[ezula] le supprimer???

bonjour,

j' avais 2 virus sur mon pc, un nommé worm/msn.kelviAC que j'ai supprimé en formatant la partition sur lequel il se trouvait, ANTIVIR n 'arrivait pas a le supprimer, un nomme worm/IRCB0-149504b sur l'autre partition que je pense avoir supprimé grace a ANTIVIR.

18 réponses

  1. depuis j'ai ezula que je n'arrive pas a supprimer.
    qelqu'un pourrait il me dire comment s'y prendre
    Merci
    0
    1. tout d abord merci de ta reponse.
      Je te joins le rapport

      Logfile of HijackThis v1.99.1
      Scan saved at 13:22:28, on 08/10/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
      C:\Program Files\AVPersonal\AVWUPSRV.EXE
      C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
      C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
      C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\AVPersonal\AVGNT.EXE
      C:\Program Files\Winamp\winampa.exe
      C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
      C:\Program Files\Media Access\MediaAccK.exe
      C:\Program Files\Media Access\MediaAccess.exe
      C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
      C:\PROGRA~1\Web Offer\wo.exe
      C:\PROGRA~1\ezula\mmod.exe
      c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\hijackthis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pmu.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
      O4 - HKLM\..\Run: [PMCS] C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug
      O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
      O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
      O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
      O4 - HKLM\..\Run: [shell32] C:\WINDOWS\system32\wuauclt10.exe
      O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\system32\smmss.exe
      O4 - HKLM\..\Run: [Windows update] C:\WINDOWS\system32\wudupdate.exe
      O4 - HKLM\..\Run: [I downloaded pirated Software from P2P and now I post my Hijack log whining] C:\WINDOWS\system32\Fifa 2006 soccer crack.exe
      O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
      O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
      O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
      O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
      O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
      O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
      O4 - HKCU\..\RunOnce: [Web Offer] C:\WINDOWS\system32\smmss.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
      O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
      O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
      O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
      O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
      O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      0
      1. Bonjour,

        Méthode à suivre dans l'ordre...

        Dans ajout suppression de programme, desinstalle ceci si present:
        - Web Offer
        - Ezula
        - Spyware cleaner
        ----------------------------------------------------------------------------
        ¤Télécharge ces logiciels mais que tu n‘utilises pas tout de suite:

        1/

        Spybot S&D 1.4 <<nouvelle version.
        http://www.safer-networking.org/fr/index.html

        Démo d’utilisation (merci à Balltrap34 pour cette réalisation).
        http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

        2/

        Ad-Aware SE 1.06 <<nouvelle version.
        http://www.lavasoftusa.com/software/adaware/
        -Une aide:
        http://www.tutopat.com/viewtopic.php?t=1191
        - installe le patch français, tu pourras le trouver ici:
        http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
        et une petite vidéo d'utilisation ici:(merci à Moe31 pour cette réalisation).
        http://pageperso.aol.fr/balltrap34/adawrevid.asf

        ----------------------------------------------------------------------------
        ¤Désactive ta restauration système (uniquement si tu es sous XP):
        Clic droit sur poste de travail puis,
        propriété, tu cliques sur onglet restauration système
        tu coches la case « désactiver la restauration » et applique.
        ----------------------------------------------------------------------------
        ¤Démarre en mode sans échec :
        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
        (Si F8 ne marche pas utilise la touche F5).
        ----------------------------------------------------------------------------
        ¤Affiche tous les fichiers et dossiers :
        Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

        Coche « afficher les fichiers et dossiers cachés »

        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

        Décoche « masquer les extensions dont le type est connu »
        Puis fais «Ok» pour valider les changements.

        Et appliquer !
        ----------------------------------------------------------------------------
        ¤Vide tes fichiers temps et tempory internet file:

        :: Supprimer les fichiers temporaires ::
        vider tout le contenu de ces dossiers.

