Virus bagle

Résolu
Bonjour,

je pense etre infecte par le virus bagle
le rapport apres scan par findykill est copié ci dessous
que dois je faire pour continuer

############################# | FindyKill V5.005 |

# User : hp (Administrateurs) # YOUR-A289DD5720
# Update on 27/07/09 by Chiquitine29
# Start at: 19:09:51 | 07/08/2009
# Website : http://pagesperso-orange.fr/NosTools/index.html

# AMD Turion(tm) 64 X2 Mobile Technology TL-50
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 6.0.2900.5512
# Windows Firewall Status : Enabled

# C:\ # Disque fixe local # 103,51 Go (21,61 Go free) # NTFS
# D:\ # Disque fixe local # 8,27 Go (1,34 Go free) [HP_RECOVERY] # FAT32
# E:\ # Disque CD-ROM

############################## | Processus actifs |

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Software Update 3\SoftAuto.exe
C:\Program Files\Micro Application\LauncherMA.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## | C: |

Présent ! D:\autorun.inf

################## | C:\WINDOWS |

Présent ! C:\WINDOWS\Prefetch\122890.EXE-312A7C45.pf
Présent ! C:\WINDOWS\Prefetch\131015.EXE-32C4E38F.pf
Présent ! C:\WINDOWS\Prefetch\144921.EXE-088C3F47.pf
Présent ! C:\WINDOWS\Prefetch\157562.EXE-092F8899.pf
Présent ! C:\WINDOWS\Prefetch\182453.EXE-16AE1D25.pf
Présent ! C:\WINDOWS\Prefetch\183937.EXE-36AD1084.pf
Présent ! C:\WINDOWS\Prefetch\207750.EXE-0A373723.pf
Présent ! C:\WINDOWS\Prefetch\FLEC006.EXE-1F4F3159.pf
Présent ! C:\WINDOWS\Prefetch\KEY_GENERATOR.EXE-014A72DB.pf
Présent ! C:\WINDOWS\Prefetch\MDELK.EXE-1D176F91.pf
Présent ! C:\WINDOWS\Prefetch\WINTEMS.EXE-2A563F9B.pf

################## | C:\WINDOWS\system32 |

Présent ! C:\WINDOWS\system32\ban_list.txt
Présent ! C:\WINDOWS\system32\mdelk.exe
Présent ! C:\WINDOWS\system32\wintems.exe

################## | C:\WINDOWS\system32\drivers |

################## | C:\Documents and Settings\hp\Application Data |

Présent ! C:\Documents and Settings\hp\Application Data\drivers
Présent ! C:\Documents and Settings\hp\Application Data\drivers\111wfs1intwq.sys
Présent ! C:\Documents and Settings\hp\Application Data\drivers\11s11ro1s1a2.sys
Présent ! C:\Documents and Settings\hp\Application Data\drivers\downld
Présent ! C:\Documents and Settings\hp\Application Data\drivers\winupgro.exe
Présent ! C:\Documents and Settings\hp\Application Data\m
Présent ! C:\Documents and Settings\hp\Application Data\m\data.oct
Présent ! C:\Documents and Settings\hp\Application Data\m\flec006.exe
Présent ! C:\Documents and Settings\hp\Application Data\m\list.oct
Présent ! C:\Documents and Settings\hp\Application Data\m\srvlist.oct
Présent ! C:\Documents and Settings\hp\Application Data\m\shared

################## | C:\Documents and Settings\hp\Temporary Internet Files |

################## | Registre / Clés infectieuses |

Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\111111s1ro1s1a]
Présent ! [HKLM\SYSTEM\ControlSet001\Services\111111s1ro1s1a]
Présent ! [HKLM\SYSTEM\ControlSet003\Services\111111s1ro1s1a]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\sK9Ou0s]
Présent ! [HKLM\SYSTEM\ControlSet001\Services\sK9Ou0s]
Présent ! [HKLM\SYSTEM\ControlSet003\Services\sK9Ou0s]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_111111s1ro1s1a]
Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_111111s1ro1s1a]
Présent ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_111111s1ro1s1a]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S]
Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S]
Présent ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S]
Présent ! [HKCU\Software\bisoft]
Présent ! [HKCU\Software\DateTime4]
Présent ! [HKCU\Software\MuleAppData]
Présent ! [HKCU\Software\Microsoft\Windows\UI] "KEY540534"
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\Microsoft\Windows\UI] "KEY540534"
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\bisoft]
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\DateTime4]
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\FFC]
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\MuleAppData]
Présent ! [HKCU\Software\Local AppWizard-Generated Applications\key_generator]
Présent ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\Local AppWizard-Generated Applications\key_generator]
Présent ! [HKU\S-1-5-21-3093132267-2353182382-1781867984-1005\Software\Local AppWizard-Generated Applications\winupgro]

################## | Etat / Services / Informations |

# Affichage des fichiers cachés : OK

Clé manquante : HKLM\...\SafeBoot | Mode sans echec non fonctionnel !

# (!) Ndisuio -> Start = 4 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
# (!) Ip6Fw -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) wuauserv -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )

################## | Cracks / Keygens / Serials |

################## | ! Fin du rapport # FindyKill V5.005 ! |
Configuration: Windows XP
Firefox 3.0.6

25 réponses

Résumé de la discussion

Une suspicion d'infection par le virus Bagle (Beagle) apparaît après un scan FindyKill et le rapport détaillé est partagé pour déterminer les étapes suivantes. Le rapport récapitule des processus actifs, des entrées de registre et des éléments d'autorun signalant une infection complexe, avec des recommandations d'utiliser Ad-remover, Toolbar-S&D et Malwarebytes Anti-Malware pour nettoyer et diagnostiquer. Plusieurs propositions proposent des procédures concrètes allant de la désinstallation de certains logiciels de sécurité incompatibles à l'exécution d'analyses en mode sans échec avec Anti-Spyware et des rapports à poster ensuite. En outre, l'échange évoque l'utilisation d'outils complémentaires comme RSIT et souligne que Bagle peut modifier le comportement réseau et nécessiter une remise à plat du système, sans conclure sur une solution définitive.

