Virus
Fermé
croco20
Messages postés
16
Date d'inscription
jeudi 17 février 2011
Statut
Membre
Dernière intervention
18 juin 2013
-
17 févr. 2011 à 00:54
Utilisateur anonyme - 17 févr. 2011 à 11:01
Utilisateur anonyme - 17 févr. 2011 à 11:01
A voir également:
- Virus
- Youtu.be virus - Accueil - Guide virus
- Svchost.exe virus - Guide
- Faux message virus ordinateur - Accueil - Arnaque
- Softonic virus ✓ - Forum Virus
- Faux message virus iphone - Forum iPhone
5 réponses
Utilisateur anonyme
17 févr. 2011 à 01:03
17 févr. 2011 à 01:03
salut
* Télécharge sur le bureau RogueKiller
* Quitte tous tes programmes en cours
* Sous Vista/Seven , clique droit -> lancer en tant qu'administrateur
* Sinon lance simplement RogueKiller.exe
* Lorsque demandé, tape 1 [SCAN] et valide
* Un rapport (RKreport.txt) a du se créer sur le bureau, poste-le.
ensuite:
MBAM est un scanner généraliste qui détecte et supprime beaucoup d'infections:
MBAM :
▣ Télécharge MBAM
▣ Tu auras un tutoriel à ta disposition pour l'installer et l'utiliser correctement.
▣ Fais la mise à jour du logiciel /!\(elle se fait normalement à l'installation)/!\
▣ A l'apparition de la fenêtre de MBAM, clique sur «exécuter un examen complet»
▣ Sélectionne les disques que tu veux analyser et clique sur "Lancer l'examen"
> L'analyse peut durer un plusieurs heures...
▣ Une fois l'analyse terminée, clique sur "OK" puis sur "Afficher les résultats"
▣ Vérifie que tout est bien coché et clique sur "Supprimer la sélection" => et ensuite sur "OK"
▣ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum > Si le logiciel te demande de redémarrer, fais le en cliquant sur « OUI » »
* Télécharge sur le bureau RogueKiller
* Quitte tous tes programmes en cours
* Sous Vista/Seven , clique droit -> lancer en tant qu'administrateur
* Sinon lance simplement RogueKiller.exe
* Lorsque demandé, tape 1 [SCAN] et valide
* Un rapport (RKreport.txt) a du se créer sur le bureau, poste-le.
ensuite:
MBAM est un scanner généraliste qui détecte et supprime beaucoup d'infections:
MBAM :
▣ Télécharge MBAM
▣ Tu auras un tutoriel à ta disposition pour l'installer et l'utiliser correctement.
▣ Fais la mise à jour du logiciel /!\(elle se fait normalement à l'installation)/!\
▣ A l'apparition de la fenêtre de MBAM, clique sur «exécuter un examen complet»
▣ Sélectionne les disques que tu veux analyser et clique sur "Lancer l'examen"
> L'analyse peut durer un plusieurs heures...
▣ Une fois l'analyse terminée, clique sur "OK" puis sur "Afficher les résultats"
▣ Vérifie que tout est bien coché et clique sur "Supprimer la sélection" => et ensuite sur "OK"
▣ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum > Si le logiciel te demande de redémarrer, fais le en cliquant sur « OUI » »
croco20
Messages postés
16
Date d'inscription
jeudi 17 février 2011
Statut
Membre
Dernière intervention
18 juin 2013
17 févr. 2011 à 01:14
17 févr. 2011 à 01:14
ogueKiller V3.10.1 by Tigzy
contact at https://www.luanagames.com/index.fr.html
mail: tigzyRK<at>gmail<dot>com
Feedback: https://www.luanagames.com/index.fr.html
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: aw [Admin rights]
Mode: Scan -- Time : 17/02/2011 00:12:14
Bad processes:
Killed c:\documents and settings\aw\application data\t-mobile internet manager\ouc.exe
Found:
HKCU\...\RUN\ ueapwjpu : C:\Documents and Settings\aw\Local Settings\Application Data\njxdphbhh\pgqqfghtssd.exe
HKCU\...\RUN\ usbkkuhe : C:\Documents and Settings\aw\Local Settings\Application Data\oumtksfud\atsxtsatssd.exe
HKCU\...\RUN\ {F5B734F2-9319-6688-F35E-902094142E3B} : "C:\Documents and Settings\aw\Application Data\Zeeppe\utbah.exe"
HKLM\...\RUN\ ueapwjpu : C:\Documents and Settings\aw\Local Settings\Application Data\njxdphbhh\pgqqfghtssd.exe