        * C:\Documents and Settings\ton compte\Local Settings\Temp
        * C:\Documents and Settings\tous les autres comptes\Local Settings\Temp
        * C:\Windows\Temp

        :: Le contenu du dossier prefetch ::

        * C:\WINDOWS\Prefetch <= sauf le fichier layout.ini

        * Ne pas oublier de vider la corbeille !
        ----------------------------------------------------------------------------
        ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php

        O4 - HKLM\..\Run: [shell32] C:\WINDOWS\system32\wuauclt10.exe

        O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\system32\smmss.exe

        O4 - HKLM\..\Run: [Windows update] C:\WINDOWS\system32\wudupdate.exe

        O4 - HKLM\..\Run: [I downloaded pirated Software from P2P and now I post my Hijack log whining] C:\WINDOWS\system32\Fifa 2006 soccer crack.exe

        O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe

        O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe

        O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe

        O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe

        O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe

        O4 - HKCU\..\RunOnce: [Web Offer] C:\WINDOWS\system32\smmss.exe

        O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot

        O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php

        O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)

        O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)

        ----------------------------------------------------------------------------
        ¤Recherche et supprime ceci:
        attention seulement les fichiers (si présents).

        C:\WINDOWS\system32\wuauclt10.exe
        C:\WINDOWS\system32\smmss.exe
        C:\WINDOWS\system32\wudupdate.exe
        C:\Program Files\Media Access <---le dossier
        C:\Program Files\Power Scan <---le dossier
        C:\Program Files\ISTsvc <---le dossier
        C:\PROGRA~1\Web Offer
        C:\PROGRA~1\ezula
        C:\Program Files\Spyware Cleaner <--le dossier

        ----------------------------------------------------------------------------
        ¤Arrête ces services :

        Clique sur Démarrer->exécuter->tape: services.msc

        Double-clique: Service: SpywareCleanerService

        Règle-le sur "Arrêté" et "Désactivé".
        ----------------------------------------------------------------------------
        ¤ Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
        ----------------------------------------------------------------------------
        ¤ Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…
        ----------------------------------------------------------------------------
        ¤ Vide ta Corbeille.
        ----------------------------------------------------------------------------
        ¤ Redémarre en mode normal, relance Hijackthis et copie/colle un nouveau rapport sur le forum.

        Précise tes soucis s’il en reste....

        Tiens-moi au courant

        A+
        0
        1. re,

          merci pour cette precieuse aide, le pb majeur semble resolu(ezula a disparu)
          je te joint comme demandé le nouveau rapport

          Logfile of HijackThis v1.99.1
          Scan saved at 19:22:49, on 08/10/2005
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
          C:\Program Files\AVPersonal\AVWUPSRV.EXE
          C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
          C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
          C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\AVPersonal\AVGNT.EXE
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\hijackthis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pmu.fr/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
          O4 - HKLM\..\Run: [PMCS] C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug
          O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
          O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
          O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
          O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
          O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

          en esperant que tu me dises que tout est ok...

          Encore merci!
          0
      2. re,
        tout me parait nikel,

        as tu un soucis a deplorer?

        a+
        0
        1. desole pour reponse tardive, mais encore une fois un GRAND merci, plus aucun pb a deplorer

          Bonne soiree a tous
          0
          1. salut
            pas grave pour la reponse tardive

            je suis ravi pour toi ^^

            recaches tes fichiers caches et reactive ta restauration systeme

            a+
            0
            1. Salut et désolé de te contacter comme ceci mais je ne savais pas comment faire autrement. J'ai le même pb, je t'envoie le log copier . Merci par avance
              joluax
              0
              1. désolé voici le log :
                Logfile of HijackThis v1.99.1
                Scan saved at 17:45:40, on 14/10/2005
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Ahead\InCD\InCDsrv.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Steganos AntiSpyware 2006\WRSSSDK.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\wdfmgr.exe
                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                C:\WINDOWS\AGRSMMSG.exe
                C:\WINDOWS\system32\qttask.exe
                C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\pchbutton.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\WINDOWS\System32\alg.exe
                C:\Program Files\D-Tools\daemon.exe
                C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
                C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
                C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
                C:\Program Files\Trend Micro\Internet Security\PCClient.EXE
                C:\Program Files\Trend Micro\Internet Security\PCCGUIDE.EXE
                C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
                C:\Program Files\eMule\emule.exe
                C:\Program Files\eXeem\eXeem.exe
                C:\Program Files\eXeem\client.dll
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\Program Files\Telecom Italia France\Barre Magique 1.05.08.22\BBarHelpers.exe
                C:\Program Files\Steganos AntiSpyware 2006\saspy2006.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\WINDOWS\system32\HPZipm12.exe
                C:\Program Files\WinRAR\WinRAR.exe
                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\Rar$EX00.375\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aliceadsl.fr/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
                O3 - Toolbar: Barre &Magique - {01A7812B-59E8-4A4F-BFD6-EEE6D4CB6BA2} - C:\Program Files\Telecom Italia France\Barre Magique 1.05.08.22\Tiscali BBar.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
                O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
                O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                O4 - HKLM\..\Run: [TiscaliParam] C:\Program Files\Tiscali\Dialer\bootparam.exe
                O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\system32\smmss.exe
                O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [Antispyware 2006] "C:\Program Files\Steganos AntiSpyware 2006\saspy2006.exe" /startintray
                O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\pchbutton.exe
                O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
                O16 - DPF: {041816FE-7869-4B5F-9BE4-FFF3B7368727} (IsHere Class) - http://barremagique.aliceadsl.fr/download/BarreMagique.cab
                O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: Trend Micro Personal Firewall (PccPfw) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Steganos AntiSpyware 2006\WRSSSDK.exe
                O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
                O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
                O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
                0
                1. salut
                  Lance ce scan en ligne:
                  http://www.bitdefender.com/scan/licence.php
                  Copie/colle le rapport

