Worm Gedza 3

philipain -  
 Rick -
Bonjour , je suis l'heureux possesseur d'un adorable Worm Gedza 3 ( detecté par Antivir ) , mais par manque de place je suis prêt à m'en débarasser. Plus sérieusement : qq'un sait il comment éradiquer ce ver qui a l'air de se répendre sur tous les fichiers html ? seul Antivir le détecte, les scans en ligne que j'ai fait ne trouvent rien ( commandondemand , secuser, ... ).
Merci pour votre aide
A voir également:

11 réponses

Nilou17 Messages postés 2386 Statut Modérateur 1 474
 
Salut Philipain,

Télécharge HijackThis :
http://www.hijackthis.de/downloads/hijackthis_199.zip
L'aide est ici :
http://www.zebulon.fr/articles/HijackThis.php

*** Dezippe-le dans un dossier prévu à cet effet
Par exemple = C:\hijackthis
*** Lance le puis clique sur "do a system scan and save logfile"
*** Fais un copier coller du log entier sur le forum

A++++++
0
philipain
 
Merci Nilou de ta réponse, voici le Hjk :




Logfile of HijackThis v1.99.1
Scan saved at 17:17:26, on 05/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Tiscali\Dialer\Dialer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\phil\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.voila.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: {92E1B3F7-0546-421E-9835-904D25B7BA66} - {C4F147D7-BF25-488E-A12B-EFD43E7029BF} - C:\WINDOWS\system32\winvbie.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: VisuExplorer - {92E1B3F7-0546-421E-9835-904D25B7BA66} - C:\WINDOWS\system32\msiev32.dll
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O8 - Extra context menu item: Tout télécharger en utilisant FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Télécharger en utilisant FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.zebulon.fr/outils/antivirus/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://www.commandondemand.com/eval/cod/cabs/cssweb.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AD08640-1137-43A4-8CAE-2ED2A90D6BAC}: NameServer = 213.36.80.1 213.36.80.1
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Alias Maya 5.0 PLE Help Server (Maya5PLEHelpServer) - Unknown owner - C:\Program Files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs\Wrapper.exe" -s "C:\Program Files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs/Wrapper.conf (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
incognito02 Messages postés 3487 Statut Contributeur 138
 
Bonjour philipain,

en attendant que Nilou analyse ton log, as tu essayé ça :

Télécharge ces logiciels:

1/Spybot S&D 1.4 <<nouvelle version
http://www.safer-networking.org/fr/index.html

Démo d utilisation (merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

2/Ad-Aware SE 1.06 <<nouvelle version
http://www.lavasoftusa.com/software/adaware/
-Une aide:
http://www.tutopat.com/viewtopic.php?t=1191
- installe le patch français, tu pourra le trouver ici:
http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
et une petite vidéo ici d'utilisation:(merci a Moe31 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/adawrevid.asf

bon courage.

a+
0
philipain
 
Merci pour vos conseils.
J'ai téléchargé et exécuter Spybot et Adaware, ils m'ont trouvé des cookies, mais pas le worm Gedza 1 et 3 que Antivir me signale quand j'ouvre Explorer, et ce sur presque tous les fichiers html que ma souris survole... que faire ?
0
balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
 
salut
essai se scan stp
Scan bit defender
http://www.bitdefender.fr
clik sur scan on line a gauche et suis la procedure
----------------
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
philipain
 
merci balltrap, je viens de faire un scan avec bitdefender mais il ne trouve rien ... par contre, si je laisse Antivir tourner, il me signale le worm dans les fichiers php et html que bitdefender scanne.
Si tu vois une autre chose a faire...
0
balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
 
tu as le chemin ou il les trouvent
0
Utilisateur anonyme
 
salut
demarer<poste de travail < c < program files < av personal < logfiles <NTGRDRT < copie colle tout ce qu il y a a l interieur

a+
0
philipain
 
Merci regis, voici un petit bout du log NTGRDTR:


