Aidez moi svp
Tchoupi51
Messages postés
11
Statut
Membre
-
bernie61 -
bernie61 -
Bonjour,
J'ai chopé un virus sur msn et depuis j'ai beau scanner et rescanner, j'arrive pas à m'en débarrasser, ils reviennent. Je ne sais plus quoi faire aidez moi SVP
Voici une partie de mes scanns
4/05/2005,20:27:54 WARNING: Contains signature of the VBS script virus VBS/LoveLetter.D!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\THC2475N\ANVBS[1].HTM
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
14/05/2005,22:19:47 [LOGON] Connection request by remote computer. Establishing secure communication channel.
14/05/2005,22:19:47 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa893b166.
14/05/2005,22:19:57 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\JOCKER[1].EXE
File has been deleted!
14/05/2005,22:20:21 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\WINDOWS\SYSTEM32\JOCKER.EXE
File has been deleted!
14/05/2005,22:20:35 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\QJWFDE3Y\REGULAR_PLUGIN[1].EXE
File has been deleted!
14/05/2005,22:20:41 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\WINDOWS\SYSTEM32\YSBINSTALL_1000489_3.EXE
File has been deleted!
14/05/2005,22:20:29 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
14/05/2005,22:20:50 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
14/05/2005,22:21:29 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
14/05/2005,22:21:32 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
14/05/2005,22:21:57 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
14/05/2005,22:23:11 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14/05/2005,22:23:16 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14/05/2005,22:23:20 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14/05/2005,22:38:28 [LOGON] Connection request by remote computer. Establishing secure communication channel.
14/05/2005,22:38:29 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa8e0932d.
14/05/2005,22:38:40 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\JOCKER[1].EXE
File has been deleted!
14/05/2005,22:39:01 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\WINDOWS\SYSTEM32\JOCKER.EXE
File has been deleted!
14/05/2005,22:39:10 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\REGULAR_PLUGIN[1].EXE
File has been deleted!
14/05/2005,22:39:18 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\WINDOWS\SYSTEM32\YSBINSTALL_1000489_3.EXE
File has been deleted!
15/05/2005,00:18:47 [INFO] Stop Filter Device.
15/05/2005,00:18:52 AVGuard service has been stopped!
15/05/2005,00:20:00 ---------------------------------------------------------
15/05/2005,00:20:00 [INIT] The AVGuard Service is starting.
15/05/2005,00:20:09 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,00:20:29 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,00:20:29 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaab80c5.
15/05/2005,00:22:31 [INFO] Start Filter Device.
15/05/2005,00:22:31 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,00:22:32 AVGuard has been started successfully!
15/05/2005,00:25:57 [INFO] Stop Filter Device.
15/05/2005,00:26:03 AVGuard service has been stopped!
15/05/2005,12:42:22 ---------------------------------------------------------
15/05/2005,12:42:22 [INIT] The AVGuard Service is starting.
15/05/2005,12:42:39 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,12:42:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,12:42:40 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa472d.
15/05/2005,12:43:16 [INFO] Start Filter Device.
15/05/2005,12:44:55 [INFO] Start Filter Device.
15/05/2005,12:44:55 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,12:44:55 AVGuard has been started successfully!
15/05/2005,12:46:57 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\REGULAR_PLUGIN[1].EXE
File has been deleted!
15/05/2005,12:47:13 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\YSBINSTALL_1000489_3.EXE
File has been deleted!
15/05/2005,12:46:20 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SHMJW92R\JOCKER[1].EXE
File has been deleted!
15/05/2005,12:47:43 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
15/05/2005,13:04:44 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,13:04:44 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaabf8829.
15/05/2005,13:10:50 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,13:10:50 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaab01244.
15/05/2005,14:00:17 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,14:00:17 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaed540e.
15/05/2005,15:22:52 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,15:22:52 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa39337b.
15/05/2005,16:00:03 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,16:00:03 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa1f0fed.
15/05/2005,16:03:22 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\I8M97LCS\PROMPT[1].PHP
File has been deleted!
15/05/2005,16:08:16 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:08:38 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:23 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to move the file to the quarantine directory:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:37 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:43 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:52 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\WEBSITE[1].OCX
15/05/2005,16:25:56 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:26:01 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:26:11 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
15/05/2005,16:26:17 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:26:22 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:27:15 [INFO] Stop Filter Device.
15/05/2005,16:27:21 AVGuard service has been stopped!
15/05/2005,16:28:15 ---------------------------------------------------------
15/05/2005,16:28:15 [INIT] The AVGuard Service is starting.
15/05/2005,16:28:17 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,16:28:33 [INFO] Start Filter Device.
15/05/2005,16:28:33 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,16:28:33 AVGuard has been started successfully!
15/05/2005,16:37:59 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,16:37:59 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa3d880.