                  a+
                  0
                  1. Salut voici le rapport :
                    BitDefender Online Scanner

                    Scan report generated at: Sat, Oct 15, 2005 - 21:17:45

                    Scan path: C:\;D:\;E:\;F:\;G:\;H:\;I:\;J:\;K:\;L:\;M:\;N:\;O:\;

                    Statistics

                    Time
                    00:33:07

                    Files
                    171393

                    Folders
                    4815

                    Boot Sectors
                    3

                    Archives
                    2167

                    Packed Files
                    16948

                    Results

                    Identified Viruses
                    11

                    Infected Files
                    165

                    Suspect Files
                    0

                    Warnings
                    0

                    Disinfected
                    0

                    Deleted Files
                    165

                    Engines Info

                    Virus Definitions
                    221681

                    Engine build
                    AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)

                    Scan plugins
                    13

                    Archive plugins
                    39

                    Unpack plugins
                    4

                    E-mail plugins
                    6

                    System plugins
                    1

                    Scan Settings

                    First Action
                    Disinfect

                    Second Action
                    Delete

                    Heuristics
                    Yes

                    Enable Warnings
                    Yes

                    Scanned Extensions
                    exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

                    Exclude Extensions

                    Scan Emails
                    Yes

                    Scan Archives
                    Yes

                    Scan Packed
                    Yes

                    Scan Files
                    Yes

                    Scan Boot
                    Yes

                    Scanned File
                    Status

                    C:\Program Files\Web Offer\apev.exe
                    Detected with: Adware.Weboffer.A

                    C:\Program Files\Web Offer\apev.exe
                    Disinfection failed

                    C:\Program Files\Web Offer\apev.exe
                    Deleted

                    C:\Program Files\Web Offer\CHPON.dll
                    Detected with: Adware.Weboffer.A

                    C:\Program Files\Web Offer\CHPON.dll
                    Disinfection failed

                    C:\Program Files\Web Offer\CHPON.dll
                    Deleted

                    C:\Program Files\Web Offer\sepng.dll
                    Detected with: Adware.Weboffer.A

                    C:\Program Files\Web Offer\sepng.dll
                    Disinfection failed

                    C:\Program Files\Web Offer\sepng.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0137060.exe
                    Infected with: Trojan.Dropper.Agent.TV

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0137060.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0137060.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0137063.exe
                    Infected with: Trojan.Pakes.DU

