bonjour,
j'ai avast comme anti virus qui m'a detecté des cheval d troie trojan et atres infections.mais malgré les mises en quarantaine, les scan de super antispyware le problème persiste.
voici le rapport hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:18, on 14/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Multimedia Mouse Driver\V5\StartAutorun.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Lexmark 2500 Series\lxddmon.exe
C:\Program Files\Multimedia Mouse Driver\V5\KMConfig.exe
C:\Program Files\Lexmark 2500 Series\lxddamon.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Multimedia Mouse Driver\V5\KMProcess.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\documents and settings\palat\local settings\application data\gqsgeua.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Pando Networks\Pando\Pando.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\PhotoJoy\bin\PjApp.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxddserv.exe
C:\WINDOWS\system32\lxddcoms.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB0.dll
R3 - URLSearchHook: (no name) - {06663B56-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL
O2 - BHO: Pando Search Assistant BHO - {06663B51-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB0.dll
O2 - BHO: (no name) - {CBF43D0E-98FB-46EF-AC09-CB3CB1834E92} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: Pando Toolbar BHO - {E3EA4FD1-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB0.dll
O3 - Toolbar: Pando Toolbar - {E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [LXBLKsk] C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe -startup
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [KMConfig] "C:\Program Files\Multimedia Mouse Driver\V5\StartAutorun.exe" KMConfig.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [PhotoJoy] C:\Program Files\PhotoJoy\bin\PhotoJoy.exe /c
O4 - HKCU\..\Run: [81776629072438244271656594933864] C:\Program Files\A360\av360.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [A00F290DC5F.exe] C:\DOCUME~1\PALAT\LOCALS~1\Temp\_A00F290DC5F.exe
O4 - HKCU\..\Run: [gqsgeua] "c:\documents and settings\palat\local settings\application data\gqsgeua.exe" gqsgeua
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {011F473E-0880-43D4-99F3-F490A84128AE} (GenimoWebGames Control) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--f86698e1-db61-441a-83b9-e220195585bd/online/ButterflyEscape/GenimoWebGamesControl.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} (PhotoboxPhotowaysUploader5 Control) - http://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20090526065014
O16 - DPF: {5392B545-31A5-4724-BEF3-4FED1D56FDAC} (CPlayFirstDinerDash2_frControl Object) - file:///C:/Documents%20and%20Settings/PALAT/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/DinerDash2_fr.1.0.0.70.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1187810420122
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://jeuxenligne.orange.fr/GameShell/online/fr/luxor/mjolauncher.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://zoleo4.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://abonnement.aliceadsl.fr/configurateur/AccountHelper.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/ImageUploader5.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - file:///C:/Documents%20and%20Settings/PALAT/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/ddfotg.1.0.0.37.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://ak.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game06.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://jeux-a-telecharger.fr.pogo.com/online2/pogo/zuma/popcaploader_v10.cab
O16 - DPF: {EB6D7E70-AAA9-40D9-BA05-F214089F2275} (Vitalize Class) - http://download.clickteam.com/vitalize3/vitalize.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: khfCrpqn - C:\WINDOWS\
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: getPlus(R) Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxddserv.exe
O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
et voilà le compte rendu de la mise en quarantaine de avast
15/11/2007 03:07:12 SYSTEM 1468 Sign of "Win32:Kapucen-B [Wrm]" has been found in "C:\Program Files\eMule\Temp\006.part" file.
02/12/2007 08:26:37 SYSTEM 1472 Sign of "Win32:Kapucen-B [Wrm]" has been found in "C:\Program Files\eMule\Temp\Priso-rec.tmp" file.
20/12/2007 08:24:17 SYSTEM 1472 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: D:\autorun.exe (D:\autorun.exe) returning error, 0000001E.
24/12/2007 17:06:39 SYSTEM 1472 Sign of "Win32:Kapucen-B [Wrm]" has been found in "C:\Program Files\eMule\Temp\Priso-rec.tmp" file.