15/05/2005,16:38:26 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\JOCKER[1].EXE
File has been deleted!
15/05/2005,16:38:41 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
15/05/2005,16:39:01 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SHMJW92R\REGULAR_PLUGIN[1].EXE
File has been deleted!
15/05/2005,16:39:07 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\YSBINSTALL_1000489_3.EXE
File has been deleted!
15/05/2005,17:01:26 [INFO] Stop Filter Device.
15/05/2005,17:01:29 AVGuard service has been stopped!
15/05/2005,17:02:22 ---------------------------------------------------------
15/05/2005,17:02:22 [INIT] The AVGuard Service is starting.
15/05/2005,17:02:23 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,17:02:39 [INFO] Start Filter Device.
15/05/2005,17:02:39 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,17:02:39 AVGuard has been started successfully!
15/05/2005,17:10:33 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,17:10:33 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa2ac06.
15/05/2005,17:11:02 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\RAR.EXE
File has been deleted!
15/05/2005,17:11:31 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\VONNER.EXE
File has been deleted!
15/05/2005,17:12:30 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
15/05/2005,17:12:48 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
15/05/2005,17:12:55 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
15/05/2005,17:13:13 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
15/05/2005,17:13:35 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
15/05/2005,17:13:48 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
15/05/2005,17:33:50 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\PROMPT[1].PHP
File has been deleted!
15/05/2005,17:38:48 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
File has been deleted!
15/05/2005,17:38:57 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:13 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:18 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:41 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:46 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:52 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:40:02 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:40:06 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:40:12 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,18:20:52 WARNING: Contains signature of the backdoor control software BDC/Gaward.!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\SS3[1].EXE
15/05/2005,18:21:15 WARNING: Contains signature of the backdoor control software BDC/Gaward.!
C:\DOCUMENTS AND SETTINGS\PAULINE00\SS3.EXE
File has been deleted!
15/05/2005,17:46:44 [INFO] Stop Filter Device.
15/05/2005,17:46:52 AVGuard service has been stopped!
15/05/2005,17:47:56 ---------------------------------------------------------
15/05/2005,17:47:56 [INIT] The AVGuard Service is starting.
15/05/2005,17:48:06 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,17:49:21 [INFO] Start Filter Device.
15/05/2005,17:49:21 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,17:49:21 AVGuard has been started successfully!
15/05/2005,17:50:57 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,17:50:57 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa9d1a6.
15/05/2005,18:59:26 [INFO] Stop Filter Device.
15/05/2005,18:59:28 AVGuard service has been stopped!
16/05/2005,13:02:27 ---------------------------------------------------------
16/05/2005,13:02:27 [INIT] The AVGuard Service is starting.
16/05/2005,13:02:28 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
16/05/2005,13:02:41 [INFO] Start Filter Device.
16/05/2005,13:02:41 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
16/05/2005,13:02:41 AVGuard has been started successfully!
16/05/2005,13:02:59 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,13:03:00 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa5e38.
16/05/2005,15:39:10 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,15:39:10 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa255a48.
16/05/2005,17:31:26 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,17:31:27 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa5c1685.
16/05/2005,18:24:58 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,18:24:58 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xab8d164d.
16/05/2005,19:39:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,19:39:40 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xabc68a39.
16/05/2005,20:43:56 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,20:43:56 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xab0c5ec5.
16/05/2005,20:45:20 [INFO] Stop Filter Device.
16/05/2005,20:45:25 AVGuard service has been stopped!
17/05/2005,12:21:55 ---------------------------------------------------------
17/05/2005,12:21:55 [INIT] The AVGuard Service is starting.
17/05/2005,12:21:56 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
17/05/2005,12:22:11 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,12:22:11 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa1849.
17/05/2005,12:22:21 [INFO] Start Filter Device.
17/05/2005,12:22:21 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
17/05/2005,12:22:21 AVGuard has been started successfully!
17/05/2005,12:25:32 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SPQLSTS3\PROMPT[1].HTM
File has been deleted!
17/05/2005,12:35:20 [INFO] Stop Filter Device.
17/05/2005,12:35:23 AVGuard service has been stopped!
17/05/2005,15:49:22 ---------------------------------------------------------
17/05/2005,15:49:22 [INIT] The AVGuard Service is starting.
17/05/2005,15:49:30 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
17/05/2005,15:49:30 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,15:49:30 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa0769.
17/05/2005,15:49:36 [INFO] Start Filter Device.
17/05/2005,15:49:36 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
17/05/2005,15:49:36 AVGuard has been started successfully!
17/05/2005,16:00:52 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,16:01:01 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
17/05/2005,17:50:20 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,17:50:20 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaac5e68e.
17/05/2005,17:50:49 [INFO] Stop Filter Device.
17/05/2005,17:50:58 AVGuard service has been stopped!