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0137063.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0137063.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0139115.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0139115.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0139115.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0139116.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0139116.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0139116.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0139118.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0139118.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP242\A0139118.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP243\A0139214.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP243\A0139214.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP243\A0139214.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP243\A0139218.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP243\A0139218.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP243\A0139218.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP243\A0139247.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP243\A0139247.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP243\A0139247.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP244\A0144466.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP244\A0144466.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP244\A0144466.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP244\A0144469.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP244\A0144469.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP244\A0144469.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP244\A0144471.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP244\A0144471.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP244\A0144471.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP247\A0144672.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP247\A0144672.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP247\A0144672.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP247\A0144674.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP247\A0144674.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0147864.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0147864.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0147864.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0147867.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0147867.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0147867.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0147880.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0147880.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0147880.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0148877.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0148877.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP249\A0148877.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP250\A0148961.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP250\A0148961.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP250\A0148961.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP250\A0148965.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP250\A0148965.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP250\A0148965.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP250\A0148967.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP250\A0148967.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP250\A0148967.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP251\A0150035.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP251\A0150035.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP251\A0150035.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP251\A0150039.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP251\A0150039.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP251\A0150039.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150168.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150168.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150168.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150171.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150171.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150171.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150366.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150366.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150366.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150434.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150434.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150434.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150436.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150436.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150438.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150438.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP253\A0150438.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150484.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150484.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150484.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150496.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150496.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150498.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150498.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150498.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150506.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150506.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150506.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150513.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150513.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150513.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150515.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150515.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150515.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150523.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150523.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP254\A0150523.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150565.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150565.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150565.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150577.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150577.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150579.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150579.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150579.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150584.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150584.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150584.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150591.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150591.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150591.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150593.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150593.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150593.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150601.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150601.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP255\A0150601.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150640.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150640.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150640.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150652.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150652.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150654.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150654.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150654.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150659.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150659.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150659.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150666.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150666.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150666.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150668.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150668.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150668.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150676.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150676.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP256\A0150676.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150715.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150715.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150715.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150727.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150727.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150729.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150729.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150729.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150734.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150734.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150734.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150741.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150741.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150741.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150743.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150743.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150743.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150751.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150751.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP257\A0150751.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150790.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150790.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150790.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150802.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150802.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150804.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150804.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150804.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150809.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150809.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150809.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150816.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150816.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150816.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150818.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150818.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150818.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150826.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150826.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150826.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150850.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150850.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0150850.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0151920.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0151920.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0151920.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0151965.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0151965.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP258\A0151965.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0152020.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0152020.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0152020.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0152022.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0152022.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0152022.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0152083.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0152083.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0152083.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0153059.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0153059.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0153059.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0153061.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0153061.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP259\A0153061.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156303.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156303.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156303.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156307.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156307.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156307.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156316.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156316.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156316.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156382.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156382.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156382.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156383.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156383.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156383.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156385.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156385.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156385.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156389.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156389.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156389.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156391.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156391.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP261\A0156391.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156858.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156858.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156858.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156860.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156860.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156861.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156861.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156861.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156885.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156885.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP265\A0156885.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0156912.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0156912.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0156912.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0156918.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0156918.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0156922.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0156922.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0156922.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157102.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157102.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157102.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157127.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157127.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157127.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157129.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157129.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157129.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157143.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157143.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157143.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157145.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157145.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157145.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157147.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157147.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP266\A0157147.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157182.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157182.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157182.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157187.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157187.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157191.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157191.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157191.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157367.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157367.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157367.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157392.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157392.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157392.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157394.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157394.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157394.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157408.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157408.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157408.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157410.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157410.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157410.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157412.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157412.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP267\A0157412.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157446.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157446.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157446.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157451.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157451.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157455.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157455.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157455.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157631.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157631.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157631.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157656.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157656.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157656.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157658.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157658.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157658.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157672.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157672.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157672.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157674.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157674.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157674.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157676.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157676.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0157676.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0158777.dll
                    Infected with: Trojan.Isbar.230

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0158777.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0158777.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0158778.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0158778.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP268\A0158778.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP269\A0158847.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP269\A0158847.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP269\A0158847.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP269\A0158849.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP269\A0158849.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP269\A0158849.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160190.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160190.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160190.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160192.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160192.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160192.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160195.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160195.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160195.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160239.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160239.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160239.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160242.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160242.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160245.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160245.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160245.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160414.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160414.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160414.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160438.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160438.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160438.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160440.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160440.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160440.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160453.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160453.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160453.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160455.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160455.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160455.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160457.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160457.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP275\A0160457.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160511.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160511.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160511.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160513.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160513.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160513.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160516.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160516.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160516.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160560.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160560.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160560.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160563.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160563.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160566.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160566.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160566.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160735.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160735.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160735.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160759.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160759.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160759.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160761.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160761.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160761.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160774.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160774.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160774.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160776.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160776.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160776.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160778.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160778.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP276\A0160778.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163079.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163079.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163079.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163083.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163083.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163083.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163091.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163091.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163091.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163133.exe
                    Infected with: Trojan.Downloader.Istbar.NQ

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163133.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163133.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163134.exe
                    Infected with: Trojan.Downloader.IstBar.IJ