05/11/2005,09:24:17 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ISRAFEL.VIR01
05/11/2005,09:24:18 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:24:22 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COORD[1].HTM.001
05/11/2005,09:24:23 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:24:30 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\LES_GATEAUX_AUX_CHATAIGNES[1].HTM.VIR
05/11/2005,09:24:34 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:24:57 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\SN=VOILA.VIG&PN=ACCUEIL_POPUP[1].HTM.VIR
05/11/2005,09:25:03 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:25:06 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\SCANWISE.HTM.VIR
05/11/2005,09:25:11 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:25:14 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\START.HTM.VIR
05/11/2005,09:25:16 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[6].JS.VIR
05/11/2005,09:28:24 [INFO] Stop Filter Device.
05/11/2005,09:28:26 AVGuard service has been stopped
0
Utilisateur anonyme
 
salut
il est en entier la? verifie stp (car l heure s arrete a 9h ce matin)

a+
0
philipain
 
Encore merci Regis, voici le NTGRDTR.log en entier.

05/11/2005,08:24:25 ---------------------------------------------------------
05/11/2005,08:24:25 [INIT] The AVGuard Service is starting.
05/11/2005,08:24:27 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
05/11/2005,08:24:38 [INFO] Start Filter Device.
05/11/2005,08:24:38 AntiVirService Version: 6.31.00.01 AVE Version 6.31.1.0 VDF Version: 6.31.1.107
05/11/2005,08:24:38 AVGuard has been started successfully!
05/11/2005,08:25:01 [LOGON] Connection request by remote computer. Establishing secure communication channel.
05/11/2005,08:25:01 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaabf076.
05/11/2005,09:21:11 [LOGON] Connection request by remote computer. Establishing secure communication channel.
05/11/2005,09:21:11 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa9e6db1.
05/11/2005,09:21:39 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\ASTASE\VBSCRIPT FACTORY\HELP\AUTOCMP.HTML
05/11/2005,09:21:45 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\FAQPE_DE.HTM
05/11/2005,09:21:44 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\FAQPE_DE.HTM
05/11/2005,09:22:18 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ACTIONCOORD[1].HTM.VIR
05/11/2005,09:22:21 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\AD3BANNER.HTML.VIR
05/11/2005,09:22:58 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ACTIONCOORD[1].HTM.VIR
05/11/2005,09:23:00 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\KERNEL32.VIR
05/11/2005,09:23:07 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\LE_DEGROUPAGE_TISCALI[1].HTM.VIR
05/11/2005,09:23:11 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\KERNEL32.VIR
05/11/2005,09:23:17 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\DEGROUPAGE[1].HTM.VIR
05/11/2005,09:23:19 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:23:37 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\IFRAMEBODY[2].JS.VIR
05/11/2005,09:23:41 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:23:47 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ISRAFEL.VIR02
05/11/2005,09:23:50 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:23:52 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ISRAFEL.VIR01
05/11/2005,09:23:52 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ISRAFEL.VIR01
05/11/2005,09:23:58 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ISRAFEL.VIR01
05/11/2005,09:24:00 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ISRAFEL.VIR01
05/11/2005,09:24:17 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ISRAFEL.VIR01
05/11/2005,09:24:18 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:24:22 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COORD[1].HTM.001
05/11/2005,09:24:23 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:24:30 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\LES_GATEAUX_AUX_CHATAIGNES[1].HTM.VIR
05/11/2005,09:24:34 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:24:57 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\SN=VOILA.VIG&PN=ACCUEIL_POPUP[1].HTM.VIR
05/11/2005,09:25:03 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:25:06 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\SCANWISE.HTM.VIR
05/11/2005,09:25:11 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[7].JS.001
05/11/2005,09:25:14 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\START.HTM.VIR
05/11/2005,09:25:16 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[6].JS.VIR