10/01/2008 20:01:26 SYSTEM 1476 Function setifaceUpdatePackages() has failed. Return code is 0x20000011, dwRes is 20000011.
10/01/2008 20:01:27 SYSTEM 1476 An error has occured while attempting to update. Please check the logs.
15/01/2008 10:35:26 SYSTEM 1468 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\album jenifer 2007.zip\setup.exe\$[37]\$PLUGINSDIR\bann.exe" file.
07/02/2008 20:15:16 SYSTEM 1424 Sign of "Win32:TrafficSol [Adw]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\sonnerie telephone portable u2 new.zip\setup.exe\$[37]\$PLUGINSDIR\bann.exe\$SYSDIR\$SYSDIR\sprt_ads.dll\[UPX]" file.
07/02/2008 20:15:30 SYSTEM 1424 Sign of "Win32:TrafficSol [Adw]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\Sexy sonnerie telephone portable u2.zip\setup.exe\$[37]\$PLUGINSDIR\bann.exe\$SYSDIR\$SYSDIR\gzmrt.dll\[UPX]" file.
08/02/2008 19:18:25 SYSTEM 1424 Sign of "Win32:Agent-QXQ [Trj]" has been found in "C:\patch.exe" file.
16/03/2008 14:50:48 SYSTEM 1472 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Program Files\Fichiers communs\Sandlot Shared\is-7CG3J.tmp" file.
04/04/2008 12:12:49 SYSTEM 1472 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\DES_PETITS_TROUS...PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\DES_PETITS_TROUS...PPS) returning error, 00000005.
26/06/2008 07:22:43 SYSTEM 1468 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\ARTICLES,INFOS\LISTEVALIDEPARLEDOCTEURDUKANLE02.DOC (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\ARTICLES,INFOS\LISTEVALIDEPARLEDOCTEURDUKANLE02.DOC) returning error, 00000005.
26/06/2008 07:22:43 SYSTEM 1468 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV ARNAUD.DOC (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV ARNAUD.DOC) returning error, 00000005.
26/06/2008 07:22:43 SYSTEM 1468 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV COM.DOC (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV COM.DOC) returning error, 00000005.
26/06/2008 07:22:43 SYSTEM 1468 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV SECRETAIRE COMPT. WORD 97-2003.DOC (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV SECRETAIRE COMPT. WORD 97-2003.DOC) returning error, 00000005.
26/06/2008 07:22:43 SYSTEM 1468 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\1097_QUITTE.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\1097_QUITTE.PPS) returning error, 00000005.
26/06/2008 07:22:43 SYSTEM 1468 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\5.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\5.PPS) returning error, 00000005.
26/06/2008 07:22:43 SYSTEM 1468 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\8BONNESRAISONS.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\8BONNESRAISONS.PPS) returning error, 00000005.
26/06/2008 07:22:43 SYSTEM 1468 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\AUBADE_HORS_SERIE.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\AUBADE_HORS_SERIE.PPS) returning error, 00000005.
26/06/2008 07:22:43 SYSTEM 1468 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\CODEPARENTAL.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\CODEPARENTAL.PPS) returning error, 00000005.
24/08/2008 08:47:41 SYSTEM 1476 Function setifaceUpdatePackages() has failed. Return code is 0x20000011, dwRes is 20000011.
25/08/2008 08:27:34 SYSTEM 1436 Function setifaceUpdatePackages() has failed. Return code is 0x20000011, dwRes is 20000011.
25/08/2008 12:29:58 SYSTEM 1436 Function setifaceUpdatePackages() has failed. Return code is 0x20000011, dwRes is 20000011.
25/08/2008 18:43:08 SYSTEM 1468 Function setifaceUpdatePackages() has failed. Return code is 0x20000011, dwRes is 20000011.