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163134.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163149.exe
                    Infected with: Trojan.Downloader.Dyfuca.EI

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163149.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163149.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163150.dll
                    Infected with: Trojan.Downloader.Dyfuca.DD

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163150.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163153.dll
                    Detected with: Application.Adware.Sidefind.B

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163153.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163153.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163154.dll
                    Detected with: Application.Adware.Sidefind.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163154.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163154.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163156.exe
                    Infected with: Trojan.Agent.AY

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163156.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163156.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163157.exe
                    Infected with: Trojan.Agent.AY

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163157.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP280\A0163157.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP281\A0163251.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP281\A0163251.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP281\A0163251.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163397.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163397.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163397.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163398.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163398.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163398.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163400.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163400.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163400.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163471.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163471.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163471.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163545.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163545.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163545.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163546.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163546.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163546.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163548.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163548.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP282\A0163548.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP283\A0163772.exe
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP283\A0163772.exe
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP283\A0163772.exe
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP283\A0163773.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP283\A0163773.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP283\A0163773.dll
                    Deleted

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP283\A0163774.dll
                    Detected with: Adware.Weboffer.A

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP283\A0163774.dll
                    Disinfection failed

                    C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP283\A0163774.dll
                    Deleted

                    C:\WINDOWS\system32\username.exe
                    Infected with: Trojan.Dropper.Agent.TV

                    C:\WINDOWS\system32\username.exe
                    Disinfection failed

                    C:\WINDOWS\system32\username.exe
                    Deleted

                    C:\WINDOWS\system32\wuauclt10.exe
                    Infected with: Trojan.Pakes.DU

                    C:\WINDOWS\system32\wuauclt10.exe
                    Disinfection failed

                    C:\WINDOWS\system32\wuauclt10.exe
                    Deleted

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/apache/xpath/res/XPATHErrorResources_sv.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/apache/xpath/res/XPATHErrorResources_zh_CN.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/apache/xpath/res/XPATHErrorResources_zh_TW.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/ietf/jgss/ChannelBinding.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/ietf/jgss/GSSContext.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/ietf/jgss/GSSCredential.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/ietf/jgss/GSSException.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/ietf/jgss/GSSManager.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/ietf/jgss/GSSName.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/ietf/jgss/MessageProp.class
                    Clean

                    D:\I386\Apps\APP28703\App28703.exe=>(ZIP Sfx s)=>hp/tmp/bin/CUI/data2.cab=>(IShield Module 839)=>org/ietf/jgss/Oid.class
                    Clean

                    0
                  2. Pardon , j'ai également ceci :
                    BitDefender Online Scanner - Real Time Virus Report

                    Generated at: Sat, Oct 15, 2005 - 21:19:10

                    --------------------------------------------------------------------------------

                    Scan Info

                    Scanned Files
                    171401

                    Infected Files
                    165

                    Virus Detected

                    Adware.Weboffer.A
                    116

                    Trojan.Downloader.Dyfuca.EI
                    14

                    Trojan.Pakes.DU
                    2

                    Trojan.Dropper.Agent.TV
                    2

                    Application.Adware.Sidefind.A
                    1

                    Trojan.Agent.AY
                    2

                    Application.Adware.Sidefind.B
                    1

                    Trojan.Downloader.IstBar.IJ
                    1

                    Trojan.Downloader.Istbar.NQ
                    1

                    Trojan.Isbar.230
                    11

                    Trojan.Downloader.Dyfuca.DD
                    14
                    0
                2. re,
                  ou en sont tes soucis?

                  a+
                  0
                  1. re et merci beaucoup car pour l'instant je n'ai plus de probleme
                    Pendant que j'y suis, peux tu me conseiller un logiciel efficace pour éviter ce genre de pbs par la suite.
                    Merci par avance et bon dimanche.
                    A+
                    JOLUAX
                    0
                3. salut
                  ben tu es bien couvert:
                  -zone alarme
                  -antivir
                  spybot et ad aware
                  -sp2

                  j ai le meme configuration...

                  Fais attentiion a tes surfs, evite les sites X et les sites douteux...
                  Mets tous ce que je t ai cité au dessu a JOUR et scan avec de temps en temps

                  A+
                  0
                  1. ....bonjour,moi c'est pareil suis infecter par web offer et arrive pas a l'enlever,comment puis-je faire voici le fichier texte..