17/05/2005,17:51:51 ---------------------------------------------------------
17/05/2005,17:51:51 [INIT] The AVGuard Service is starting.
17/05/2005,17:51:59 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
17/05/2005,17:52:00 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,17:52:00 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa1d53.
17/05/2005,17:52:04 [INFO] Start Filter Device.
17/05/2005,17:52:04 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
17/05/2005,17:52:04 AVGuard has been started successfully!
17/05/2005,17:52:36 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\RAR.EXE
File has been deleted!
17/05/2005,17:52:59 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\VONNER.EXE
File has been deleted!
17/05/2005,17:55:53 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\E1SR67G7\PROMPT[1].HTM
File has been deleted!
17/05/2005,18:00:55 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1URKDEN\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,18:01:02 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1URKDEN\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,18:04:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,18:04:41 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa6f81b.
17/05/2005,18:04:54 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
17/05/2005,18:05:00 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
17/05/2005,19:00:32 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1URKDEN\WEBSITE[1].OCX
File has been deleted!
17/05/2005,19:15:13 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\I8M97LCS\WEBSITE[1].OCX
File has been deleted!
17/05/2005,18:55:48 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6BM9MHS1\PROMPT[1].HTM
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,19:15:20 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6BM9MHS1\PROMPT[1].HTM
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,19:19:45 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6BM9MHS1\PROMPT[1].HTM
File has been deleted!
17/05/2005,19:25:58 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\PROMPT[1].HTM
File has been deleted!
17/05/2005,19:42:08 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,19:42:08 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaacf2661.
18/05/2005,01:32:22 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,01:32:23 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xab0c9f65.
18/05/2005,08:27:41 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,08:27:41 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa988c715.
18/05/2005,10:28:21 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,10:28:21 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa93a4d76.
18/05/2005,13:17:24 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,13:17:25 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xae811a92.
18/05/2005,13:42:03 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\JOCKER[1].EXE
File has been deleted!
18/05/2005,13:44:50 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
18/05/2005,13:44:38 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
Unable to delete the file:
0x00000002 - Le fichier spécifié est introuvable.
18/05/2005,13:44:04 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
Unable to delete the file:
0x00000002 - Le fichier spécifié est introuvable.
18/05/2005,14:52:45 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,14:52:45 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xae28536a.
18/05/2005,15:52:47 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,15:52:47 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xae134644.
18/05/2005,18:41:01 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,18:41:01 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaff95fc3.
18/05/2005,21:42:17 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,21:42:18 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaf53403a.
18/05/2005,21:48:37 [INFO] Stop Filter Device.
18/05/2005,21:48:44 AVGuard service has been stopped!
18/05/2005,23:02:57 ---------------------------------------------------------
18/05/2005,23:02:57 [INIT] The AVGuard Service is starting.
18/05/2005,23:03:18 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
18/05/2005,23:03:19 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,23:03:19 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa570f.
18/05/2005,23:03:38 [INFO] Start Filter Device.
18/05/2005,23:03:38 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
18/05/2005,23:03:38 AVGuard has been started successfully!
18/05/2005,23:05:16 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
18/05/2005,23:05:28 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
18/05/2005,23:05:55 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\NFTQIYRZ\JOCKER[1].EXE
File has been deleted!
18/05/2005,23:05:58 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
18/05/2005,23:06:56 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\NFTQIYRZ\REGULAR_PLUGIN[1].EXE
File has been deleted!
18/05/2005,23:06:58 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\YSBINSTALL_1000489_3.EXE
File has been deleted!
18/05/2005,23:07:10 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
18/05/2005,23:08:08 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
18/05/2005,23:09:26 WARNING: Is the Trojan horse TR/Qhosts.Script.A!
C:\WINDOWS\SYSTEM32\HOSTS
File has been deleted!
18/05/2005,23:09:31 WARNING: Contains signature of the worm Worm/Randon.AB.4!
C:\WINDOWS\SYSTEM32\PALSP.EXE
File has been deleted!
18/05/2005,23:09:34 WARNING: Contains a signature of the (dangerous) backdoor program BDS/HacDef.073.B.4 Backdoor server programs !
C:\WINDOWS\SYSTEM32\ZEMA
File has been deleted!
18/05/2005,23:10:32 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
18/05/2005,23:12:47 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
18/05/2005,23:13:11 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
18/05/2005,23:13:28 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
J'ai chopé un virus sur msn et depuis j'ai beau scanner et rescanner, j'arrive pas à m'en débarrasser, ils reviennent. Je ne sais plus quoi faire aidez moi SVP
Voici une partie de mes scanns
4/05/2005,20:27:54 WARNING: Contains signature of the VBS script virus VBS/LoveLetter.D!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\THC2475N\ANVBS[1].HTM
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
14/05/2005,22:19:47 [LOGON] Connection request by remote computer. Establishing secure communication channel.