Bobot (l’IA à votre service)
  1. j'ai posté hier dond demain c'est aujourd'hui, lol :)

    Très bien, ton ordinateur n'est plus infecté !

    Avant de retourner sur le net, il y a quelques petites choses que tu dois faire pour finir le nettoyage et améliorer sensiblement la sécurité de ton ordinateur, ça t'évitera peut-être de devoir revenir ici avec une nouvelle infection dans le futur ;)

    Mais sache qu'aucun logiciel de sécurité ne te protègera à 100%, ce qui fait la différence, c'est ta vigilance lorsque tu télécharges ou installes quelque chose : pour en savoir plus, je t'invite à bien lire la page indiquée tout en bas de ce message.

    Tout est important /!\

    1) Les barres d'outils

    Souvent installées avec d'autres logiciels sans que l'utilisateur y fasse attention, les barres d'outils se multiplient sur les ordinateurs et ont deux résultats : ralentir les ordinateurs et provoquer des bugs des navigateurs.

    Ce qu'il faut savoir sur les toolbars (barres d'outils)
    Je te conseille vivement de ne pas en installer.

    2) Sécurise ton ordinateur

    Anti-virus :

    OK

    Anti-spyware :

    * Installe Spybot (a l'installation decoche le tea timer qui ne sert a rien !). Mets le à jour regulierement (une fois par semaine), et fais les vaccinations à chaque fois.

    * En complément, garde MalwareBytes pour son scan de nettoyage performant.

    Pour naviguer sur internet plus en sécurité et à l’abri des publicités, je te conseille vivement d’installer et d'utiliser le navigateur Firefox 3 avec deux extensions :
    AdBlockPlus pour bloquer les publicités ;

    WOT, pour t'avertir des sites web dangereux.

    3) Télécharge ToolsCleaner sur ton Bureau pour nettoyer l'ordi de tous les outils qu'on a utilisé : ToolsCleaner

    Lance le, clique sur Recherche et laisse le scan se finir, puis clique sur Suppression pour nettoyer.
    Tu peux aussi supprimer les fichiers temporaires.
    Ensuite, supprime manuellement ToolsCleaner (mets le à la corbeille).
    S'il ne supprime pas tout, supprime manuellement ce qui reste.

    4) Télécharge et installe Ccleaner (si ce n’est déjà fait) :

    Lance CCleaner
    Option --> avancé --> décoche « effacer uniquement les fichiers plus vieux que 48h »
    Puis nettoyeur --> Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
    Enfin, registre --> corrige toutes les erreurs, et recommence jusqu'à ce qu'il ne trouve plus d'erreurs.

    (Tu peux garder ce logiciel et l'utiliser régulièrement).

    5) Pour finir le nettoyage, il faut purger la restauration du système (pour supprimer les points de restauration infectés).

    Fais un clic droit sur poste de travail (qui est sur ton Bureau ou dans le menu démarrer), puis propriétés.
    Sélectionne l'onglet restauration du système
    Coche l'option Désactiver la restauration du système sur tous les lecteurs
    Clique sur OK.

    Puis refais la manipulation inverse pour réactiver la restauration système.

    6) Je t'invite enfin à visiter cette page qui t'apportera des informations de prévention et de protection contre les infections (environ 15 minutes de lecture très instructive et utile):
    Prévention et sécurité sur internet

    Bonne lecture, bon courage, et n'hésite pas à poser des questions en cas de besoin ;)

    Et penses a mettre ton sujet en « RESOLU » ;)

    1. je ferais toutes ces manip demain
      encore merci pour votre aide
      je vais sensibiliser tous les utilisateurs aux consignes données
  2. tu as des restes de Norton, pour ne pas créer de conflits :
    utilise cet outil

    pour Firefox :

    MAJ FIREFOX : http://www.mozilla-europe.org/fr/

    je te donne la fin demain :)

    1. bonjour

      desinstalation norton faite
      pour l'instant je vais garder ie
      mozilla est desinstallé

      a demain

      bonne journée
  3. oui je sais , t es pas fini , je sais , pas la peine de le repeter ;)
    1. euhhhhhhhhhh je ne me rappelle pas avoir dis que j'avais fini !

      luaos, post 37 au cas ou tu n'aurais pas vu :)
      1. j' ai mis a jour ie et adobe
        pour certains le site me propose un autre logiciel poor la lecture des medias
        j ai supprime mozilla
    2. tres bien Lauos, tu peux passer aux MAJ (et ne fais pas attention aux intrus, c'est souvent le week end quand y'a rien a la tv ^^)
      1. Sans vouloir t offenser t as oublié des services inutiles :

        O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

        oublie pas de supprimer les dossiers

        +++
        1. sans vouloir t'offenser, prendre des ujets au pif de genhackman, moi,... ca t'eclates ?
          prends toi des sujets tu verras , on t'embettra pas ;)
          1. non habitue des forums
            je ne comprends pas votre discussion avec christina
            merci en tout cas de votre aide
        2. Hello ,

          MAJ ADOBE , bah pourquoi , l user a pas adobe ...

          TU supprimes des services non néfaste pourquoi ? l user t as demandé d accéléré sa machine ?

          le dossier : C:\Program Files\Fichiers communs\Symantec Shared , il passe a la trape ??