                    Logfile of HijackThis v1.99.1
                    Scan saved at 16:02:16, on 23/10/2005
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\System32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\crypserv.exe
                    C:\WINDOWS\SYSTEM32\GEARSEC.EXE
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\UAService7.exe
                    C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
                    C:\WINDOWS\SOUNDMAN.EXE
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
                    C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                    C:\progra~1\softwin\bitdef~2\bdswitch.exe
                    C:\Program Files\Softwin\BitDefender9\bdoesrv.exe
                    C:\progra~1\softwin\bitdef~2\bdnagent.exe
                    C:\progra~1\softwin\bitdef~2\bdmcon.exe
                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                    C:\DeeEnEs\DeeEnEs.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\VIA\RAID\raid_tool.exe
                    C:\WINDOWS\Packs\Crystal XP\YzToolbar\YzToolbar.exe
                    C:\Program Files\Softwin\BitDefender9\vsserv.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\PROGRA~1\WEBOFF~1\wo.exe
                    C:\Program Files\Outlook Express\msimn.exe
                    C:\Program Files\Azureus\Azureus.exe
                    C:\Program Files\Java\jre1.5.0_02\bin\javaw.exe
                    C:\WINDOWS\system32\ping.exe
                    C:\Program Files\MSN Messenger\msnmsgr.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Documents and Settings\Ptipat\Bureau\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
                    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                    O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
                    O4 - HKLM\..\Run: [BDSwitchAgent] "C:\progra~1\softwin\bitdef~2\bdswitch.exe"
                    O4 - HKLM\..\Run: [BDOESRV] "C:\Program Files\Softwin\BitDefender9\bdoesrv.exe"
                    O4 - HKLM\..\Run: [BDNewsAgent] "C:\progra~1\softwin\bitdef~2\bdnagent.exe"
                    O4 - HKLM\..\Run: [BDMCon] C:\progra~1\softwin\bitdef~2\bdmcon.exe
                    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
                    O4 - HKLM\..\Run: [shell32] C:\WINDOWS\system32\wuauclt10.exe
                    O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\system32\smmss.exe
                    O4 - HKCU\..\Run: [DeeEnEs] C:\DeeEnEs\DeeEnEs.exe
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - Startup: Y'z Toolbar.lnk = ?
                    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O4 - Global Startup: BitDefender for MSN Messenger.lnk = C:\Program Files\Softwin\BitDefender for MSN Messenger\msnmon.exe
                    O4 - Global Startup: BitDefender_P2P_Startup.lnk = C:\WINDOWS\BitDefender_P2P_Startup.exe
                    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
                    O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                    O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                    O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                    O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                    O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
                    O9 - Extra button: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - C:\Program Files\Allocam Multi Visio\allocam.exe (file missing)
                    O9 - Extra 'Tools' menuitem: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - C:\Program Files\Allocam Multi Visio\allocam.exe (file missing)
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
                    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
                    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
                    O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
                    O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\SYSTEM32\GEARSEC.EXE
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
                    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
                    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
                    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)
                    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

                    .......merci pour votre aide....
                    0
                    1. bonjour j'ai le même problème avec web offer et ezula

                      Logfile of HijackThis v1.99.1
                      Scan saved at 21:43:10, on 26/10/2005
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      
                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      C:\Program Files\Norton Internet Security\ISSVC.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      C:\WINDOWS\system32\LEXBCES.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
                      C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                      C:\flexlm\SolidWorks SolidNetWork License Manager\lmgrd.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                      C:\flexlm\SolidWorks SolidNetWork License Manager\SW_D.EXE
                      C:\WINDOWS\system32\Fast.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                      C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
                      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
                      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
                      C:\Program Files\Sonic\Sonic Solutions Product CD\Media Experience\DMXLauncher.exe
                      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                      C:\Program Files\MessengerPlus! 3\MsgPlus1.exe
                      C:\Program Files\D-Tools\daemon.exe
                      C:\WINDOWS\system32\cmd.exe
                      C:\Program Files\ISTsvc\istsvc.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\WINDOWS\system32\taskswitch.exe
                      C:\WINDOWS\system32\fast.exe
                      C:\WINDOWS\tcfupqkj.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
                      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                      C:\Program Files\MSN Messenger\msnmsgr.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\HijackThis.exe
                      