31/08/2008 09:02:56 SYSTEM 1464 Function setifaceUpdatePackages() has failed. Return code is 0x20000011, dwRes is 20000011.
07/09/2008 14:36:46 SYSTEM 1468 Sign of "Win32:FraudTool-HA [Tool]" has been found in "C:\instala-emuleplus.exe" file.
09/09/2008 07:47:10 PALAT 1356 Sign of "Win32:FraudTool-HA [Tool]" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP432\A0093422.exe" file.
15/09/2008 07:19:56 PALAT 1324 Sign of "WMA:Wimad [Drp]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\chanson pour lauvergnat.mp3" file.
15/09/2008 07:20:20 PALAT 1324 Sign of "WMA:Wimad [Drp]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\lorie album 2007.mp3" file.
15/09/2008 07:20:35 PALAT 1324 Sign of "Win32:DsBot-K [Trj]" has been found in "C:\Documents and Settings\PALAT\Mes documents\Mes fichiers reçus\DSC01497(1).zip" file.
15/09/2008 07:20:44 PALAT 1324 Sign of "Win32:DsBot-K [Trj]" has been found in "C:\Documents and Settings\PALAT\Mes documents\Mes fichiers reçus\DSC01497(2).zip" file.
15/09/2008 07:20:50 PALAT 1324 Sign of "Win32:DsBot-K [Trj]" has been found in "C:\Documents and Settings\PALAT\Mes documents\Mes fichiers reçus\DSC01497.zip" file.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0183.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0183.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0186.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0186.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0189.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0189.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0190.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0190.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0191.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0191.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0193.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0193.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0194.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0194.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0195.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0195.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0196.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0196.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0197.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0197.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0198.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0198.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0199.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0199.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0200.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0200.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0201.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0201.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0203.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0203.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0205.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2008_0820\DSCF0205.JPG) returning error, 00000005.
15/09/2008 12:32:39 SYSTEM 1460 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\TIMEO OH.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\TIMEO OH.JPG) returning error, 00000005.
15/09/2008 20:58:56 SYSTEM 1460 Sign of "WMA:Wimad [Drp]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Incomplete\T-3877627-william balde et christophe ma .mp3" file.
16/09/2008 12:16:11 SYSTEM 1460 Sign of "Win32:Lineage-351 [Trj]" has been found in "C:\Program Files\eMule\Temp\003.part" file.
18/09/2008 10:12:50 PALAT 3944 Sign of "Win32:Kapucen-B [Wrm]" has been found in "C:\Program Files\eMule\Temp\006.part" file.
05/10/2008 12:39:53 SERVICE RÉSEAU 1456 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS LIVE CONTACTS\FAMPALAT@HOTMAIL.FR\REAL\CONTACTCOLL.CACHE (C:\DOCUMENTS AND SETTINGS\PALAT\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS LIVE CONTACTS\FAMPALAT@HOTMAIL.FR\REAL\CONTACTCOLL.CACHE) returning error, 00000005.
13/12/2008 14:33:28 PALAT 1132 Sign of "Win32:Navipromo-H [Adw]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temp\NSIS_Install_WMP.exe\$PLUGINSDIR\NSUtils.dll\[UPX]" file.
13/12/2008 14:34:12 PALAT 1132 Sign of "Win32:Mailskinner [Trj]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temp\NSIS_Install_WMP.exe\$INSTDIR\WebMediaPlayer.exe" file.
13/12/2008 14:40:47 PALAT 1132 Sign of "WMA:Wimad [Drp]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\moriarty cute girl has orgasm on webcam.mp3" file.
13/12/2008 19:25:09 SYSTEM 1464 Sign of "HTML:Iframe-inf" has been found in "http://bigmp3online.com/?sid=aff0043\?sid=aff0043" file.
13/12/2008 20:54:09 PALAT 1132 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Program Files\eMule\Incoming\PRISON BREAK SAISON 2 french episode 25 Share Accelerator\zapu2.145.exe\%MAINDIR%\Zapu\ZapuInstallerSigned.exe\$INSTDIR\Installer.exe\$INSTDIR\Bin\2.0.22\ShoppingReport.dll" file.