HKLM\...\RUN\ usbkkuhe : C:\Documents and Settings\aw\Local Settings\Application Data\oumtksfud\atsxtsatssd.exe
HKUS\S-1-5-21-583907252-1682526488-1417001333-1004...\RUN\ ueapwjpu : C:\Documents and Settings\aw\Local Settings\Application Data\njxdphbhh\pgqqfghtssd.exe
HKUS\S-1-5-21-583907252-1682526488-1417001333-1004...\RUN\ usbkkuhe : C:\Documents and Settings\aw\Local Settings\Application Data\oumtksfud\atsxtsatssd.exe
HKUS\S-1-5-21-583907252-1682526488-1417001333-1004...\RUN\ {F5B734F2-9319-6688-F35E-902094142E3B} : "C:\Documents and Settings\aw\Application Data\Zeeppe\utbah.exe"
HKLM\...\ControlSet002\...\Tcpip\...\Interface\{E04EEAD9-9D46-4A88-B989-CEE2A3E31597}: 149.254.230.7 149.254.199.126
HOSTS File:
127.0.0.1 localhost
Finished
contact at https://www.luanagames.com/index.fr.html
mail: tigzyRK<at>gmail<dot>com
Feedback: https://www.luanagames.com/index.fr.html
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: aw [Admin rights]
Mode: Scan -- Time : 17/02/2011 00:12:14
Bad processes:
Killed c:\documents and settings\aw\application data\t-mobile internet manager\ouc.exe
Found:
HKCU\...\RUN\ ueapwjpu : C:\Documents and Settings\aw\Local Settings\Application Data\njxdphbhh\pgqqfghtssd.exe
HKCU\...\RUN\ usbkkuhe : C:\Documents and Settings\aw\Local Settings\Application Data\oumtksfud\atsxtsatssd.exe
HKCU\...\RUN\ {F5B734F2-9319-6688-F35E-902094142E3B} : "C:\Documents and Settings\aw\Application Data\Zeeppe\utbah.exe"
HKLM\...\RUN\ ueapwjpu : C:\Documents and Settings\aw\Local Settings\Application Data\njxdphbhh\pgqqfghtssd.exe
HKLM\...\RUN\ usbkkuhe : C:\Documents and Settings\aw\Local Settings\Application Data\oumtksfud\atsxtsatssd.exe
HKUS\S-1-5-21-583907252-1682526488-1417001333-1004...\RUN\ ueapwjpu : C:\Documents and Settings\aw\Local Settings\Application Data\njxdphbhh\pgqqfghtssd.exe
HKUS\S-1-5-21-583907252-1682526488-1417001333-1004...\RUN\ usbkkuhe : C:\Documents and Settings\aw\Local Settings\Application Data\oumtksfud\atsxtsatssd.exe
HKUS\S-1-5-21-583907252-1682526488-1417001333-1004...\RUN\ {F5B734F2-9319-6688-F35E-902094142E3B} : "C:\Documents and Settings\aw\Application Data\Zeeppe\utbah.exe"
HKLM\...\ControlSet002\...\Tcpip\...\Interface\{E04EEAD9-9D46-4A88-B989-CEE2A3E31597}: 149.254.230.7 149.254.199.126
HOSTS File:
127.0.0.1 localhost
Finished
Utilisateur anonyme
17 févr. 2011 à 01:15
17 févr. 2011 à 01:15
un rogue comme prévu
MBAM est un scanner généraliste qui détecte et supprime beaucoup d'infections:
MBAM :
▣ Télécharge MBAM
▣ Tu auras un tutoriel à ta disposition pour l'installer et l'utiliser correctement.
▣ Fais la mise à jour du logiciel /!\(elle se fait normalement à l'installation)/!\
▣ A l'apparition de la fenêtre de MBAM, clique sur «exécuter un examen complet»
▣ Sélectionne les disques que tu veux analyser et clique sur "Lancer l'examen"
> L'analyse peut durer un plusieurs heures...
▣ Une fois l'analyse terminée, clique sur "OK" puis sur "Afficher les résultats"
▣ Vérifie que tout est bien coché et clique sur "Supprimer la sélection" => et ensuite sur "OK"
▣ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum > Si le logiciel te demande de redémarrer, fais le en cliquant sur « OUI » »
MBAM est un scanner généraliste qui détecte et supprime beaucoup d'infections:
MBAM :
▣ Télécharge MBAM
▣ Tu auras un tutoriel à ta disposition pour l'installer et l'utiliser correctement.
▣ Fais la mise à jour du logiciel /!\(elle se fait normalement à l'installation)/!\
▣ A l'apparition de la fenêtre de MBAM, clique sur «exécuter un examen complet»
▣ Sélectionne les disques que tu veux analyser et clique sur "Lancer l'examen"
> L'analyse peut durer un plusieurs heures...