05/11/2005,09:28:24 [INFO] Stop Filter Device.
05/11/2005,09:28:26 AVGuard service has been stopped!
05/11/2005,12:19:42 ---------------------------------------------------------
05/11/2005,12:19:42 [INIT] The AVGuard Service is starting.
05/11/2005,12:19:44 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
05/11/2005,12:19:52 [INFO] Start Filter Device.
05/11/2005,12:19:52 AntiVirService Version: 6.31.00.01 AVE Version 6.31.1.0 VDF Version: 6.31.1.107
05/11/2005,12:19:52 AVGuard has been started successfully!
05/11/2005,12:21:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
05/11/2005,12:21:40 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa80877.
05/11/2005,12:37:53 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\FICHIERS ZIP ET SETUP\MICROSOFT SERIAL, KEY, CRACK FOR ALL VERSIONS OF 95, 98, 98 SE, 2000, XP, CORP, VISUAL C++, VISUAL BASIC, EXCEL, MONEY, OFFICE, PUBLISHER, WORD, WORKS, AND MANY MORE (ANTI-MS).ZIP
05/11/2005,14:12:24 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\FICHIERS ZIP ET SETUP\MICROSOFT SERIAL, KEY, CRACK FOR ALL VERSIONS OF 95, 98, 98 SE, 2000, XP, CORP, VISUAL C++, VISUAL BASIC, EXCEL, MONEY, OFFICE, PUBLISHER, WORD, WORKS, AND MANY MORE (ANTI-MS).ZIP
05/11/2005,14:32:47 [INFO] Stop Filter Device.
05/11/2005,14:32:50 AVGuard service has been stopped!
05/11/2005,16:38:00 ---------------------------------------------------------
05/11/2005,16:38:00 [INIT] The AVGuard Service is starting.
05/11/2005,16:38:01 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
05/11/2005,16:38:10 [INFO] Start Filter Device.
05/11/2005,16:38:10 AntiVirService Version: 6.31.00.01 AVE Version 6.31.1.0 VDF Version: 6.31.1.107
05/11/2005,16:38:10 AVGuard has been started successfully!
05/11/2005,16:40:29 [LOGON] Connection request by remote computer. Establishing secure communication channel.
05/11/2005,16:40:29 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa9b7c6.
05/11/2005,16:44:36 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\MAMMIFERES\BASTOUNE.HTM
05/11/2005,16:49:53 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\GRAPHISME\1ST PAGE 2000\1ST PAGE 2000\HELP\1STPAGE GUIDE\EXPLORER.HTM
05/11/2005,18:36:24 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\20E2E9\FILE.VBS
05/11/2005,18:36:38 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\3B3C0B\FILE.VBS
05/11/2005,18:36:41 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\935CF\FILE.VBS
05/11/2005,18:36:42 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\30DA9C\FILE.VBS
05/11/2005,18:36:43 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\2D09A6\FILE.VBS
05/11/2005,18:36:48 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\254D7B\FILE.VBS
05/11/2005,18:36:51 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\326E44\FILE.VBS
05/11/2005,18:36:52 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\2209C1\FILE.VBS
05/11/2005,18:36:58 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\338A61\FILE.VBS
05/11/2005,18:36:59 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\3C53B\FILE.VBS
05/11/2005,18:37:00 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\57DC5\FILE.VBS
05/11/2005,18:37:01 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\173533\FILE.VBS
05/11/2005,18:37:02 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\97E5\FILE.VBS
05/11/2005,18:37:03 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\1DE166\FILE.VBS
05/11/2005,18:37:04 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\0BC9\FILE.VBS
05/11/2005,18:37:05 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\81682\FILE.VBS
05/11/2005,18:37:06 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\30B0DC\FILE.VBS
05/11/2005,18:37:08 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\5A5EA\FILE.VBS
05/11/2005,18:37:09 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\12F65\FILE.VBS
05/11/2005,18:37:46 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\CF792\FILE.VBS
05/11/2005,18:37:58 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK.ZIP
05/11/2005,18:38:00 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK1.ZIP
05/11/2005,18:38:01 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK2.ZIP
05/11/2005,18:38:01 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK3.ZIP
05/11/2005,18:38:02 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK4.ZIP
05/11/2005,18:38:03 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK5.ZIP
05/11/2005,18:38:03 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK6.ZIP
05/11/2005,18:38:04 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK7.ZIP
05/11/2005,18:38:05 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK8.ZIP