14/05/2005,22:19:47 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa893b166.
14/05/2005,22:19:57 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\JOCKER[1].EXE
File has been deleted!
14/05/2005,22:20:21 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\WINDOWS\SYSTEM32\JOCKER.EXE
File has been deleted!
14/05/2005,22:20:35 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\QJWFDE3Y\REGULAR_PLUGIN[1].EXE
File has been deleted!
14/05/2005,22:20:41 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\WINDOWS\SYSTEM32\YSBINSTALL_1000489_3.EXE
File has been deleted!
14/05/2005,22:20:29 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
14/05/2005,22:20:50 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
14/05/2005,22:21:29 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
14/05/2005,22:21:32 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
14/05/2005,22:21:57 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
14/05/2005,22:23:11 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14/05/2005,22:23:16 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14/05/2005,22:23:20 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14/05/2005,22:38:28 [LOGON] Connection request by remote computer. Establishing secure communication channel.
14/05/2005,22:38:29 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa8e0932d.
14/05/2005,22:38:40 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\JOCKER[1].EXE
File has been deleted!
14/05/2005,22:39:01 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\WINDOWS\SYSTEM32\JOCKER.EXE
File has been deleted!
14/05/2005,22:39:10 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\REGULAR_PLUGIN[1].EXE
File has been deleted!
14/05/2005,22:39:18 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\WINDOWS\SYSTEM32\YSBINSTALL_1000489_3.EXE
File has been deleted!
15/05/2005,00:18:47 [INFO] Stop Filter Device.
15/05/2005,00:18:52 AVGuard service has been stopped!
15/05/2005,00:20:00 ---------------------------------------------------------
15/05/2005,00:20:00 [INIT] The AVGuard Service is starting.
15/05/2005,00:20:09 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,00:20:29 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,00:20:29 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaab80c5.
15/05/2005,00:22:31 [INFO] Start Filter Device.
15/05/2005,00:22:31 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,00:22:32 AVGuard has been started successfully!
15/05/2005,00:25:57 [INFO] Stop Filter Device.
15/05/2005,00:26:03 AVGuard service has been stopped!
15/05/2005,12:42:22 ---------------------------------------------------------
15/05/2005,12:42:22 [INIT] The AVGuard Service is starting.
15/05/2005,12:42:39 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,12:42:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,12:42:40 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa472d.
15/05/2005,12:43:16 [INFO] Start Filter Device.
15/05/2005,12:44:55 [INFO] Start Filter Device.
15/05/2005,12:44:55 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,12:44:55 AVGuard has been started successfully!
15/05/2005,12:46:57 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\REGULAR_PLUGIN[1].EXE
File has been deleted!
15/05/2005,12:47:13 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\YSBINSTALL_1000489_3.EXE
File has been deleted!
15/05/2005,12:46:20 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SHMJW92R\JOCKER[1].EXE
File has been deleted!
15/05/2005,12:47:43 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
15/05/2005,13:04:44 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,13:04:44 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaabf8829.
15/05/2005,13:10:50 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,13:10:50 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaab01244.
15/05/2005,14:00:17 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,14:00:17 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaed540e.
15/05/2005,15:22:52 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,15:22:52 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa39337b.
15/05/2005,16:00:03 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,16:00:03 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa1f0fed.
15/05/2005,16:03:22 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\I8M97LCS\PROMPT[1].PHP
File has been deleted!
15/05/2005,16:08:16 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:08:38 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:23 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to move the file to the quarantine directory:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:37 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:43 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:52 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\WEBSITE[1].OCX
15/05/2005,16:25:56 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:26:01 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:26:11 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
15/05/2005,16:26:17 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:26:22 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:27:15 [INFO] Stop Filter Device.
15/05/2005,16:27:21 AVGuard service has been stopped!
15/05/2005,16:28:15 ---------------------------------------------------------
15/05/2005,16:28:15 [INIT] The AVGuard Service is starting.
15/05/2005,16:28:17 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,16:28:33 [INFO] Start Filter Device.
15/05/2005,16:28:33 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,16:28:33 AVGuard has been started successfully!
15/05/2005,16:37:59 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,16:37:59 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa3d880.
15/05/2005,16:38:26 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\JOCKER[1].EXE
File has been deleted!
15/05/2005,16:38:41 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
15/05/2005,16:39:01 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SHMJW92R\REGULAR_PLUGIN[1].EXE
File has been deleted!
15/05/2005,16:39:07 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\YSBINSTALL_1000489_3.EXE
File has been deleted!
15/05/2005,17:01:26 [INFO] Stop Filter Device.
15/05/2005,17:01:29 AVGuard service has been stopped!