▣ Une fois l'analyse terminée, clique sur "OK" puis sur "Afficher les résultats"
▣ Vérifie que tout est bien coché et clique sur "Supprimer la sélection" => et ensuite sur "OK"
▣ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum > Si le logiciel te demande de redémarrer, fais le en cliquant sur « OUI » »
croco20
Messages postés
16
Date d'inscription
jeudi 17 février 2011
Statut
Membre
Dernière intervention
18 juin 2013
17 févr. 2011 à 02:54
17 févr. 2011 à 02:54
voila le rMalwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5777
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
17/02/2011 01:52:41
mbam-log-2011-02-17 (01-52-40).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|)
Objects scanned: 188808
Time elapsed: 48 minute(s), 51 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 29
Registry Values Infected: 7
Registry Data Items Infected: 0
Folders Infected: 9
Files Infected: 79
Memory Processes Infected:
c:\program files\AVGT\antivirusgt.exe (Rogue.AntivirusGT) -> 1264 -> Unloaded process successfully.
Memory Modules Infected:
c:\program files\windows live\messenger\msimg32.dll (PUP.FunWebProducts) -> Not selected for removal.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\SolutionAV (Rogue.AntivirSolutionPro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Miracle (PUP.PerfectOptimizer) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ueapwjpu (Rogue.AntivirusSuite.Gen) -> Value: ueapwjpu -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\usbkkuhe (Rogue.AntivirusSuite.Gen) -> Value: usbkkuhe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{F5B734F2-9319-6688-F35E-902094142E3B} (Trojan.ZbotR.Gen) -> Value: {F5B734F2-9319-6688-F35E-902094142E3B} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AVGT (Rogue.AntivirusGT) -> Value: AVGT -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ueapwjpu (Rogue.AntivirusSuite.Gen) -> Value: ueapwjpu -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\usbkkuhe (Rogue.AntivirusSuite.Gen) -> Value: usbkkuhe -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\program files\AVGT (Rogue.AntivirusGT) -> Quarantined and deleted successfully.
c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\all users\AVP 2009 (Malware.Trace) -> Quarantined and deleted successfully.
Files Infected:
c:\program files\windows live\messenger\msimg32.dll (PUP.FunWebProducts) -> Not selected for removal.
c:\documents and settings\administrator\start menu\Programs\Startup\doruc.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\aw\local settings\Temp\50.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\default user\start menu\Programs\Startup\ogsau.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\program files\uninstall fun web products.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\windows live\messenger\riched20.dll (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP172\A0247553.exe (PUP.Fbsearch) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP172\A0247560.exe (PUP.Fbsearch) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248129.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248147.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248128.scr (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248130.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248131.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248132.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248133.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248134.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248135.SCR (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248136.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248137.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248138.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248139.EXE (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248140.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248141.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248142.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248143.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248145.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248146.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248148.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248149.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248150.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248152.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248153.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248154.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248155.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248156.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248157.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248158.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248159.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248160.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248161.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248174.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248176.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248177.DLL (PUP.PerfectOptimizer) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248178.DLL (PUP.PerfectOptimizer) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248179.DLL (PUP.PerfectOptimizer) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248180.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP177\A0248346.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP177\A0248344.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP177\A0248345.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP177\A0248347.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\aw\Desktop\antivirusgt.lnk (Rogue.AntivirusGT) -> Quarantined and deleted successfully.
c:\program files\AVGT\antivirusgt.exe (Rogue.AntivirusGT) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000977B4.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0009D97C.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000C6ECC.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000D9B17.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000E66B4.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000EE3E3.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00103049.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0011680E.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0011DAEC.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00131FC0.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\001418F5.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00153E89.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0015D904.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\001A0418.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0088CF02.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0097C6EB.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0097F31B.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00991E4D.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\009A5C5B.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\009B64C3.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\009CF43C.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\009DFCD3.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00A0A9E2.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\f3wallpp.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\wrkparam.lst (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
apport
www.malwarebytes.org
Database version: 5777
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
17/02/2011 01:52:41
mbam-log-2011-02-17 (01-52-40).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|)
Objects scanned: 188808
Time elapsed: 48 minute(s), 51 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 29
Registry Values Infected: 7
Registry Data Items Infected: 0
Folders Infected: 9
Files Infected: 79
Memory Processes Infected:
c:\program files\AVGT\antivirusgt.exe (Rogue.AntivirusGT) -> 1264 -> Unloaded process successfully.