          ++++
          1. je t'ai repondu au dessus ;)

            Pour firefox, il n'est pas a jour non plus, il faudra le mettre a jour et ton probleme sera peut etre reglé :)
            1. je voudrais quand meme verifier quelquechose, peux tu faire ca :

              • Rends toi sur le site https://www.virustotal.com/gui/
              • Clique sur Parcourir, et navigue jusqu'au fichier suivant et valide :
              C:\Program Files\Micro Application\LauncherMA.exe

              • Clique sur "Envoyer le fichier" : s'il a déjà été analysé, demande une nouvelle analyse.
              • Fais un copier/coller du rapport sur le forum.

              Si tu ne trouves pas le fichier, fais ceci :
              • Menu Démarrer --> Panneau de configuration --> Options des dossiers --> Affichage
              • Coche "Afficher les fichiers et dossiers cachés", décoche "Masquer les extensions de fichiers connus", décoche "Masquer les fichiers protégés du Système", puis valide.
              • Tu pourras à nouveau masquer les fichiers cachés une fois la manipulation terminée, si tu le souhaites.


              En attendant ma reponse :


              • Adobe Reader n’est pas à jour, c’est une faille de sécurité. Désinstalle le en allant dans menu démarrer --> panneau de configuration --> ajout/suppression de programmes. Puis télécharge et installe la nouvelle version.

              MAJ ADOBE : https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html
              A cause de ca

              pareil pour Internet explorer
              MAJ IE8 : https://support.microsoft.com/en-us/office/internet-explorer-help-23360e49-9cd3-4dda-ba52-705336cc0de2?ui=en-US&rs=en-001&ad=US

              • Tu dois aussi mettre à jour tous tes autres programmes pour combler des failles de sécurité... Vérifie les mises disponibles à l'aide de ce petit programme (choisis la version sans installation) : Update Checker

              on pourra "enfin"terminer une fois ca fait (demain sans doute :) )

              pourquoi tenir ses programmes a jour
              1. voila le rapport
                Antivirus Version Dernière mise à jour Résultat
                a-squared 4.5.0.24 2009.08.08 -
                AhnLab-V3 5.0.0.2 2009.08.08 -
                AntiVir 7.9.0.248 2009.08.07 -
                Antiy-AVL 2.0.3.7 2009.08.07 -
                Authentium 5.1.2.4 2009.08.08 -
                Avast 4.8.1335.0 2009.08.07 -
                AVG 8.5.0.406 2009.08.08 -
                BitDefender 7.2 2009.08.08 -
                CAT-QuickHeal 10.00 2009.08.08 -
                ClamAV 0.94.1 2009.08.07 -
                Comodo 1912 2009.08.08 -
                DrWeb 5.0.0.12182 2009.08.08 -
                eSafe 7.0.17.0 2009.08.06 -
                eTrust-Vet 31.6.6667 2009.08.08 -
                F-Prot 4.4.4.56 2009.08.08 -
                F-Secure 8.0.14470.0 2009.08.08 -
                Fortinet 3.120.0.0 2009.08.08 -
                GData 19 2009.08.08 -
                Ikarus T3.1.1.64.0 2009.08.08 -
                Jiangmin 11.0.800 2009.08.08 -
                K7AntiVirus 7.10.814 2009.08.08 -
                Kaspersky 7.0.0.125 2009.08.08 -
                McAfee 5703 2009.08.08 -
                McAfee+Artemis 5703 2009.08.08 -
                McAfee-GW-Edition 6.8.5 2009.08.07 -
                Microsoft 1.4903 2009.08.08 -
                NOD32 4317 2009.08.08 -
                Norman 6.01.09 2009.08.07 -
                nProtect 2009.1.8.0 2009.08.08 -
                Panda 10.0.0.14 2009.08.08 -
                PCTools 4.4.2.0 2009.08.08 -
                Prevx 3.0 2009.08.08 -
                Rising 21.41.52.00 2009.08.08 -
                Sophos 4.44.0 2009.08.08 -
                Sunbelt 3.2.1858.2 2009.08.08 -
                Symantec 1.4.4.12 2009.08.08 -
                TheHacker 6.3.4.3.378 2009.08.08 -
                TrendMicro 8.950.0.1094 2009.08.08 -
                VBA32 3.12.10.9 2009.08.07 -
                ViRobot 2009.8.8.1875 2009.08.08 -
                VirusBuster 4.6.5.0 2009.08.08 -
                Information additionnelle
                File size: 485376 bytes
                MD5...: f0ea603e7b91046ca48ea4b3593a007d
                SHA1..: 52c6cd15baf1dfaea8b87cbbab04780aa08c87be
                SHA256: acd81cd50ed837da12cb0846d9f7a9e177b7bc5a9426fe6830ff72bf42356018
                ssdeep: 12288:j9CbgpLAJhpMT/Yru4BUvaHGFH0yernVUqz1Z:MbphpMTwZUb0yen9n
                PEiD..: -
                TrID..: File type identification
                Win64 Executable Generic (59.6%)
                Win32 Executable MS Visual C++ (generic) (26.2%)
                Win32 Executable Generic (5.9%)
                Win32 Dynamic Link Library (generic) (5.2%)
                Generic Win/DOS Executable (1.3%)
                PEInfo: PE Structure information

                ( base data )
                entrypointaddress.: 0x351e0
                timedatestamp.....: 0x4991b128 (Tue Feb 10 16:54:00 2009)
                machinetype.......: 0x14c (I386)