15/05/2005,17:02:22 ---------------------------------------------------------
15/05/2005,17:02:22 [INIT] The AVGuard Service is starting.
15/05/2005,17:02:23 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,17:02:39 [INFO] Start Filter Device.
15/05/2005,17:02:39 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,17:02:39 AVGuard has been started successfully!
15/05/2005,17:10:33 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,17:10:33 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa2ac06.
15/05/2005,17:11:02 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\RAR.EXE
File has been deleted!
15/05/2005,17:11:31 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\VONNER.EXE
File has been deleted!
15/05/2005,17:12:30 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
15/05/2005,17:12:48 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
15/05/2005,17:12:55 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
15/05/2005,17:13:13 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
15/05/2005,17:13:35 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
15/05/2005,17:13:48 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
15/05/2005,17:33:50 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\PROMPT[1].PHP
File has been deleted!
15/05/2005,17:38:48 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
File has been deleted!
15/05/2005,17:38:57 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:13 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:18 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:41 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:46 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:52 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:40:02 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:40:06 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:40:12 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,18:20:52 WARNING: Contains signature of the backdoor control software BDC/Gaward.!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\SS3[1].EXE
15/05/2005,18:21:15 WARNING: Contains signature of the backdoor control software BDC/Gaward.!
C:\DOCUMENTS AND SETTINGS\PAULINE00\SS3.EXE
File has been deleted!
15/05/2005,17:46:44 [INFO] Stop Filter Device.
15/05/2005,17:46:52 AVGuard service has been stopped!
15/05/2005,17:47:56 ---------------------------------------------------------
15/05/2005,17:47:56 [INIT] The AVGuard Service is starting.
15/05/2005,17:48:06 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,17:49:21 [INFO] Start Filter Device.
15/05/2005,17:49:21 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,17:49:21 AVGuard has been started successfully!
15/05/2005,17:50:57 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,17:50:57 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa9d1a6.
15/05/2005,18:59:26 [INFO] Stop Filter Device.
15/05/2005,18:59:28 AVGuard service has been stopped!
16/05/2005,13:02:27 ---------------------------------------------------------
16/05/2005,13:02:27 [INIT] The AVGuard Service is starting.
16/05/2005,13:02:28 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
16/05/2005,13:02:41 [INFO] Start Filter Device.
16/05/2005,13:02:41 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
16/05/2005,13:02:41 AVGuard has been started successfully!
16/05/2005,13:02:59 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,13:03:00 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa5e38.
16/05/2005,15:39:10 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,15:39:10 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa255a48.
16/05/2005,17:31:26 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,17:31:27 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa5c1685.
16/05/2005,18:24:58 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,18:24:58 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xab8d164d.
16/05/2005,19:39:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,19:39:40 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xabc68a39.
16/05/2005,20:43:56 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,20:43:56 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xab0c5ec5.
16/05/2005,20:45:20 [INFO] Stop Filter Device.
16/05/2005,20:45:25 AVGuard service has been stopped!
17/05/2005,12:21:55 ---------------------------------------------------------
17/05/2005,12:21:55 [INIT] The AVGuard Service is starting.
17/05/2005,12:21:56 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
17/05/2005,12:22:11 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,12:22:11 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa1849.
17/05/2005,12:22:21 [INFO] Start Filter Device.
17/05/2005,12:22:21 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
17/05/2005,12:22:21 AVGuard has been started successfully!
17/05/2005,12:25:32 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SPQLSTS3\PROMPT[1].HTM
File has been deleted!
17/05/2005,12:35:20 [INFO] Stop Filter Device.
17/05/2005,12:35:23 AVGuard service has been stopped!
17/05/2005,15:49:22 ---------------------------------------------------------
17/05/2005,15:49:22 [INIT] The AVGuard Service is starting.
17/05/2005,15:49:30 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
17/05/2005,15:49:30 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,15:49:30 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa0769.
17/05/2005,15:49:36 [INFO] Start Filter Device.
17/05/2005,15:49:36 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
17/05/2005,15:49:36 AVGuard has been started successfully!
17/05/2005,16:00:52 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,16:01:01 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
17/05/2005,17:50:20 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,17:50:20 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaac5e68e.
17/05/2005,17:50:49 [INFO] Stop Filter Device.
17/05/2005,17:50:58 AVGuard service has been stopped!
17/05/2005,17:51:51 ---------------------------------------------------------
17/05/2005,17:51:51 [INIT] The AVGuard Service is starting.
17/05/2005,17:51:59 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
17/05/2005,17:52:00 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,17:52:00 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa1d53.
17/05/2005,17:52:04 [INFO] Start Filter Device.
17/05/2005,17:52:04 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
17/05/2005,17:52:04 AVGuard has been started successfully!
17/05/2005,17:52:36 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\RAR.EXE
File has been deleted!
