.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help & Manual 4.1.0 build 866.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help Center.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help Creator 1.0.0.56.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help Desk Server 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help Development Studio 1.92.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help Publisher for Dreamweaver 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help Publisher for FrontPage 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help Publisher for Visual Studio 2003 1.00.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help System 101 - Mac 7.1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help System 101 7.1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Help Writer 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpBasePro 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpBreeze HTML HelpJavaHelp Edition 3.0e.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpBreeze for MS Word 2000 3.0c.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpBubble .NET 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpCruiser 1.3.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpDesk - CDCorporate for Access 3.2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpDesk 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpDesk Pro 6.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpDesk VNC 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpExpert 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpLogic 1.0 pr5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpLogic 1.0pr5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpMaster 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpMaster Pro Enterprise Edition 7.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpMeeting Presenter 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpScribble 7.6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpStar Help Desk Software Test Drive 9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpStudio 1.02 build 0011.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpTrans 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HelpTron HTML Help 2.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helperion 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Helpmatic Pro HTML 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hemsoft Crossroads (ARM) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HennieStein 2 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\HepYek 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heparin Dose Manager 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Herbal Life 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Herbal Medicine 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Herbal Remedies 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Herbie Fully Loaded Trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Herbivore Distributed Anti Spam Filter 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Herbs 3.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hercules 3D Prophet II GTS 64MB 7.52.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hercules Game Theater XP Audio Card Driver (Windows 98SEMe2000 5.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hercules Gamesurround Fortissimo III 7.1 Audio Card Driver (Wind 5.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hercules Prophet 4000XT4500 Driver (Windows 2000) 7.103.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hercules Setup Utility 2.7.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hercules Terminator Beast BIOS k3g (120301).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hercules demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Here It Is 1.5.115.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heredis 1000.15.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heretic II updated demo (full version) 1.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heretic demo 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heritage Village 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Herken 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hermetic Stego 6.32.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hermetic Word Frequency Counter 5.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hero Audio Converter 2.7.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hero DVD Player 3.0.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hero Photo Show 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hero Screen Recorder 2.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hero Super Player 3000 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hero Trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hero Video Converter 2.7.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic 2 Editor 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic II demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic III Shadow of Death 3.1 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic IV 1.0 to 1.3 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic IV 1.2 to 1.3 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic IV 1.3 to 2.0 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic IV 2.0 to 2.2 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic IV Equilibris Mod .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic IV editor patch 2.1 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic IV v2.2 to v3.0 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Might and Magic V demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of Redmarch Goblin Bane 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heroes of the Pacific demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Heth Client Utility 5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hex Comparison 1.85.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hex Edit 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hex Editor 3.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hex Editor Delphi5ActiveX Control 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hex Puzzle demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrateur\Complete\Hex Workshop 4.23.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
10 Août 2006 21:45:25

ta pas besoin du rapport ewido???
10 Août 2006 21:53:06

bha là vu la longueur, on va arreter là :) 
Fais la suite.
11 Août 2006 01:15:10

Analyser le Poste de travail
----------------------------
Analysés : 216799
Infectés : 23
Non traités : 0
Lancement : 10/08/2006 22:13:29
Durée : 02:22:09
Fin : 11/08/2006 00:35:38


Infectés
--------
Etat Objet
---- -----
supprimé : numéroteur automatique not-a-virus:p orn-Dialer.Win32.Agent.a Le fichier: D:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0310268.exe/UPX
supprimé : adware not-a-virus:AdWare.Win32.180Solutions Le fichier: D:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP193\A0310269.dll/UPX
supprimé : adware not-a-virus:AdWare.Win32.Altnet.f Le fichier: D:\Program Files\Kazaa\TopSearch.dll
supprimé : adware not-a-virus:AdWare.Win32.Cydoor Le fichier: D:\Program Files\Kazaa\My Shared Folder\Shared\Logiciel\flash get 140.exe/WISE0018.BIN/cd_clint.dll/PECompact
supprimé : adware not-a-virus:AdWare.Win32.Altnet.o Le fichier: D:\Program Files\Kazaa\My Shared Folder\Shared\Logiciel\klite202f.exe/data0009
supprimé : virus Email-Worm.Win32.Dumaru.a Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\03D11F2B/CryptFF
supprimé : virus EICAR-Test-File Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\071F1A98.txt/CryptFF
supprimé : virus EICAR-Test-File Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\08A174F0.txt/CryptFF
supprimé : virus Email-Worm.Win32.Dumaru.a Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\10545C97/CryptFF
supprimé : virus P2P-Worm.Win32.SdDrop.e Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\17B1348D.dat/CryptFF
supprimé : virus Email-Worm.Win32.Dumaru.a Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\230E0063/CryptFF
supprimé : virus Email-Worm.Win32.Dumaru.a Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\25053862/CryptFF
supprimé : virus Virus.Win32.Parite.b Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\3EF3262E.dat/CryptFF
supprimé : virus Email-Worm.Win32.Dumaru.a Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\433E3317/CryptFF
supprimé : virus Email-Worm.Win32.Dumaru.a Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\48EC2C37/CryptFF
supprimé : virus P2P-Worm.Win32.SdDrop.e Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\5BB46C8C.dat/CryptFF
supprimé : virus Email-Worm.Win32.Dumaru.a Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\795742F5/CryptFF
supprimé : virus P2P-Worm.Win32.Tanked.11 Le fichier: D:\Program Files\Norton AntiVirus\Quarantine\7AAD2277.dat/CryptFF
supprimé : adware not-a-virus:AdWare.Win32.Altnet.f Le fichier: D:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP194\A0311444.dll
supprimé : adware not-a-virus:AdWare.Win32.Cydoor Le fichier: D:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP194\A0311445.exe/WISE0018.BIN/cd_clint.dll/PECompact
supprimé : adware not-a-virus:AdWare.Win32.Altnet.o Le fichier: D:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP194\A0311446.exe/data0009
supprimé : adware not-a-virus:AdWare.Win32.Cydoor Le fichier: D:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP194\A0311445.exe
supprimé : adware not-a-virus:AdWare.Win32.Altnet.o Le fichier: D:\System Volume Information\_restore{B790F2B8-EE92-428B-BB51-B1DB3457C79D}\RP194\A0311446.exe