14/12/2008 01:11:47 PALAT 1132 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\MultiMedia Toolbar\MultiMedia - Installer.exe\$INSTDIR\Installer.exe" file.
14/12/2008 02:32:04 SYSTEM 1464 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temporary Internet Files\Content.IE5\7R7QKZFL\wax[1].jpg" file.
14/12/2008 07:43:43 SYSTEM 1464 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\system32\khfCrpqn.dll" file.
14/12/2008 07:44:08 SYSTEM 1464 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\system32\khfCrpqn.dll" file.
14/12/2008 07:44:50 SYSTEM 1464 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\system32\khfCrpqn.dll" file.
14/12/2008 07:45:03 SYSTEM 1464 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\system32\khfCrpqn.dll" file.
14/12/2008 07:45:26 SYSTEM 1464 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\system32\khfCrpqn.dll" file.
14/12/2008 07:45:39 SYSTEM 1464 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\system32\khfCrpqn.dll" file.
14/12/2008 07:51:30 PALAT 4884 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\byxrjklb.dll" file.
14/12/2008 07:51:43 PALAT 4884 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\fccdddcc.dll" file.
14/12/2008 07:51:48 PALAT 4884 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\jkkiypno.dll" file.
14/12/2008 07:51:55 PALAT 4884 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\khfcrpqn.dll" file.
14/12/2008 07:52:04 PALAT 4884 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\mljappix.dll" file.
14/12/2008 07:52:14 PALAT 4884 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\qomgebyy.dll" file.
14/12/2008 07:52:33 PALAT 4884 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\xxyayxrr.dll" file.
14/12/2008 07:52:36 PALAT 4884 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\xxyvvmmk.dll" file.
14/12/2008 07:52:38 PALAT 4884 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\xxyyayrl.dll" file.
14/12/2008 08:05:47 SYSTEM 1464 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temporary Internet Files\Content.IE5\QZ3JSO74\wax[1].jpg" file.
14/12/2008 08:22:26 PALAT 5268 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temporary Internet Files\Content.IE5\QZ3JSO74\wax[1].jpg" file.
14/12/2008 08:37:25 SYSTEM 1464 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\waxx.exe" file.
14/12/2008 09:19:19 PALAT 248 Sign of "Win32:Adware-gen [Adw]" has been found in "c:\windows\system32\khfcrpqn.dll" file.
14/12/2008 11:31:23 SYSTEM 1492 Sign of "HTML:Iframe-inf" has been found in "http://bigmp3online.com/?sid=aff0043\?sid=aff0043" file.
14/12/2008 12:29:30 PALAT 3028 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP532\A0120686.exe\%MAINDIR%\Zapu\ZapuInstallerSigned.exe\$INSTDIR\Installer.exe\$INSTDIR\Bin\2.0.22\ShoppingReport.dll" file.
14/12/2008 12:31:40 SYSTEM 1492 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temporary Internet Files\Content.IE5\7R7QKZFL\wax[1].jpg" file.
14/12/2008 12:31:44 PALAT 3028 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP532\A0120690.exe\$INSTDIR\Installer.exe" file.
14/12/2008 12:31:51 SYSTEM 1492 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\waxx.exe" file.
14/12/2008 13:47:05 PALAT 1516 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temporary Internet Files\Content.IE5\4P1WBF4J\wax[1].jpg" file.
14/12/2008 13:47:16 PALAT 1516 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\waxx.exe" file.
14/12/2008 19:23:20 PALAT 1512 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temporary Internet Files\Content.IE5\A475BWE6\wax[1].jpg" file.
14/12/2008 19:23:38 PALAT 1512 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\waxx.exe" file.
14/12/2008 20:35:05 SYSTEM 1520 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\hgGxWmll.dll" file.