Memory Modules Infected:
c:\program files\windows live\messenger\msimg32.dll (PUP.FunWebProducts) -> Not selected for removal.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\SolutionAV (Rogue.AntivirSolutionPro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Miracle (PUP.PerfectOptimizer) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ueapwjpu (Rogue.AntivirusSuite.Gen) -> Value: ueapwjpu -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\usbkkuhe (Rogue.AntivirusSuite.Gen) -> Value: usbkkuhe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{F5B734F2-9319-6688-F35E-902094142E3B} (Trojan.ZbotR.Gen) -> Value: {F5B734F2-9319-6688-F35E-902094142E3B} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AVGT (Rogue.AntivirusGT) -> Value: AVGT -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ueapwjpu (Rogue.AntivirusSuite.Gen) -> Value: ueapwjpu -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\usbkkuhe (Rogue.AntivirusSuite.Gen) -> Value: usbkkuhe -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\program files\AVGT (Rogue.AntivirusGT) -> Quarantined and deleted successfully.
c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\all users\AVP 2009 (Malware.Trace) -> Quarantined and deleted successfully.
Files Infected:
c:\program files\windows live\messenger\msimg32.dll (PUP.FunWebProducts) -> Not selected for removal.
c:\documents and settings\administrator\start menu\Programs\Startup\doruc.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\aw\local settings\Temp\50.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\default user\start menu\Programs\Startup\ogsau.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\program files\uninstall fun web products.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\windows live\messenger\riched20.dll (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP172\A0247553.exe (PUP.Fbsearch) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP172\A0247560.exe (PUP.Fbsearch) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248129.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248147.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248128.scr (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248130.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248131.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248132.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248133.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248134.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248135.SCR (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248136.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248137.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248138.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248139.EXE (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248140.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248141.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248142.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248143.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248145.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248146.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248148.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248149.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248150.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248152.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248153.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248154.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248155.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248156.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248157.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248158.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248159.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248160.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248161.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248174.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248176.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248177.DLL (PUP.PerfectOptimizer) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248178.DLL (PUP.PerfectOptimizer) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248179.DLL (PUP.PerfectOptimizer) -> Not selected for removal.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP175\A0248180.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP177\A0248346.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP177\A0248344.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP177\A0248345.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b0212e98-a9aa-4c3a-9b1d-579227edd6b8}\RP177\A0248347.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\aw\Desktop\antivirusgt.lnk (Rogue.AntivirusGT) -> Quarantined and deleted successfully.
c:\program files\AVGT\antivirusgt.exe (Rogue.AntivirusGT) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000977B4.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0009D97C.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000C6ECC.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000D9B17.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000E66B4.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\000EE3E3.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00103049.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0011680E.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0011DAEC.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00131FC0.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\001418F5.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00153E89.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0015D904.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\001A0418.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0088CF02.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0097C6EB.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\0097F31B.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00991E4D.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\009A5C5B.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\009B64C3.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\009CF43C.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\009DFCD3.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\00A0A9E2.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\f3wallpp.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images\wrkparam.lst (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
apport
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Utilisateur anonyme
17 févr. 2011 à 11:01
17 févr. 2011 à 11:01
ok...
pas mal d'infection, on va voir tout ce que tu as:
pour une analyse de ton système, fais ceci:
----->ZHPDIAG<-----
/!\ utilisateur de vista et seven, désactiver l'UAC./!\
/!\ utilisateur de vista et seven faite clique droit et "éxécuter en temps qu'administrateur/!\
▶ Télécharge zhpdiag (de Nicolas Coolman)
▶ Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
> /!\Utilisateur de Vista et Seven : Clique droit sur le logo de ZHPdiag, « exécuter en tant qu'Administrateur »/!\
▶ Clique sur la petite loupe en haut à gauche pour débuter l'analyse :
▶ attention, le scan peut durer un certain temps, ne touche a rien d'autre tant que le scan est en cour
▶ Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
▶ Héberge le rapport ZHPDiag.txt sur cjoint, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum.
@++
pas mal d'infection, on va voir tout ce que tu as:
pour une analyse de ton système, fais ceci:
----->ZHPDIAG<-----
/!\ utilisateur de vista et seven, désactiver l'UAC./!\
/!\ utilisateur de vista et seven faite clique droit et "éxécuter en temps qu'administrateur/!\
▶ Télécharge zhpdiag (de Nicolas Coolman)
▶ Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
> /!\Utilisateur de Vista et Seven : Clique droit sur le logo de ZHPdiag, « exécuter en tant qu'Administrateur »/!\
▶ Clique sur la petite loupe en haut à gauche pour débuter l'analyse :
▶ attention, le scan peut durer un certain temps, ne touche a rien d'autre tant que le scan est en cour
▶ Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
▶ Héberge le rapport ZHPDiag.txt sur cjoint, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum.
@++