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assistant/accoona_search_assistant.jsp?&utm_id=400011&utm_content=leftnav&utm_source=wdz&utm_medium=bund&utm_campaign=wdz0605
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
                      O1 - Hosts: <HTML><HEAD>
                      O1 - Hosts: <TITLE>404 Not Found</TITLE>
                      O1 - Hosts: </HEAD><BODY>
                      O1 - Hosts: <H1>Not Found</H1>
                      O1 - Hosts: The requested URL /stat.dat was not found on this server.<P>
                      O1 - Hosts: </BODY></HTML>
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SS SS Plugin - {1D1B2879-99FF-11E3-8D96-D7ACAC95952A} - C:\WINDOWS\system32\baju18wb.dll (file missing)
                      O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll (file missing)
                      O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                      O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                      O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dll (file missing)
                      O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                      O3 - Toolbar: Accoona - {364B6276-C6C1-40B6-A6D7-6C48871FD707} - C:\Program Files\Accoona\atoolbar.dll (file missing)
                      O3 - Toolbar: ISTbar - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - C:\Program Files\ISTbar\istbarcm.dll (file missing)
                      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
                      O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                      O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
                      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
                      O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Sonic\Sonic Solutions Product CD\Media Experience\DMXLauncher.exe
                      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                      O4 - HKLM\..\Run: [adiras] adiras.exe
                      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                      O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus1.exe"
                      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
                      O4 - HKLM\..\Run: [MindSoft Task Accelerator] C:\Program Files\MindSoft\MindSoft Utilities XP 8.2\taskaccl.exe /T
                      O4 - HKLM\..\Run: [MindSoft FreeRAM] C:\Program Files\MindSoft\MindSoft Utilities XP 8.2\FreeRAM.exe
                      O4 - HKLM\..\Run: [Windows Installer] C:\WINDOWS\system32\ntdll.exe
                      O4 - HKLM\..\Run: [Windows Spooler] C:\WINDOWS\system32\spoolsv32.exe
                      O4 - HKLM\..\Run: [Windows DLL Host] C:\WINDOWS\system32\dllhost32.exe
                      O4 - HKLM\..\Run: [Microsoft LSASS Network File] C:\WINDOWS\system32\KLSASS.exe
                      O4 - HKLM\..\Run: [shell32] C:\WINDOWS\system32\wuauclt10.exe
                      O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\system32\smmss.exe
                      O4 - HKLM\..\Run: [I downloaded pirated Software from P2P and now I post my Hijack log whining] C:\WINDOWS\system32\Moto GP Ultimate Racing Technology 3 crack.exe
                      O4 - HKLM\..\Run: [sp2protect] C:\WINDOWS\system32\sp2protect.exe
                      O4 - HKLM\..\Run: [baju18] C:\WINDOWS\system32\baju18.exe
                      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                      O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
                      O4 - HKLM\..\Run: [vkGcN9] C:\WINDOWS\tvtijx.exe
                      O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [BackgroundSwitcher] C:\WINDOWS\system32\bgswitch.exe
                      O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
                      O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe
                      O4 - HKLM\..\Run: [Windows update] C:\WINDOWS\system32\wudupdate.exe
                      O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
                      O4 - HKLM\..\Run: [qt1pcDdOJ] C:\WINDOWS\tcfupqkj.exe
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
                      O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus1.exe" /WinStart
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\RunOnce: [Web Offer] C:\WINDOWS\system32\smmss.exe
                      O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
                      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                      O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll (file missing)
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
                      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                      O16 - DPF: {42E1F024-ECC3-456F-B98A-4CE5ACDBF25C} (ActiveFormX Contrôle) - https://ssl-tb.sitadelle.com/selfcare.cegetel.net/templates/static/ocx/AFAutoConfig.ocx
                      O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.7) - http://gameadvisor.futuremark.com/global/msc37.cab
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{F28D3E8B-A25A-4E40-8034-6AF5B9626CE1}: NameServer = 217.19.192.132 217.19.192.131
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
                      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      O23 - Service: SolidWorks SolidNetWork License Manager - Macrovision Corporation - C:\flexlm\SolidWorks SolidNetWork License Manager\lmgrd.exe
                      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                      
                      
                      0
                      1. Bonjour charley,
                        Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
                        Procèdes comme ceci :
                        http://pageperso.aol.fr/balltrap34/demofairesontmessage.htm

                        A bientôt, si qqun ne t a pas pris en charge, je t aiderais

                        a+
                        0