17/05/2005,17:52:59 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\VONNER.EXE
File has been deleted!
17/05/2005,17:55:53 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\E1SR67G7\PROMPT[1].HTM
File has been deleted!
17/05/2005,18:00:55 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1URKDEN\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,18:01:02 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1URKDEN\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,18:04:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,18:04:41 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa6f81b.
17/05/2005,18:04:54 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
17/05/2005,18:05:00 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
17/05/2005,19:00:32 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1URKDEN\WEBSITE[1].OCX
File has been deleted!
17/05/2005,19:15:13 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\I8M97LCS\WEBSITE[1].OCX
File has been deleted!
17/05/2005,18:55:48 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6BM9MHS1\PROMPT[1].HTM
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,19:15:20 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6BM9MHS1\PROMPT[1].HTM
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,19:19:45 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6BM9MHS1\PROMPT[1].HTM
File has been deleted!
17/05/2005,19:25:58 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\PROMPT[1].HTM
File has been deleted!
17/05/2005,19:42:08 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,19:42:08 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaacf2661.
18/05/2005,01:32:22 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,01:32:23 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xab0c9f65.
18/05/2005,08:27:41 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,08:27:41 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa988c715.
18/05/2005,10:28:21 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,10:28:21 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa93a4d76.
18/05/2005,13:17:24 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,13:17:25 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xae811a92.
18/05/2005,13:42:03 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\JOCKER[1].EXE
File has been deleted!
18/05/2005,13:44:50 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
18/05/2005,13:44:38 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
Unable to delete the file:
0x00000002 - Le fichier spécifié est introuvable.
18/05/2005,13:44:04 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
Unable to delete the file:
0x00000002 - Le fichier spécifié est introuvable.
18/05/2005,14:52:45 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,14:52:45 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xae28536a.
18/05/2005,15:52:47 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,15:52:47 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xae134644.
18/05/2005,18:41:01 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,18:41:01 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaff95fc3.
18/05/2005,21:42:17 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,21:42:18 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaf53403a.
18/05/2005,21:48:37 [INFO] Stop Filter Device.
18/05/2005,21:48:44 AVGuard service has been stopped!
18/05/2005,23:02:57 ---------------------------------------------------------
18/05/2005,23:02:57 [INIT] The AVGuard Service is starting.
18/05/2005,23:03:18 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
18/05/2005,23:03:19 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,23:03:19 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa570f.
18/05/2005,23:03:38 [INFO] Start Filter Device.
18/05/2005,23:03:38 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
18/05/2005,23:03:38 AVGuard has been started successfully!
18/05/2005,23:05:16 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
18/05/2005,23:05:28 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
18/05/2005,23:05:55 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\NFTQIYRZ\JOCKER[1].EXE
File has been deleted!
18/05/2005,23:05:58 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
18/05/2005,23:06:56 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\NFTQIYRZ\REGULAR_PLUGIN[1].EXE
File has been deleted!
18/05/2005,23:06:58 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\YSBINSTALL_1000489_3.EXE
File has been deleted!
18/05/2005,23:07:10 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
18/05/2005,23:08:08 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
18/05/2005,23:09:26 WARNING: Is the Trojan horse TR/Qhosts.Script.A!
C:\WINDOWS\SYSTEM32\HOSTS
File has been deleted!
18/05/2005,23:09:31 WARNING: Contains signature of the worm Worm/Randon.AB.4!
C:\WINDOWS\SYSTEM32\PALSP.EXE
File has been deleted!
18/05/2005,23:09:34 WARNING: Contains a signature of the (dangerous) backdoor program BDS/HacDef.073.B.4 Backdoor server programs !
C:\WINDOWS\SYSTEM32\ZEMA
File has been deleted!
18/05/2005,23:10:32 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
18/05/2005,23:12:47 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
18/05/2005,23:13:11 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
18/05/2005,23:13:28 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14 réponses
salut
utilise ceci et ensuite refait un scan
a faire hors connection
http://pageperso.aol.fr/Balltrap34/CleanUp312.exe
utilise ceci et ensuite refait un scan
a faire hors connection
http://pageperso.aol.fr/Balltrap34/CleanUp312.exe
voici mon scann avec clean up
CleanUp! started on 05/19/05 15:55:12.
C:\Documents and Settings\Pauline00\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
'Typed URLs' (Internet Explorer) - removed from the registry.