                ( 5 sections )
                name viradd virsiz rawdsiz ntrpy md5
                .text 0x1000 0x4e4e8 0x4e600 6.57 0404385855e7e6f2b38445bf5a871937
                .rdata 0x50000 0x12b66 0x12c00 4.76 c1333591f20aad2e90ddd7ff4b5feb6c
                .data 0x63000 0x72b8 0x3600 4.22 c42d1c492c244793f8dc713f7c51ad95
                .rsrc 0x6b000 0x7c70 0x7e00 5.09 1ea73bcf4c9babf05e9e60b0e1d94d5f
                .reloc 0x73000 0x9c30 0x9e00 4.17 1cd55f842c065319b3c191e872740f7a

                ( 14 imports )
                > KERNEL32.dll: SetErrorMode, GetFileAttributesW, GetFileSizeEx, GetFileTime, GetTickCount, GetStartupInfoW, HeapSize, VirtualProtect, VirtualAlloc, GetSystemInfo, VirtualQuery, RtlUnwind, RaiseException, ExitThread, CreateThread, ExitProcess, SetUnhandledExceptionFilter, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, HeapDestroy, VirtualFree, QueryPerformanceCounter, GlobalFlags, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, LCMapStringW, LCMapStringA, GetTimeZoneInformation, InitializeCriticalSectionAndSpinCount, GetLocaleInfoA, GetConsoleCP, GetConsoleMode, GetStringTypeA, GetStringTypeW, GetCurrentDirectoryA, GetDriveTypeA, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, SetEnvironmentVariableA, TlsFree, LocalReAlloc, TlsSetValue, TlsAlloc, GlobalHandle, GlobalReAlloc, TlsGetValue, InterlockedIncrement, CreateFileW, GetFullPathNameW, GetVolumeInformationW, GetCurrentProcess, DuplicateHandle, GetFileSize, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, GetThreadLocale, GetModuleHandleA, InterlockedDecrement, GetCurrentProcessId, WritePrivateProfileStringW, FreeResource, GlobalAddAtomW, GlobalFindAtomW, GetVersionExW, CompareStringW, LoadLibraryA, GetVersionExA, GlobalDeleteAtom, GetCurrentThread, ConvertDefaultLocale, EnumResourceLanguagesW, lstrcmpA, GetLocaleInfoW, LoadLibraryW, CompareStringA, InterlockedExchange, lstrcmpW, FreeLibrary, GetModuleHandleW, GetProcAddress, SuspendThread, SetEvent, GetCurrentThreadId, SetThreadPriority, CloseHandle, FindFirstFileW, FileTimeToLocalFileTime, FileTimeToSystemTime, FindNextFileW, FindClose, SetLastError, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, MulDiv, CreateEventW, ReleaseMutex, CreateMutexW, LocalFree, LocalAlloc, lstrcpynW, FormatMessageW, GetModuleFileNameW, EnterCriticalSection, LeaveCriticalSection, HeapAlloc, HeapReAlloc, GetProcessHeap, InitializeCriticalSection, lstrlenA, DeleteCriticalSection, HeapFree, GetLastError, WideCharToMultiByte, Sleep, WaitForSingleObject, ResumeThread, CreateSemaphoreW, FindResourceW, LoadResource, LockResource, SizeofResource, MultiByteToWideChar, GetSystemTimeAsFileTime, lstrlenW
                > USER32.dll: RegisterClipboardFormatW, ReleaseCapture, SetCapture, LoadCursorW, GetSysColorBrush, CharUpperW, EndPaint, BeginPaint, GetWindowDC, ReleaseDC, GetDC, ClientToScreen, GrayStringW, DrawTextExW, DrawTextW, TabbedTextOutW, ShowWindow, MoveWindow, SetWindowTextW, IsDialogMessageW, DestroyMenu, GetWindowThreadProcessId, SetCursor, GetMenuCheckMarkDimensions, LoadBitmapW, ModifyMenuW, EnableMenuItem, CheckMenuItem, GetDesktopWindow, CreateDialogIndirectParamW, IsWindowEnabled, GetNextDlgTabItem, EndDialog, SetWindowContextHelpId, MapDialogRect, SendDlgItemMessageA, WinHelpW, IsChild, GetCapture, GetClassLongW, GetClassNameW, SetPropW, GetPropW, RemovePropW, GetFocus, IsWindow, SetFocus, GetWindowTextW, GetForegroundWindow, SetActiveWindow, GetDlgItem, GetTopWindow, DestroyWindow, UnhookWindowsHookEx, GetMessageTime, GetMessagePos, MapWindowPoints, SetMenu, UpdateWindow, MessageBoxW, CreateWindowExW, GetClassInfoExW, GetClassInfoW, RegisterClassW, GetSysColor, AdjustWindowRectEx, GetParent, EqualRect, GetDlgCtrlID, DefWindowProcW, CopyRect, PtInRect, GetMenu, GetWindowLongW, SetWindowPos, OffsetRect, IntersectRect, SystemParametersInfoA, GetWindowPlacement, GetWindowRect, GetWindow, UnregisterClassW, MessageBeep, GetNextDlgGroupItem, InvalidateRgn, InvalidateRect, PostQuitMessage, SetWindowsHookExW, CopyAcceleratorTableW, SetRect, IsRectEmpty, CharNextW, SendDlgItemMessageW, CallNextHookEx, GetMessageW, GetActiveWindow, IsWindowVisible, GetKeyState, ValidateRect, GetMenuState, GetMenuItemID, GetMenuItemCount, PostMessageW, TrackPopupMenu, SetForegroundWindow, GetCursorPos, SetMenuDefaultItem, GetSubMenu, LoadMenuW, RegisterWindowMessageW, SetWindowLongW, CallWindowProcW, EnableWindow, SetMenuItemBitmaps, InsertMenuItemW, DrawIcon, GetClientRect, GetSystemMetrics, IsIconic, SendMessageW, AppendMenuW, GetSystemMenu, LoadIconW, DispatchMessageW, TranslateMessage, PeekMessageW, PostThreadMessageW, GetLastActivePopup
                > GDI32.dll: ExtSelectClipRgn, DeleteDC, GetStockObject, GetBkColor, CreateRectRgnIndirect, GetRgnBox, GetMapMode, GetWindowExtEx, GetViewportExtEx, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, TextOutW, RectVisible, GetTextColor, GetDeviceCaps, DeleteObject, SetMapMode, RestoreDC, SaveDC, ExtTextOutW, CreateBitmap, GetObjectW, SetBkColor, SetTextColor, GetClipBox, PtVisible
                > COMDLG32.dll: GetFileTitleW
                > WINSPOOL.DRV: DocumentPropertiesW, ClosePrinter, OpenPrinterW
                > ADVAPI32.dll: RegQueryValueW, RegOpenKeyW, RegEnumKeyW, RegDeleteKeyW, RegOpenKeyExW, RegSetValueExW, RegCreateKeyExW, RegCloseKey, RegQueryValueExW
                > SHELL32.dll: SHGetSpecialFolderPathW, ShellExecuteW, Shell_NotifyIconW, ExtractIconExW
                > COMCTL32.dll: InitCommonControlsEx
                > SHLWAPI.dll: PathFindFileNameW, PathStripToRootW, PathIsUNCW, PathFindExtensionW
                > oledlg.dll: OleUIBusyW
                > ole32.dll: CoUninitialize, CLSIDFromString, CoCreateInstance, CoTaskMemFree, CoTaskMemAlloc, CLSIDFromProgID, CoGetClassObject, StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal, OleUninitialize, CoFreeUnusedLibraries, OleInitialize, CoRevokeClassObject, OleIsCurrentClipboard, OleFlushClipboard, CoRegisterMessageFilter, CoInitialize
                > OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -
                > gdiplus.dll: GdipCreateBitmapFromScan0, GdipCreateHBITMAPFromBitmap, GdiplusShutdown, GdiplusStartup, GdipDrawImageRectI, GdipDeleteGraphics, GdipGetImageGraphicsContext, GdipCreateBitmapFromHICON, GdipCloneImage, GdipAlloc, GdipDisposeImage, GdipFree
                > WS2_32.dll: WSASetEvent, WSAEventSelect, WSAConnect, WSAEnumNetworkEvents, WSASend, WSAResetEvent, WSACreateEvent, -, WSAGetOverlappedResult, -, -, -, WSACloseEvent, WSASocketW, getaddrinfo, WSARecv, freeaddrinfo, -