je t'ai mis que ce qui a été suprimé car la suite est bien trop longue et est ce que je dois desinstaller kaspersky car il veut que je fasse des mise a jours pour pas infecté????
11 Août 2006 01:25:47

Désinstaller Kaspersky trial et ewido.

Copie/colle un nouveau rapport HijackThis.
11 Août 2006 10:33:05

Logfile of HijackThis v1.99.1
Scan saved at 10:34:36, on 11/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Messager Wanadoo\Demon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\KLIFO167\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [Demon] C:\PROGRA~1\Messager Wanadoo\Demon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {00000000-0000-0000-0000-000020050660} - http://207.234.185.217/ABoxInst_int15.exe
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://fr.systemdoctor.com/download/2006/cab/SystemDoct...
O17 - HKLM\System\CCS\Services\Tcpip\..\{B76CAE64-09B1-46E2-83A8-B277F4AD9294}: NameServer = 80.10.246.130 80.10.246.3
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

11 Août 2006 10:38:10

Sur HijackThis, coche ligne :
O16 - DPF: {00000000-0000-0000-0000-000020050660} - http://207.234.185.217/ABoxInst_int15.exe
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://fr.systemdoctor.com/downloa [...] all_fr.cab
--> clic sur fix checked

Ca me parait OK :) 


Désactive puis réactive la restauration du système :
- Mode d'emploi Windows XP

je t'invite à jeter un coup d'oeil à ces liens dans la mesure du possible, essaye de rapporter ton infection :

Comment se protéger des virus : - Tout ceci est résume sur cette page : Sécuriser son ordinateur et connaître les menaces

Rapporte ton infection pour faire condamner les auteurs - créer ton message pour faire avancer les choses sur Malware-Complaints, pour faire entendre notre voix, nous devons être le plus nombreux possibles, alors rapport ton infection :
- Voir les règles du forum
- Après t'être enregistré à l'aide du bouton en haut "register", tu as alors sous forme de liste un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).
Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), créé un message dans le sujet "Autres infections" conforme au règle du forum (age, ville, département etc..)
---> http://www.malwarecomplaints.info/viewforum.php?f=10


23 Octobre 2006 09:56:43

Salut, donc j'ai le meme probleme...c'est à dire des pops ups, des antivirus doctor etc ou winantivirus...des pages de rencontres, bref des horreurs..Donc si j'ai bien compris je colle le rapport sous mon message et ca devrait disparaitre.
Si tu peux me donner des conseils car ca me prend bien la tete...tu regardes un dvd et toutes les 15 mn, il y a une page d'antivirus à acheter ou à telecharger..Merci de tes conseils..Logfile of HijackThis v1.99.1
Scan saved at 09:55:23, on 23/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\VideoCompressionCodec\isamonitor.exe
C:\Program Files\VideoCompressionCodec\pmsngr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\VideoCompressionCodec\pmmon.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\VideoCompressionCodec\isamini.exe
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\WINDOWS\system32\MMTray.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Washer\washer.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\eChanblard\emule.exe
C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\admin\Mes documents\lynda.mezhoudi\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {45A4902E-4479-4EAE-A186-8D0F7E4C78DE} - C:\Program Files\Starware316\bin\Starware316.dll
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d9b138c6a53b} - C:\Program Files\VideoCompressionCodec\isaddon.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Starware316 - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - C:\Program Files\Starware316\bin\Starware316.dll
O3 - Toolbar: Protection Bar - {8aed5df3-6e0b-4930-b1a5-f8aa8d757497} - C:\Program Files\VideoCompressionCodec\iesplugin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Fichiers communs\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [SS1HelperStartUp] C:\PROGRA~1\SEASID~1\SS1HEL~1.EXE /partner SS1
O4 - HKLM\..\Run: [BI1HelperStartUp] C:\PROGRA~1\BEACHI~1\BI1HEL~1.EXE /partner BI1
O4 - HKLM\..\Run: [WhenUSearchWHSE] "C:\Program Files\WhenUSearch\whse.exe"
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [VirusBurster] C:\Program Files\VirusBurster\virusburster.exe /h
O4 - HKLM\..\Run: [uwa6pcw] "C:\Program Files\WinAntiVirus Pro 2006\uwa6pcw.exe" -c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.skymasters.biz
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x40...
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5B57C94-7FFE-4E4A-B107-3B1C17DBB7DB}: NameServer = 80.10.246.1 80.10.246.132
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: contrabandists - {dfa61db1-388e-4c87-8d56-540fa229bcb4} - C:\WINDOWS\system32\dpfwu.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe


Malekal_morte a dit :
Bonjour,

ça sent le look2me et alcan

- Télécharge HijackThis sur ton bureau.
- Renomme le fichier HijackThis.exe en Scanner.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste
- Tape Scanner.exe et Appuye sur la touche Entrée.
- Génère un rapport en suivant ces indications :
- Double-clic sur Scanner.exe
- Exécute le et clique sur Do a scan and save log file.
- Le rapport s'ouvre sur leBloc-Note
- Colle le rapport ici, pour cela :
- Menu Edition / Selectionner Tout
- Menu Edition / copier
- Ici dans un nouveau message : clic droit / coller
- N'hésite pas à consulter l'aide HijackThis -

19 Décembre 2006 02:37:41

jai le mm probleme.... alors je vais coller le raport ci dessous.....:

Logfile of HijackThis v1.99.1
Scan saved at 21:30:42, on 18/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 4.0\Reader\AcroRd32.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Samuel Moreau\Bureau\Scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: SponsorAdulto Class - {511F9316-771B-4953-A268-1C36DA667FE9} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\SPONSORADULTO.DLL (file missing)
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - C:\WINDOWS\system32\SearchTool\nsh74.dll
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-436325722327} - C:\WINDOWS\system32\SmartShopper\SmartShopper0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jh...
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts...
O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} (SponsorAdulto Class) - http://ip.sponsoradulto.com/cab/3/fr/SysWebTelecomInt.c...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

19 Décembre 2006 02:47:07

(j'ai comme vrmt mais vrmt besoin daide.... je suis infecter au possible... jai bien beau avoir avast mais.... on va dire quil ne detecte pas tous.... alors svp aider moi...(avertissement je ne suis pas un pro en informatique... jme debrouille mais pas plus...))
19 Décembre 2006 02:50:29

Moi c'est vrmt du trouble... car je vais sur internet tous les jours.... et a chaque CHAQUES page que je load sa me donne un pop-up... que se soi de casino ou des image de.... disons de porn....(jai 15 ans lol) alors svp aider moi!!!!!!!!!!
19 Décembre 2006 18:22:25

ooo et en passant jai oublier de dire qua jai downloader hijack this mais je sais jsuet pas quelle coche y faut que je coche....!
22 Janvier 2007 22:59:56

salut mon ordi a ete infecté par serwab, jai loader hijack this ,le scan est fait il est copier et la sa sarrete la pour moi je ne sais plus quoi faire apres pouvez vous maider svp

voici mon rapport....


Logfile of HijackThis v1.99.1
Scan saved at 16:36:31, on 2007-01-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\fast.exe
C:\Program Files\F-Secure\Common\FSM32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\PROGRA~1\MESSEN~1\Msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
C:\Program Files\PhoTags Express\Photags AutoDetect.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure\Common\FSMA32.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\F-Secure\Common\FSMB32.EXE
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\F-Secure\Common\FCH32.EXE
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\F-Secure\Common\FAMEH32.EXE
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
C:\Program Files\F-Secure\Common\FNRB32.EXE
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure\Common\FIH32.EXE
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Guylaine\Bureau\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SmartShopper - {2BA1C226-EC1B-4471-A65F-D0688AC6EE3A} - C:\Program Files\SmartShopper\Bin\2.0.20\SmrtShpr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [BackgroundSwitcher] C:\WINDOWS\system32\bgswitch.exe
O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\Msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Photags AutoDetect.lnk = C:\Program Files\PhoTags Express\Photags AutoDetect.exe
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\SmartShopper\Bin\2.0.20\SmrtShpr.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\SmartShopper\Bin\2.0.20\SmrtShpr.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls...
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

23 Juin 2007 13:26:54

bonjour, meme probleme, voici le rapport aidé moi s'il vous plait !!!!

probleme resolu : installer Spybot !
Tom's guide dans le monde
  • Allemagne
  • Italie
  • Irlande
  • Royaume Uni
  • Etats Unis
Suivre Tom's Guide
Inscrivez-vous à la Newsletter
  • ajouter à twitter
  • ajouter à facebook
  • ajouter un flux RSS