D.James
Messages postés95Date d'inscriptionsamedi 31 octobre 2009StatutMembreDernière intervention16 juin 2011
-
31 oct. 2009 à 19:48
olivier114
Messages postés1552Date d'inscriptionmercredi 4 mars 2009StatutMembreDernière intervention26 novembre 2013
-
1 nov. 2009 à 17:44
Bonsoir,
Depuis quelque temps j'ai remarqué des choses anormal sur mon ordinateur...
Comme mon UC qui est très haut (entre 80%et 100%)
Toutes les applications qui nécessitent un peu de puissances marchent en saccades (dont les vidéos)
Windows ne peux plus gérer la connexion aux réseaux sans-fil (je change toujours la valeur dans regedit mais ça reviens 2jours après)
et avast ne fonctionne plus ( n'est pas une application win32 valide )
...
J'ai parcouru plusieurs sujets la dessus et j'ai fait une analyse à partir de Malwarebytes et voici le résultat :
--------------------------
Malwarebytes' Anti-Malware 1.41
Version de la base de données: 3043
Windows 5.1.2600 Service Pack 3
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live-Player (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sK9Ou0s (Worm.Bagle) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\srosa (Worm.Bagle) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qcnxjueq (Adware.Navipromo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\flec003.exe (Email.Worm) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\german.exe (Worm.Bagle) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\drvsyskit (Worm.Bagle) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Worm.Bagle) -> No action taken.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Documents and Settings\James\Application Data\m (Trojan.Agent) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld (Worm.Bagle) -> Files: 1808 -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\webserver (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\Incoming (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\lang (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\skins (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\Temp (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config (Worm.Bagle) -> No action taken.
Fichier(s) infecté(s):
C:\Documents and Settings\James\Local Settings\Application Data\qcnxjueq_navps.dat (Adware.Navipromo.H) -> No action taken.
C:\Documents and Settings\James\Local Settings\Application Data\qcnxjueq.dat (Adware.Navipromo.H) -> No action taken.
C:\Documents and Settings\James\Local Settings\Application Data\qcnxjueq.exe (Adware.Navipromo.H) -> No action taken.
C:\Documents and Settings\James\Local Settings\Application Data\qcnxjueq_nav.dat (Adware.Navipromo.H) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\348638093.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP133\A0087331.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\348472390.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\7365000.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\62723031.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\84250921.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\84261687.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\16900375.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_4[2].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_4[5].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_4[6].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087607.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087522.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K3H32YZH\b64_4[2].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087644.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0090662.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088942.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\87987484.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087579.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[1].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087599.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[3].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[4].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[5].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\23102734.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\182640.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[8].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\1161187.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_4[4].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\flec003.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088910.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\171761359.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088943.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[2].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\3424218.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\439908484.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\62729500.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\455569718.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\174266671.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP136\A0089028.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\147812.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[11].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\152328.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\53962031.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[2].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[3].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\105391609.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\169125.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\174277375.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\176920687.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\176926812.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\180687.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\409656000.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\53953484.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\424870375.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\191984765.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\104601671.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_3[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\1317671.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\1327203.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_3[4].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\69206703.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\69248890.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_4[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\80621156.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\23125406.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\86617406.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\86631562.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_4[7].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_4[8].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\488703.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_4[9].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\51961406.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\194312.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\195491968.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\UH5IVI9G\b64_4[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\95721953.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088987.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\455590343.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\30530640.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\30536062.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\257125421.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\520218.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[12].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP136\A0089041.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\83292781.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089125.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\105395125.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\105119546.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\409650531.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\120216125.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\120220671.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[9].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K3H32YZH\b64_4[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_3[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_3[3].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\192003187.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\194078.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\314687.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_4[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\340073234.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\258152625.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\273520968.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\273540609.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\275953.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\80626531.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\S5CNKXG1\b64_3[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\364271203.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\185968.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\TISVV94X\b64_3[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\159215578.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\TISVV94X\b64_4[1].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\172156.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\TISVV94X\b64_4[3].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\439905375.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\UH5IVI9G\b64_3[1].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088986.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\95715031.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP133\A0087332.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087580.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\988312.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087523.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087524.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_3[2].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K3H32YZH\b64_3[1].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089124.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[11].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[4].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[5].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087600.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087605.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087606.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\161644234.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\364286359.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089658.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[9].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_3[4].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_4[5].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[10].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\TISVV94X\b64_4[2].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_3[3].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087828.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087829.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087891.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087892.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[6].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64_3[7].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088883.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[10].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088884.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP136\A0089084.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088909.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP138\A0090964.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_3[2].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088952.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP138\A0091003.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\340260671.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[7].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[8].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP136\A0089027.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089657.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_4[5].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP136\A0089085.exe (Email.Worm) -> No action taken.