                ( 0 exports )
                PDFiD.: -
                RDS...: NSRL Reference Data Set
                -

                ATENTION ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares.

                Autre fichier
                VirusTotal © Hispasec Sistemas -
            2. merci mais certains ne comprennent pas ou ne le trouvent pas, donc la solution de facilité ............
              1. puis je profiter de vos competences pour vous demander la raison du msg suivant quand je lance mozilla

                Exception... "Component returned failure code: 0x80520001 (NS_ERROR_FILE_UNRECOGNIZED_PATH) [nsILocalFile.initWithPath]" nsresult: "0x80520001 (NS_ERROR_FILE_UNRECOGNIZED_PATH)" location: "JS frame :: chrome://megaupload/content/xpcom/network.js :: anonymous :: line 38" data: no]
            3. Hello ,

              Télécharges le fichier d'installation

              Il suffait de demander d aller à ce fichier

              C:\Program Files\trend micro\hp.exe

              C est l'éxecutif HJT

              +++
              1. télécharges le fichier d'installation
                HIJACKTHIS

                Enregistre HJTInstall.exe sur ton bureau.

                Double-clique sur HJTInstall.exe pour lancer le programme

                Par défaut, il s'installera là :
                C:\Program Files\Trend Micro\HijackThis

                Accepte la licence en cliquant sur le bouton "I Accept"

                clic sur
                DO A SYSTEM SCAN ONLY
                puis coches toutes ces lignes (et seulement ces lignes : tu pourrais altérer le fonctionnement de ton pc!)
                puis clic sur
                FIX CHEKEED

                R3 - Default URLSearchHook is missing
                O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll
                O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe

                Dis moi quand c'est ok , ensuite on s'occuppe de tes mises a jours programmes , tu as l'air faché avec, lol , ce sont pourtant de grosses failles de securite pour certaines !
                1. apres avoir clic sir fix chekked
                  om me pose une question si je veux effaver ou reparer ce que je selectionne
                  dois je repondre oui
              2. slt

                penses surtout a vider la quarantaine de MBAM.

                dois je telecharger antivir aussi


                oui en suivant ceci, il faut virer avast avant , ensuite tu peux en profiter pour faire un scan avec et poste le rapport.

                Désinstalle via Ajout/Suppression de Programmes (si présents) :

                * Avast!

                Télécharge et exécute Désinstalleur d'Avast!
                Ceci effacera la majorité des traces du produit Avast! d'Alwil Software

                Télécharge AntiVir sur ton Bureau.:

                * Double clique sur l'exécutable téléchargé pour lancer l'installation.
                * À la fin de l'installation, clique sur Finish.
                * Ouvre Antivir, assure-toi qu’il soit bien à jour !

                Note : Pour une éradication des menaces plus efficace, lance le scan en mode sans échec.

                Pourquoi changer ? Avast vs Antivir.

                Aide : Comment installer et utiliser AntiVir.

                Tuto Antivir

                Configuration de Antivir :

                clic droit sur son icone dans la barre des taches et séléctionner Configurer Antivir.

                cocher la case : Mode Expert.

                => Cliquer sur Scanner dans le volet de gauche :

                > Dans "Fichiers" séléctionner Tous les fichiers.