C:\Documents and Settings\Pauline00\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf - deleted
C:\WINDOWS\Prefetch\LAUNAPP.EXE-2728A3F2.pf - deleted
C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf - deleted
C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf - deleted
C:\WINDOWS\Prefetch\IGFXTRAY.EXE-3391579A.pf - deleted
C:\WINDOWS\Prefetch\HKCMD.EXE-1D05234B.pf - deleted
C:\WINDOWS\Prefetch\SYNTPLPR.EXE-28BB9F3B.pf - deleted
C:\WINDOWS\Prefetch\SYNTPENH.EXE-315D3ABC.pf - deleted
C:\WINDOWS\Prefetch\LAUNCHAP.EXE-04C655F4.pf - deleted
C:\WINDOWS\Prefetch\HOTKEYAPP.EXE-33C84604.pf - deleted
'Run MRU' list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
CleanUp! recovered 154.2 KB of disk space from 10 files.
CleanUp! finished on 05/19/05 15:55:14.
Le problème c'est que quand je redémarre les fichiers ne se suppriment pas.
Merci pour vos solutions
CleanUp! started on 05/19/05 15:55:12.
C:\Documents and Settings\Pauline00\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
'Typed URLs' (Internet Explorer) - removed from the registry.
C:\Documents and Settings\Pauline00\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf - deleted
C:\WINDOWS\Prefetch\LAUNAPP.EXE-2728A3F2.pf - deleted
C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf - deleted
C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf - deleted
C:\WINDOWS\Prefetch\IGFXTRAY.EXE-3391579A.pf - deleted
C:\WINDOWS\Prefetch\HKCMD.EXE-1D05234B.pf - deleted
C:\WINDOWS\Prefetch\SYNTPLPR.EXE-28BB9F3B.pf - deleted
C:\WINDOWS\Prefetch\SYNTPENH.EXE-315D3ABC.pf - deleted
C:\WINDOWS\Prefetch\LAUNCHAP.EXE-04C655F4.pf - deleted
C:\WINDOWS\Prefetch\HOTKEYAPP.EXE-33C84604.pf - deleted
'Run MRU' list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
CleanUp! recovered 154.2 KB of disk space from 10 files.
CleanUp! finished on 05/19/05 15:55:14.
Le problème c'est que quand je redémarre les fichiers ne se suppriment pas.
Merci pour vos solutions
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
fait un scan ici ont i verrat plus clair
Faite scan en ligne et coller le rapport ici sur le post
utiliser l'antivirus en ligne suivant :
http://www.ravantivirus.com/scan/
Cliquer sur "To continue without subscribing click here" et attendre quelques minutes.
Lorsque "Ready" est affiché dans "status", cocher la case "Autoclean" puis cliquer sur "Scan my PC"
A la fin de l'analyse, copier/coller le rapport ici.
Faite scan en ligne et coller le rapport ici sur le post
utiliser l'antivirus en ligne suivant :
http://www.ravantivirus.com/scan/
Cliquer sur "To continue without subscribing click here" et attendre quelques minutes.
Lorsque "Ready" est affiché dans "status", cocher la case "Autoclean" puis cliquer sur "Scan my PC"
A la fin de l'analyse, copier/coller le rapport ici.
Mon ordinateur ne veut pas accéder à l'antivirus en ligne. J'ai essayer celui de Secuser aussi et ça n'a pas marché. Il me dit que les paramètres de sécurité de mon ordinateur ne me permettent pas d'accéder aux pages.
Et Antivir continue de me détecter ces virus...
Et Antivir continue de me détecter ces virus...
salut à tous
tchoupi relances cleanup puis antivir mais en mode sans échec (hors connection) pour effacer plus facilement, ensuite si toujours pas clean fais ceci
* tu charges Sysclean Package là:
http://fr.trendmicro-europe.com/enterprise/support/tsc.php
et le fichier dernière version signatures virus « LTPxxx.ZIP » (xxx représente les chiffres indiquant la version ) là
http://fr.trendmicro-europe.com/enterprise/support/pattern.php
*tu décomprimes le ltpxxx.zip et place le fichier ltp$vpn.xxx dans le même répertoire que Sysclean
* tu redémarres en mode sans échec
*tu lances le scan en cliquant sur sysclean.com et il est créé un fichier sysclean.log dans ce répertoire ;
a+
tchoupi relances cleanup puis antivir mais en mode sans échec (hors connection) pour effacer plus facilement, ensuite si toujours pas clean fais ceci
* tu charges Sysclean Package là:
http://fr.trendmicro-europe.com/enterprise/support/tsc.php
et le fichier dernière version signatures virus « LTPxxx.ZIP » (xxx représente les chiffres indiquant la version ) là
http://fr.trendmicro-europe.com/enterprise/support/pattern.php
*tu décomprimes le ltpxxx.zip et place le fichier ltp$vpn.xxx dans le même répertoire que Sysclean
* tu redémarres en mode sans échec
*tu lances le scan en cliquant sur sysclean.com et il est créé un fichier sysclean.log dans ce répertoire ;
a+
voici un apercu de mon dernier scann qui est encore en cours
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
19/05/2005,21:26:22 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
19/05/2005,21:26:56 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
19/05/2005,21:29:01 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
19/05/2005,21:31:16 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
19/05/2005,21:32:06 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
19/05/2005,21:32:19 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
19/05/2005,21:34:04 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDABK9EN\PROMPT[1].HTM
File has been deleted!