C:\WINDOWS\system32\wintems.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_3[5].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64_3[6].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_3[6].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\87992109.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_4[4].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_3[6].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP138\A0091029.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089624.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_4[2].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\RJTBNLSK\b64_4[2].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_4[6].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP138\A0090965.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087784.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64_3[5].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_4[7].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089498.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_4[8].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\984453.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_4[2].jpg (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\996390.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\285812.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089499.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\RJTBNLSK\b64_3[1].jpg (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP138\A0091002.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0090663.exe (Email.Worm) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP138\A0091028.exe (Email.Worm) -> No action taken.
C:\WINDOWS\system32\mdelk.exe (Email.Worm) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\srosa2.sys (Trojan.Agent) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\winupgro.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\PLauncher.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\James\Application Data\m\srvlist.oct (Trojan.Agent) -> No action taken.
C:\Documents and Settings\James\Application Data\m\list.oct (Trojan.Agent) -> No action taken.
C:\Documents and Settings\James\Application Data\m\data.oct (Trojan.Agent) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Compact Query 1.0.1.22.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\69164437.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\87763781.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\CodeX Apps Personal Edition 1.6.0312.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Com-Collector 1.2.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\HTML Search & Replace 1.00.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Charon 0.6.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[10].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\216750.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Checklist 3.8.5.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Context Italian 4.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[4].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[1].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[7].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64[7].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\103814609.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\BoostXP 2.00 (Key).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[11].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Blaze Audio RipEditBurn 2.3.36.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\m\flec006.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[2].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\345828.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\IceView 4.01.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[6].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\DigClock Opera Widget 1.2.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Internet Access Monitor for Novell BorderManager 2.7d.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\iMagic Inventory Software 2.23.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\BeeConverted 1.0.8.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\145937.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\4574453.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\103649453.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[12].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\InstaColl 0.9.5630.40.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[2].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[4].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[4].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\79731953.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\347703546.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\SmartAudio Console 1.0 (Cracked).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\191891953.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Battlefield Vietnam Jungle Warfare Map.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[3].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\CapturePad 0.1 beta.zip (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087525.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[10].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[1].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\409506531.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[3].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64[1].jpg (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP133\A0087330.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[7].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Cute Web Messenger 3.1 (Cracked).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\SplitLink 2.0.7.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\84227656.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K3H32YZH\b64[1].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64[6].jpg (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087646.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087527.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087578.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\339877000.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP134\A0087596.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Audio Catalog 3.7.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\119781109.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\RJTBNLSK\b64[1].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\22933609.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Battlefield 1942 Forgotten Hope mod (file 2 of 2) 0.6.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64[4].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\TISVV94X\b64[1].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\TISVV94X\b64[2].jpg (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088908.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\51868421.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64_3[7].jpg (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088939.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\UH5IVI9G\b64[1].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[3].jpg (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088984.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[5].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[6].jpg (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP136\A0089026.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[8].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\665468.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\IP Guardian 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\150515.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP136\A0089098.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[10].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\154765.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\16372390.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089122.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089497.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\CountLn 1.01.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\CourseForum 5.4.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Crazy sphere 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64[3].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\191546.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087612.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0090660.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K3H32YZH\b64[2].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\152437.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\127531.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087786.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087825.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\133359.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\134843.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\62535859.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP138\A0091104.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087899.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0088882.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\105265812.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\ProShow 2.6.1775.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\downloads.bak (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\C++ Custom Button Class 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\file.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\names.txt (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[2].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Reset Password Management 4.04 Build 1020 [Serial].zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\AC_BootstrapIPs.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\AC_SearchStrings.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[5].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\cancelled.met (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[7].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[8].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\LFZNDTOM\b64[9].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\emfriends.met (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\key_index.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\known.met (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\known2_64.met (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\load_index.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[1].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\preferences.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\preferences.ini (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[5].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\server.met (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64[2].jpg (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP135\A0087611.exe (Worm.Bagle) -> No action taken.