                > Dans procédure de recherche, cocher Autoriser l'arrêt, et dans "priorité scanner" séléctionner Elevé.

                > Dans "Autres réglages" cocher toutes les cases.

                NE SURTOUT PAS OUBLIER LA RECHERCHE DES ROOTKIT QUI EST TRES IMPORTANTE !

                Ensuite

                Peux tu refaire la manip avec RSIT stp, cette fois 1 seul rapport s'ouvrira, poste le et ensuite on sera proche de la fin ;)
                1. voici le rapport rsit

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by hp at 2009-08-08 16:36:12
                  Microsoft Windows XP Professionnel Service Pack 3
                  System drive C: has 22 GB (21%) free of 106 GB
                  Total RAM: 1023 MB (54% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 16:36:30, on 08/08/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Creative\Software Update 3\SoftAuto.exe
                  C:\Program Files\Micro Application\LauncherMA.exe
                  C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                  C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                  C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Creative\Shared Files\CTDevSrv.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\eHome\ehRecvr.exe
                  C:\WINDOWS\eHome\ehSched.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\system32\PSIService.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\WINDOWS\system32\dllhost.exe
                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                  C:\Program Files\RamBoost XP\rambxpfr.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\hp\Mes documents\Téléchargements\RSIT(2).exe
                  C:\Program Files\trend micro\hp.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - Default URLSearchHook is missing
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
                  O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [SoftAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe"
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Startup: Lanceur.lnk = C:\Program Files\Micro Application\LauncherMA.exe
                  O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                  O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                  O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                  O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                  O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                  O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                  O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
                  O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe
                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                  O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
              3. ok

                pourrais tu poster ton rapport complet stp, j'aimerais voir la fin au cas ou il y aurait autrechose,
                il sera trop long pour ccm donc il faut l'heberger:

                rends toi ds MBAM puis onglet rapport/log
                enregistre ton rapport sur ton bureau par ex dans un fichier txt (avec le bloc notes)
                rends toi sur cjoint.com
                clic sur parcourir
                choisis le fichier que tu viens de créer et valide en cliquant sur "creer le lient"
                un lien te sera généré, poste le moi stp

              4. ok la suite au post 14 :)
                1. voici le rapportde malwabytes
                  bonne soiree

                  Malwarebytes' Anti-Malware 1.40
                  Version de la base de données: 2575
                  Windows 5.1.2600 Service Pack 3

                  07/08/2009 23:08:23
                  mbam-log-2009-08-07 (23-08-22).txt

                  Type de recherche: Examen complet (C:\|D:\|)
                  Eléments examinés: 204194
                  Temps écoulé: 53 minute(s), 40 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 1
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 1255

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  C:\Documents and Settings\hp\Temporary Internet Files\Content.IE5\AAB71DSO\b64_3[1].jpg (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP313\A0323364.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP313\A0323365.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323405.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323406.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323407.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323420.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323421.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323422.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323435.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323436.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323438.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323437.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323495.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323496.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP314\A0323497.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323576.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323577.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323578.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323596.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323597.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323598.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323614.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323615.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323616.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323637.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323634.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323635.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323636.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323661.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323662.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP315\A0323663.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323696.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323697.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323698.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324018.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323931.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323932.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323933.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323957.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323958.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323959.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323960.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323971.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323972.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0323973.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324019.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324020.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324032.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324033.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324034.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324045.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324046.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324047.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324098.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324099.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP316\A0324100.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324173.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324174.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324186.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324187.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324188.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324191.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324211.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324212.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324213.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324172.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324242.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324278.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324226.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324227.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324228.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324241.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324243.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324244.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324263.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324264.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324265.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324277.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324279.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324291.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324292.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324294.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324321.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324322.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324343.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324344.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324345.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324362.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324363.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0324364.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0325365.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0325366.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0325367.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP319\A0325368.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325448.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325449.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325474.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325475.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325476.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325501.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325503.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325504.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325519.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325520.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325521.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325579.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325580.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325581.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325595.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325596.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325597.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325598.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325610.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325611.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325612.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325625.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325626.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP320\A0325627.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326222.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326158.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326159.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326160.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326205.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326206.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326207.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326219.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326220.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326223.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326224.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326236.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326237.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326238.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326248.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326249.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326250.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326251.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326281.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326282.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326283.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326315.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326316.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326317.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326329.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326330.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326406.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326407.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326408.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326365.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326366.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326367.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326432.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326433.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326456.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326457.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326458.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326459.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326476.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326477.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326478.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326490.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326491.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326492.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326529.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326530.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326531.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326565.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326566.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326568.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326328.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326435.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326587.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326588.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326589.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326631.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326632.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326633.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326656.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326742.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326743.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326755.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326756.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326757.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326758.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326759.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326760.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326864.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326744.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326865.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326867.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326885.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326886.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326887.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326899.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326901.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326911.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326912.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326913.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326926.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326927.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326928.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326939.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326941.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326942.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326994.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326995.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326996.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326997.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327017.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327018.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327019.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327031.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327032.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327033.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327044.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327045.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327046.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327047.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327058.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327059.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327073.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327074.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327075.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327088.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327089.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327090.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327091.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327092.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328088.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328089.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328090.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328105.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328106.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328108.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0326900.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327060.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0327078.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328207.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328208.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328209.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328224.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328225.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328236.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328237.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328238.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328325.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328326.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328327.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328337.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328338.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328339.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328354.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328355.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328356.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328357.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328372.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328373.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328374.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328375.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328223.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328455.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328456.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328458.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328469.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328470.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328471.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328481.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328482.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328483.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328484.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP328\A0328485.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328505.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328507.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328508.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328610.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328611.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328612.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328613.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328615.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328626.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328627.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328628.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328629.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328653.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328654.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328655.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP329\A0328656.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP330\A0328671.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP330\A0328672.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329514.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329515.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329516.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329570.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329571.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329573.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329598.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329599.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329600.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329601.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329513.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329612.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329613.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329614.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329641.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329642.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329644.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329645.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329658.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329659.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329660.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329714.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329715.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329716.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329718.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329721.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329676.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329677.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329678.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329679.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329787.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329788.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329789.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329792.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329895.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329896.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329897.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329912.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329913.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329914.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329925.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329926.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329927.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329928.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329929.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329941.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329942.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329943.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0329944.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0330959.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0330960.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0330961.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0330962.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0330963.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0330965.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0330976.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0330977.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0330978.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331092.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331093.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331094.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331095.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331109.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331110.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331111.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331112.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331113.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331118.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331263.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331264.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331265.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331266.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0331268.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333294.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333295.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333293.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333487.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333488.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333490.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333491.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333513.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333522.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333523.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333524.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333533.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333534.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333535.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333538.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333552.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333553.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333554.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333555.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333558.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333559.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333560.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333584.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333585.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333589.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333590.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333594.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333595.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333609.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333624.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333628.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333629.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333630.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333637.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333638.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333639.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333643.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333646.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333658.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333659.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333669.exe (Worm.Bagle) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP334\A0333677.exe (Worm.Bagle) -> Quarantined and deleted success
              5. ok tres bien , a TOOLSBARSD