05/11/2005,18:38:05 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK9.ZIP
05/11/2005,18:38:06 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DSOEXPLOIT.ZIP
05/11/2005,18:38:06 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DSOEXPLOIT1.ZIP
05/11/2005,18:38:06 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DSOEXPLOIT2.ZIP
05/11/2005,18:38:07 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DSOEXPLOIT3.ZIP
05/11/2005,18:38:07 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DSOEXPLOIT4.ZIP
05/11/2005,18:38:11 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\FASTCLICK.ZIP
05/11/2005,18:38:13 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\GATOR2.ZIP
05/11/2005,18:38:14 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MEDIAPLEX.ZIP
05/11/2005,18:38:15 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MEDIAPLEX1.ZIP
05/11/2005,18:38:16 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MEDIAPLEX2.ZIP
05/11/2005,18:38:16 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MEDIAPLEX3.ZIP
05/11/2005,18:38:17 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MEDIAPLEX4.ZIP
05/11/2005,18:38:18 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MEDIAPLEX5.ZIP
05/11/2005,18:38:18 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MEDIAPLEX6.ZIP
05/11/2005,18:38:19 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MYSEARCH.ZIP
05/11/2005,18:38:19 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MYSEARCH1.ZIP
05/11/2005,18:38:20 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MYSEARCH10.ZIP
05/11/2005,18:38:21 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MYSEARCH11.ZIP
05/11/2005,18:38:22 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MYSEARCH12.ZIP
05/11/2005,18:38:24 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MYSEARCH13.ZIP
05/11/2005,18:38:28 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\MYSEARCH14.ZIP
05/11/2005,18:41:33 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\2C3055\FILE.VBS
05/11/2005,18:41:39 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\217E23\FILE.VBS
05/11/2005,18:41:41 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\D4A4C\FILE.VBS
05/11/2005,18:41:42 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\16EF2E\FILE.VBS
05/11/2005,18:41:43 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\1D5CA5\FILE.VBS
05/11/2005,18:41:47 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\189D1D\FILE.VBS
05/11/2005,18:41:48 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\1B5B0E\FILE.VBS
05/11/2005,18:41:49 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\2DAB5E\FILE.VBS
05/11/2005,18:41:50 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\42677\FILE.VBS
05/11/2005,18:41:52 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\208D1E\FILE.VBS
05/11/2005,18:41:53 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\107223\FILE.VBS
05/11/2005,18:41:57 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\416843\FILE.VBS
05/11/2005,18:41:58 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\2DA66A\FILE.VBS
05/11/2005,18:41:59 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\93389\FILE.VBS
05/11/2005,18:42:00 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\1422F3\FILE.VBS
05/11/2005,18:42:01 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C6506515\412531\FILE.VBS
05/11/2005,18:46:47 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\1BE581\FILE.VBS
05/11/2005,18:46:58 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\678ED\FILE.VBS
05/11/2005,18:46:59 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\1DC18C\FILE.VBS
05/11/2005,18:47:02 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\1AC40D\FILE.VBS
05/11/2005,18:47:03 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\2554D5\FILE.VBS
05/11/2005,19:08:13 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\FICHIERS ZIP ET SETUP\MICROSOFT SERIAL, KEY, CRACK FOR ALL VERSIONS OF 95, 98, 98 SE, 2000, XP, CORP, VISUAL C++, VISUAL BASIC, EXCEL, MONEY, OFFICE, PUBLISHER, WORD, WORKS, AND MANY MORE (ANTI-MS).ZIP
05/11/2005,18:51:36 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\1F6B29\FILE.VBS
05/11/2005,19:08:25 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\2BFF57\FILE.VBS
05/11/2005,19:08:26 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\4D1FE\FILE.VBS
05/11/2005,19:08:27 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\3BB2B0\FILE.VBS
05/11/2005,19:08:28 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\E8497\FILE.VBS
05/11/2005,19:08:31 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\41F776\FILE.VBS
05/11/2005,19:08:32 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\2CD8D5\FILE.VBS