C:\System Volume Information\_restore{0698C787-2F7E-4FDA-A967-472C26B53E0F}\RP137\A0089826.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\statistics.ini (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\StoredSearches.met (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0TGBC7S7\b64[8].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\XproMill 2.1.6.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\YTK Pro 1.5 Build 446.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\[APP.ITA]Kaspersky.Personal.Pro.5+seriale.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\[PS][SLPS-00917].Clock.Tower.The.First.Fear.(J).(AVG).(Human).钟楼.-.é¦–åº¦ææƒ§.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\A123 AVI MPEG WMV MOV MP4 FLV Converter 5.3.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\A4 Audio CD Studio 2.23.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Absolutely Online 2.9.1.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\ActiveInsert 1.10.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\ActiveWords Plus 1.9 (Serial).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\363848031.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\AFL LINK 2.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\AMV Studio 2.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\downloads.txt (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Any Weblock 1.0.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\ASP .NET Icons 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\server.txt (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\ASPPhotoResizer 1.0 (KeyGen).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\AsUnit.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\HappyChecker 1.5.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\RIA-Media Add-ins for Microsoft Office Outlook 2.3.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Rune Death Bowl map.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Secret Squirrel 0.8.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Virtual Vision 1.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Warcraft III Reign Of Chaos Patch 1.18.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\StrataStripe 1.1.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Stretch Mark Fighters 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Iron Space II 1.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\KingConvert For Video Disc Player 3.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\KookieJar 6.3.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Kruptos 2 3.0.0.21 Build 1.0.0.34.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\LectriCalc for Windows 2.1.2 (Key+Serial).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Lexus IS300 Screensaver 1.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Marwan Worms 1.1.32.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\McAfee.Internet.Security.Suite.9.-2007-.FULL.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[8].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\QJARMHI3\b64[9].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\src_index.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Mobile Device Icons.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Digital GEM Plug-in 1.0.4.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Digital Physiognomy 1.62.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\E.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Earth 3D Space Tour Screensaver 1.0 [Key+Serial].zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\eAutoRun 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Elecard StreamEye Tools 2.9.1.61206.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Error Fix 3.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Evergreen Rebrand 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Excel Swap (Reverse) Rows & Columns Software 1.1 (Cracked).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Field Lines Screensaver 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\File Renamer 1.2.0.3.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\File System Reviewer 1.1 Build 17.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Firefly 0.4.1.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\FmPro Migrator 3.75.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Free Matching Hearts 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\FreshOutline 1.4.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\FxIF 0.2.3.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Gallery 2.7.5.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Geiss 4.28.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Golden SpotsMap of USA 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Half-Life Pirates Vikings Knights Mod 2.1 beta.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Timesheet 2.14.3 (KeyGen).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Unreal Tournament 2003 - Coulour beta deathmatch map.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\USB Disk Security 5.0.0.66.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\174036531.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K1A7OXMF\b64[9].jpg (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\SyncCell for Motorola 2.0.4.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\WinSurvey 3.2.8.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\StripShow Screensaver 1.7.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Symantec.Ghost.v8.0.Corporate-SOS.ShareReactor.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\273322875.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Teddy Factory.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\The Professional Undelete 4.8.5.