                ENSUITE (au cas ou je repasse pas ce soir)


                Imprime ces instructions ou sauvegarde les sur ton Bureau car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                Télécharge Malwarebytes’ Anti-Malware

                (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX)

                - Sur la page cliques sur Télécharger Malwarebyte’s Anti-Malware
                - Enregistres le sur le bureau
                - Double cliques sur le fichier téléchargé pour lancer le processus d’installation
                - Lorsqu’il te le sera demandé, met à jour Malwarebytes anti malware
                - Si le pare-feu demande l’autorisation de se connecter pour malwarebytes, acceptes
                - Une fois la mise à jour terminée, ferme Malwarebytes
                - Double-cliques sur l’icône de malwarebytes pour le relancer
                - Dans l’onglet, Recherche, probablement ouvert par défaut,
                - Sélectionne Exécuter un examen complet
                - Clique sur Rechercher
                - Le scan démarre
                - A la fin de l’analyse, un message s’affiche : L’examen s’est terminé normalement. Cliquez sur ‘Afficher les résultats’ pour afficher tous les objets trouvés.
                - Cliques sur Ok pour poursuivre.
                - Si des malwares ont été détectés, cliques sur Afficher les résultats
                - Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                - Malwarebytes va ouvrir le bloc-notes et y copier le rapport d’analyse.
                - Rends toi dans l’onglet rapport/log
                - Tu cliques dessus pour l’afficher une fois affiché
                - Tu cliques sur édition en haut du bloc notes, et puis sur sélectionner tout
                - Tu recliques sur édition et puis sur copier et tu reviens sur le forum et dans ta réponse
                - Tu cliques droit dans le cadre de la réponse et coller

                Si tu as besoin d’aide regarde ce tutorial

                https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                ps: s'il te demande de redemarrer : fais le !
                1. voila le rapport toolbar

                  -----------\\ ToolBar S&D 1.2.8 XP/Vista

                  Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 X2 Mobile Technology TL-50 )
                  BIOS : PhoenixBIOS 4.0 Release 6.1
                  USER : hp ( Administrator )
                  BOOT : Normal boot
                  C:\ (Local Disk) - NTFS - Total:103 Go (Free:22 Go)
                  D:\ (Local Disk) - FAT32 - Total:8 Go (Free:1 Go)
                  E:\ (CD or DVD)

                  "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                  Option : [2] ( 07/08/2009|21:25 )

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ Extensions

                  (hp) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
                  (hp) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
                  (hp) - {991A772A-BA13-4c1d-A9EF-F897F31DEC7D} => megaupload

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                  "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                  "Search Page"="https://www.google.com/?gws_rd=ssl"
                  "Search Bar"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                  "Default_page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                  "Window Title"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                  "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                  "Start Page"="https://www.msn.com/fr-fr/"
                  "Search Bar"="http://www.bing.com/spresults.aspx"

                  --------------------\\ Recherche d'autres infections

                  --------------------\\ Cracks & Keygens ..

                  C:\DOCUME~1\hp\Application Data\Real\RealPlayer\History\Crack Addict.lnk
                  C:\DOCUME~1\hp\Application Data\Real\RealPlayer\History\Eminem, Crack A Bottle..lnk
                  C:\DOCUME~1\hp\Mes documents\Ma musique\fightclub\CD2\12 - Limp Bizkit - Crack Addict.mp3

                  1 - "C:\ToolBar SD\TB_1.txt" - 07/08/2009|21:25 - Option : [2]