19/05/2005,22:04:29 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\PROMPT[1].HTM
File has been deleted!
19/05/2005,22:10:14 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
19/05/2005,22:10:23 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce f
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
19/05/2005,21:26:22 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
19/05/2005,21:26:56 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
19/05/2005,21:29:01 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
19/05/2005,21:31:16 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
19/05/2005,21:32:06 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
19/05/2005,21:32:19 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
19/05/2005,21:34:04 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDABK9EN\PROMPT[1].HTM
File has been deleted!
19/05/2005,22:04:29 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\PROMPT[1].HTM
File has been deleted!
19/05/2005,22:10:14 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
19/05/2005,22:10:23 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce f
salut
regardes dans Démarrer/panneauConfig/ajoutSupressionProgrammes
si tu as 180solutions et désinstalles ou bien un log similaire, Dyfuca, Bagains, une toolbar (mais pas n'importe laquelle dis nous quoi), etc...
sinon dans C:ProgramFiles/180solution... ou les autres ou un pgm que tu connais pas et dis nous quoi
tu pourrais effacer complètement le répertoire en question
a+
regardes dans Démarrer/panneauConfig/ajoutSupressionProgrammes
si tu as 180solutions et désinstalles ou bien un log similaire, Dyfuca, Bagains, une toolbar (mais pas n'importe laquelle dis nous quoi), etc...
sinon dans C:ProgramFiles/180solution... ou les autres ou un pgm que tu connais pas et dis nous quoi
tu pourrais effacer complètement le répertoire en question
a+
je vais suivre de tres pres vos conseils je crois avoir exactement le meme blem et de plus quand j'ouvre msn les fenetres de mes contacts connectes s'ouvrent d'1 seul coup et leurs envoient 1 adresse http antivir detect sans des trojean du meme type que tchoupi je crois et bit defender n'arrive pas àles effacer ils les deplacent merci pour les solutions que vous apporterez merciiiiiiiiiiiiiii!!!!!!!!!
Je ne trouve aucun de ces noms.
Si vous aviez une autre solution ce serait vraiment très gentil
Merci
Si vous aviez une autre solution ce serait vraiment très gentil
Merci
salut tchoupi:
vide tes fichiers temps et tempory internet file sur tous les utilisateur
utilise ceci pour le faire
http://pageperso.aol.fr/Balltrap34/CleanUp312.exe
ensuite verifie les releve d antivir et colle les ici qd tu as une detection !
ou sinon:
http://housecall-beta.trendmicro.com/en/start_corp.asp
lance un scan ici
a+
vide tes fichiers temps et tempory internet file sur tous les utilisateur
utilise ceci pour le faire
http://pageperso.aol.fr/Balltrap34/CleanUp312.exe
ensuite verifie les releve d antivir et colle les ici qd tu as une detection !
ou sinon:
http://housecall-beta.trendmicro.com/en/start_corp.asp
lance un scan ici
a+
re salut à tous
tchoupi, installes AdAware et Spybot , mettre à jour et scan avec tu effaces/coches tout ce qu'ils trouvent
anti adware de lavasoft là gratuit AdAware-SE
http://www.lavasoftusa.com/support/download/
Et SpySwepper là :
http://www.webroot.com/products/spysweeper/ free 1mois puis payant
http://www.pctools.com/spyware-doctor/ scan en ligne+download gratuit 15j puis payant pour update
et SpySubtract (gratuit 1 mois)
http://www.intermute.com/products/spysubtract.html
et surtout celui là Spybot S&D là: (free) version 1.4beta2
http://www.softpedia.com/progDownload/SpyBot--Search--Destroy--beta-Download-1865.html
Recherche aussi OptimizeInternet et si tu trouves tu désinstalles ou effaces tout le répertoire
a+
tchoupi, installes AdAware et Spybot , mettre à jour et scan avec tu effaces/coches tout ce qu'ils trouvent
anti adware de lavasoft là gratuit AdAware-SE
http://www.lavasoftusa.com/support/download/
Et SpySwepper là :
http://www.webroot.com/products/spysweeper/ free 1mois puis payant
http://www.pctools.com/spyware-doctor/ scan en ligne+download gratuit 15j puis payant pour update
et SpySubtract (gratuit 1 mois)
http://www.intermute.com/products/spysubtract.html
et surtout celui là Spybot S&D là: (free) version 1.4beta2
http://www.softpedia.com/progDownload/SpyBot--Search--Destroy--beta-Download-1865.html
Recherche aussi OptimizeInternet et si tu trouves tu désinstalles ou effaces tout le répertoire
a+