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\ThumbsPlus 7.0 SP1 Build 2234 KeyGen.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\176779171.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\170626453.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Mcafee.Virusscan.Enterprise.v8.0i Patch 11.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\MCS Firewall 5.2.0.4.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Media Studio Lite 1.4.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\WirelessMon 3.0 Build 1002.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\MorseCoder 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\MP3Producer 2.57 [Key].zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\My MemoPad 1.2.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\MyLife Organized 1.9.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\NetSim 2.0 With Crack.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Nod32.2.51.30.ITA.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\NOD32.7.29.DOS.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\NxS XFade 0.7.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\office Convert Pdf to Jpg Jpeg Tiff 6.2.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Open Video Converter 3.0.3.620 [With Crack].zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\OraSphere Query Master 1.4.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Picture Emailer 8.2.294.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Picword 1.8 (KeyGen).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Whizlabs SCJP 1.4 Preparation Kit 6.0.1 (Serial).zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Quick Notes Plus 5.0.0.48 [Key+Serial].zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\QuickFolders 0.4.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\RAStik 1.2.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\RecallWorks Invoicing 2.9.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Remote Queue Manager Professional 5.20.173.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\257932750.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\Resource Tuner Console 1.98.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\95566140.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\AC_ServerMetURLs.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\454934250.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\clients.met (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\clients.met.bak (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\cryptkey.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\256906312.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\113062.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\209234.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\210968.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\699078.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\nodes.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\945843.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\439832859.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\preferencesKad.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\161344046.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\server_met.old (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\config\shareddir.dat (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\120324515.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\424645031.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\drivers\downld\456312.exe (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\XDesk 3.9.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\AdSpy Eliminator 1.0.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\hidires\WDIR\AnalogX LinkExaminer 1.01.zip (Worm.Bagle) -> No action taken.
C:\Documents and Settings\James\Application Data\
olivier114
Messages postés1552Date d'inscriptionmercredi 4 mars 2009StatutMembreDernière intervention26 novembre 2013104 31 oct. 2009 à 19:59
Ton PC est infecté par l'ad-aware Navipromo/Magic Control qui affiche des publicités intempestives.
Il s'installe via certains programmes, dont ceux-ci :
/!\ Fais attention de ne pas faire la même erreur, donc évite ces programmes /!\
▶ Télécharge sur le bureau Navilog1
*Si ton antivirus s'affole , le désactiver
▶ sous vista : Clic-droit sur le raccourci Navilog1 présent sur le bureau et choisis "Exécuter en tant qu'administrateur"
▶ Sous XP : double-clic dessus pour l'installer et le lancer
▶ Quand installé
▶ taper F
▶ Appuyer sur une touche jusqu' arriver aux options
▶ Choisir l'option 1 (recherche/désinfection automatique)
▶ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes
D.James
Messages postés95Date d'inscriptionsamedi 31 octobre 2009StatutMembreDernière intervention16 juin 201125 31 oct. 2009 à 21:52
Salut Olivier114,
D'abord merci pour ta réponse.
Au redémmarrage de mon Ordi j'ai eu des problèmes ...
peut-être à cause qu'à un moment j'ai vu qu'il etait marqué
"impossible de... .exe" je sais plus exactement mais j'ai laissé faire et ça s'est terminé tout seul
Quand j'ai redémarré on auraitt dit qu'il manquait des composants de windows donc j'ai éteind et rallumer et la il y a eu quelque chose comme une récupération de donnée ou autre chose et tout est redevenu normal ...
Et voici le rapport (j'ai toruvé "cleanavi.txt dans C: ) :
Fix Navipromo version 4.0.3 commencé le sam. 31/10/2009 20:58:42,03
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 21.10.2009 à 22h00 par IL-MAFIOSO
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Atom(TM) CPU N270 @ 1.60GHz )
BIOS : BIOS Date: 10/17/08 10:15:53 Ver: 08.00.12
USER : James ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:79 Go (Free:3 Go)
D:\ (Local Disk) - NTFS - Total:61 Go (Free:57 Go)