05/11/2005,19:08:34 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\1E9FDA\FILE.VBS
05/11/2005,19:08:35 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\374E0F\FILE.VBS
05/11/2005,19:08:36 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\15204\FILE.VBS
05/11/2005,19:08:37 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\2A6741\FILE.VBS
05/11/2005,19:08:37 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\F8195\FILE.VBS
05/11/2005,19:08:38 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\39C848\FILE.VBS
05/11/2005,19:08:39 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\ED2A\FILE.VBS
05/11/2005,19:08:40 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\19E6DE\FILE.VBS
05/11/2005,19:08:42 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\28990C\FILE.VBS
05/11/2005,19:08:43 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\17D1C0\FILE.VBS
05/11/2005,19:08:43 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\9F919\FILE.VBS
05/11/2005,19:08:44 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\31F918\FILE.VBS
05/11/2005,19:09:12 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUME~1\PHIL\LOCALS~1\TEMP\AAWTMP\C7568562\20AF0D\FILE.VBS
05/11/2005,19:09:48 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK.ZIP
05/11/2005,19:10:07 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK1.ZIP
05/11/2005,19:10:09 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK2.ZIP
05/11/2005,19:10:09 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK3.ZIP
05/11/2005,19:10:14 WARNING: Contains signature of the worm WORM/Gedza.1!
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\RECOVERY\DOUBLECLICK4.ZIP
05/11/2005,19:42:07 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\ACTUALITES.PHP
05/11/2005,19:45:55 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\ANNUAIRE_FORM.PHP
05/11/2005,19:45:58 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\ANNUAIRE_MAJ_RECENTES.PHP
05/11/2005,19:46:01 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\APPATS.HTM
05/11/2005,19:46:01 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\CARPE_GALERIE_JCP.HTM
05/11/2005,19:46:02 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\CARPE_GALERIE_VISITEURS.HTM
05/11/2005,19:46:03 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\CARPE_MENU.HTM
05/11/2005,19:46:04 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\KILLESHANDRA.HTM
05/11/2005,19:46:04 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\LEPTITPECHEUR.HTM
05/11/2005,19:46:05 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\MONTAGES.HTM
05/11/2005,19:46:06 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\MONTAGES_LIGNE.HTM
05/11/2005,19:46:06 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\MOUCHE_FLY_TYING.HTM
05/11/2005,19:46:07 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\NOEUDS.HTM
05/11/2005,19:46:07 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\OU_PECHER.HTM
05/11/2005,19:46:08 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\OU_TROUVER.HTM
05/11/2005,19:46:08 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\PECHE.HTM
05/11/2005,19:46:09 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\PECHE_ANGLAISE.HTM
05/11/2005,19:46:10 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\PECHE_AU_COUP.HTM
05/11/2005,19:46:10 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\PECHE_BOLOGNAISE.HTM
05/11/2005,19:46:11 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\PECHE_CARNASSIERS.HTM
05/11/2005,19:46:12 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\PECHE_CONSEILS.HTM
05/11/2005,19:46:12 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\PECHE_DEBUTANT.HTM
05/11/2005,19:46:12 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\PECHE_QUIVER.HTM
05/11/2005,19:46:13 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\PECHE_SILURE.HTM
05/11/2005,19:46:13 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\POISSONS.HTM
05/11/2005,19:46:14 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\REGLEMENTATION.HTM
05/11/2005,19:46:14 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOC PêCHE\SITESDEPECHE.HTM
05/11/2005,19:46:14 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\DOCS NATURE\ACCUEIL_FAUCONS.HTM
05/11/2005,19:46:15 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\FAQ_QUESTION_FORM.PHP
05/11/2005,19:46:18 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\FEUILLES CALCULS\PECHE_AUX_LEURRES.HTM
05/11/2005,19:46:19 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\FEUILLES CALCULS\PECHE_A_LA_MOUCHE.HTM
05/11/2005,19:46:21 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOCUMENTS\STATISTIQUES.HTM