                  -----------\\ Fin du rapport a 21:25:38,21
              6. dsl, essaie ce lien :))
                1. voila le raaport ad report
                  .
                  ======= RAPPORT D'AD-REMOVER 1.1.4.5_O | UNIQUEMENT XP/VISTA/SEVEN =======
                  .
                  Mit à jour par C_XX le 24/06/2009 à 7:10 PM
                  Contact: AdRemover.contact@gmail.com
                  Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                  .
                  Lancé à: 20:54:41, 07/08/2009 | Mode Normal | Option: CLEAN
                  Exécuté de: C:\Program Files\Ad-remover\
                  Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                  Nom du PC: YOUR-A289DD5720 | Utilisateur actuel: hp
                  .
                  Administrateur: Administrateur
                  N'est pas administrateur: ASPNET
                  N'est pas administrateur: HelpAssistant *Desactive*
                  Administrateur: hp
                  N'est pas administrateur: Invité *Desactive*
                  N'est pas administrateur: SUPPORT_388945a0 *Desactive*
                  .
                  ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                  .
                  .
                  HKCR\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
                  HKCR\EoRezoBHO.EoBho
                  HKCR\EoRezoBHO.EoBho.1
                  HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                  HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                  HKCU\Software\EoRezo
                  HKCU\Software\ItsLabel
                  HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
                  HKLM\Software\EoRezo
                  HKLM\Software\ItsLabel
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
                  HKLM\Software\Search Settings
                  HKLM\Software\Trymedia Systems
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings
                  HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                  HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                  .
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\cmhost.cyp
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\ConfMedia.cyp
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\ConfMedia.cyp.old
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\db
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\eoDesktop
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\eoStats
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather.cfg
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\host.cyp
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\user.cyp
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\db\cat.cyp
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\eoDesktop\config.xml
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\eoDesktop\eoDesktop.html
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\eoDesktop\userConfig.xml
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\eoStats\eoStats.txt
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\EoWeatherVal_02EC282.cfg
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\67_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\67_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\69_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\69_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\70_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\70_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\78_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\78_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\82_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\82_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\83_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\83_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\84_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\84_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\85_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\85_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\89_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\89_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\back.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\background.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\background_1.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\background_1days.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\background_2days.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\background_7days.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\backPressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\band.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\band_small.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\close.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\closePressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\dayPrevisionBackground.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\dayPrevisionClose.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\earth.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\fonds_‚cran.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\help.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\helpPressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\minimise.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\minimisePressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\next.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\nextPressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\option.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\optionPressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\reflet_ecran.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\small_background.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_classic\Thumbs.db
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\67_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\67_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\69_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\69_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\70_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\70_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\78_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\78_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\82_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\82_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\83_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\83_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\84_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\84_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\85_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\85_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\89_day.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\89_night.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\about.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\back.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\background.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\background_1.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\background_1days.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\background_2days.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\background_7days.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\backPressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\close.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\closePressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\dayPrevisionBackground.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\dayPrevisionClose.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\earth.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\fonds_‚cran.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\help.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\helpPressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\minimise.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\minimisePressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\next.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\nextPressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\option.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\optionPressed.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\reflet_ecran.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\Thumbs.db
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo\EoWeather\images_station_meteo\txt_14x13.png
                  C:\DOCUME~1\hp\APPLIC~1\EoRezo
                  C:\DOCUME~1\hp\APPLIC~1\ItsLabel\ItsTV
                  C:\DOCUME~1\hp\APPLIC~1\ItsLabel\ItsTV\itsTV.xml
                  C:\DOCUME~1\hp\APPLIC~1\ItsLabel
                  C:\DOCUME~1\hp\APPLIC~1\Search Settings\kb128
                  C:\DOCUME~1\hp\APPLIC~1\Search Settings\kb128\temp
                  C:\DOCUME~1\hp\APPLIC~1\Search Settings\kb128\temp\ws-14461.log
                  C:\DOCUME~1\hp\APPLIC~1\Search Settings
                  C:\Program Files\EoRezo\EoAdv
                  C:\Program Files\EoRezo\EoWeather
                  C:\Program Files\EoRezo\EoAdv\eoAdv.url
                  C:\Program Files\EoRezo\EoAdv\EoRezoBho.old
                  C:\Program Files\EoRezo\EoWeather\ItsTV.exe
                  C:\Program Files\EoRezo
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\chrome.manifest
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\COMPONENTS
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\install.rdf
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT\DStringsUtils.js
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT\searchsettingsplugin.js
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT\searchsettingsplugin.xul
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE\EN-US
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE\EN-US\searchsettingsplugin.dtd
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE\EN-US\searchsettingsplugin.properties
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\COMPONENTS\IFBHOSearch.xpt
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\COMPONENTS\IFBHOSearchHelperEngine.xpt
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\COMPONENTS\IFHelperPreferences.xpt
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\COMPONENTS\SearchSettingsFF.dll
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\COMPONENTS\sscfg.ini
                  C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com

                  (!) -- Fichiers temporaires supprimés.

                  .
                  ============== Scan additionnel ==============
                  .

                  * Mozilla FireFox Version 3.5 *

                  Nom du profil: jpsrov1o.default (hp)
                  .
                  (Prefs.js) user_pref("browser.search.defaultenginename", "Yahoo");
                  (Prefs.js) user_pref("browser.search.selectedEngine", "Yahoo");
                  (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
                  (Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.fr/firefox?client=firefox-a&rls=org.mozilla:fr:official");
                  (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.1");
                  .
                  .

                  * Internet Explorer Version 6.0.2900.5512 *

                  [HKEY_CURRENT_USER\..\Internet Explorer\Main]

                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                  Search Page: hxxp://www.google.com
                  Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Search bar: hxxp://search.msn.com/spbasic.htm
                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Start Page: hxxp://fr.msn.com/

                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                  Tabs: res://ieframe.dll/tabswelcome.htm

                  ============== Suspect (Cracks, Serials ... ) ==============

                  .
                  .
                  ===================================
                  .
                  13176 Octet(s) - C:\Ad-Report-CLEAN.log
                  .
                  8 Fichier(s) - C:\DOCUME~1\hp\LOCALS~1\Temp
                  77 Fichier(s) - C:\WINDOWS\Temp
                  .
                  17 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
                  23 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
                  .
                  Fin à: 21:15:35 | 07/08/2009
                  .
                  ============== E.O.F ==============
                  .
              • 1
              • 2