05/11/2005,19:59:38 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DONNéES CREATION DE SITES\COMMERCE.HTML
05/11/2005,20:08:23 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DONNéES CREATION DE SITES\CONTACTS_DESABONNEMENT_FORM.HTM
05/11/2005,20:08:26 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DONNéES CREATION DE SITES\CONTACTS_LETTRE_INFO.HTM
05/11/2005,20:08:27 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DONNéES CREATION DE SITES\COPYRIGHT.HTM
05/11/2005,20:08:27 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DONNéES CREATION DE SITES\CREATIONSITE.HTML
05/11/2005,20:08:31 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DONNéES CREATION DE SITES\IMAGES POUR SITE\HARLE.HTML
05/11/2005,20:08:38 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DONNéES CREATION DE SITES\KIT02\INDEX.HTM
File has been moved to quarantine directory!
05/11/2005,20:08:52 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DONNéES CREATION DE SITES\KITS EXEMPLES\INDEX.HTM
File has been moved to quarantine directory!
05/11/2005,20:08:58 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\BANNIER.HTML
File has been moved to quarantine directory!
05/11/2005,20:09:01 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\BANNIERE.HTM
File has been moved to quarantine directory!
05/11/2005,20:09:06 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\BINTRO\BINTRO.HTM
File has been moved to quarantine directory!
05/11/2005,20:09:09 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\BOUTONDROIT.HTM
File has been moved to quarantine directory!
05/11/2005,20:09:11 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\BR1.HTM
File has been moved to quarantine directory!
05/11/2005,20:09:13 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\BRICO.HTM
File has been moved to quarantine directory!
05/11/2005,20:09:15 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\BRICO2.HTML
File has been moved to quarantine directory!
05/11/2005,20:09:17 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\BRICO3.HTM
File has been moved to quarantine directory!
05/11/2005,20:09:20 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\CONTACT.HTML
05/11/2005,20:09:23 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\ES.HTM
05/11/2005,20:09:23 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\ESSAI METTRE EN FAVORI.HTML
05/11/2005,20:09:24 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\ESSAI PAGE IMPRIMER.HTML
05/11/2005,20:09:25 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\ESSAI PAGE NEIGE.HTML
05/11/2005,20:09:25 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\ESSAIPAGE-PHOTO.HTML
05/11/2005,20:09:26 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\F1.HTM
05/11/2005,20:09:26 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\FIC1.HTM
05/11/2005,20:09:27 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\FIC2.HTML
05/11/2005,20:09:28 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\FIC4.HTML
05/11/2005,20:09:28 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\DOSSIERS NATURE CONCEPT\NATURE CONCEPT\FORM.HTM
05/11/2005,20:19:53 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\MAMMIFERES\BASTOUNE.HTM
05/11/2005,20:20:13 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\FAQPE_DE.HTM
05/11/2005,20:20:12 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\FAQPE_DE.HTM
05/11/2005,20:20:40 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\ACTIONCOORD[1].HTM.VIR
05/11/2005,20:20:42 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\AD3BANNER.HTML.VIR
05/11/2005,20:20:50 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[2].JS.002
05/11/2005,20:20:52 WARNING: Contains signature of the worm WORM/Gedza.3!
C:\PROGRAM FILES\AVPERSONAL\INFECTED\COMMON[2].JS.003
0
Utilisateur anonyme
 
re,
ptin il se propage ou koi lol

1/telecharge et execute ceci
Clean Up 40:
http://pageperso.aol.fr/balltrap34/CleanUp40.exe
-aide en image:(merci à Balltrap34).
http://pageperso.aol.fr/balltrap34/democleanup.htm

2/lance spybot
sauvegardes , coche tout et purges
+vaccine

3/supprime tout ce qu il y a l interieeur de ceci (c est ta quarantaine)
C:\PROGRAM FILES\AVPERSONAL\INFECTED <---vide tout ce qu il y a dedans et vide ta corbeille

4/Poste nous un hijack this, il y a surrement des choses a supprimer

a bientot
0
Rick
 
Tien voici un petit program que j'adore depuis que je lai deniché "Active Virus Shield" https://download.cnet.com/s/aol-active-virus-shield/
c'est avec ceci que jai réalisé que mon ordi etais plus que contaminé incluan gedza et il a tout reparé en un seul scan :) bonne chance et au plaisir davoir des nouvelles
0