14/12/2008 20:36:10 SYSTEM 1520 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\geBtUlJb.dll" file.
14/12/2008 21:05:51 SYSTEM 1520 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temporary Internet Files\Content.IE5\4P1WBF4J\wax[1].jpg" file.
14/12/2008 21:06:09 SYSTEM 1520 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\waxx.exe" file.
14/12/2008 21:08:58 PALAT 2920 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "c:\windows\system32\gebtuljb.dll" file.
14/12/2008 21:10:31 PALAT 2920 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "c:\windows\system32\hggxwmll.dll" file.
14/12/2008 22:05:06 PALAT 1512 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temporary Internet Files\Content.IE5\4ERHBIX1\something[1].exe" file.
14/12/2008 22:05:17 PALAT 1512 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\systemer.exe" file.
15/12/2008 21:02:30 SYSTEM 1500 Sign of "HTML:Iframe-inf" has been found in "http://bigmp3online.com/?sid=aff0043\?sid=aff0043" file.
16/12/2008 18:11:17 SYSTEM 1492 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\SYSTEM32\VCYRBA.DLL" file.
16/12/2008 19:05:27 SYSTEM 1492 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\vcyrba.dll" file.
16/12/2008 19:05:47 SYSTEM 1492 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\vcyrba.dll" file.
16/12/2008 19:05:57 SYSTEM 1492 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\vcyrba.dll" file.
16/12/2008 19:13:35 SYSTEM 1492 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\SYSTEM32\JBKJQS.DLL" file.
16/12/2008 19:42:48 PALAT 480 Sign of "Win32:Rbot-GJB [Trj]" has been found in "C:\WINDOWS\fxstaller.exe.vir" file.
16/12/2008 20:19:48 PALAT 480 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\htjqqcte.dll" file.
16/12/2008 20:20:34 PALAT 480 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\nfxeuhul.dll" file.
16/12/2008 20:21:47 PALAT 480 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\trzB0.tmp" file.
31/12/2008 14:13:59 PALAT 1504 Sign of "WMA:Wimad [Drp]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Incomplete\T-5745425-zaza fournier.mp3" file.
31/12/2008 14:14:01 PALAT 1504 Sign of "WMA:Wimad [Drp]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\zaza fournier.mp3" file.
01/01/2009 13:03:40 SYSTEM 1508 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV CECILE PALAT.DOC (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV CECILE PALAT.DOC) returning error, 00000005.
01/01/2009 13:03:40 SYSTEM 1508 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV SECRETAIRE COMPT. WORD 97-2003.DOC (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CV SECRETAIRE COMPT. WORD 97-2003.DOC) returning error, 00000005.
01/01/2009 13:03:40 SYSTEM 1508 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CVASSISTANTE COMPTABLE COULEUR LIN WORD 97-2003.DOC (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\CV CéCILE\CVASSISTANTE COMPTABLE COULEUR LIN WORD 97-2003.DOC) returning error, 00000005.
30/01/2009 12:33:10 SYSTEM 1520 Function setifaceUpdatePackages() has failed. Return code is 0x20000011, dwRes is 20000011.
02/03/2009 06:14:10 SYSTEM 1520 Function setifaceUpdatePackages() has failed. Return code is 0x20000011, dwRes is 20000011.
24/03/2009 23:07:44 SYSTEM 1632 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES VIDéOS\IDEDEVACANCES.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES VIDéOS\IDEDEVACANCES.PPS) returning error, 00000005.
11/04/2009 19:45:59 SYSTEM 1540 Sign of "Win32:BHO-WF [Trj]" has been found in "C:\DOCUME~1\PALAT\LOCALS~1\Temp\dat29D.tmp\[UPX]" file.
11/04/2009 19:46:10 SYSTEM 1540 Sign of "Win32:BHO-WF [Trj]" has been found in "C:\WINDOWS\system32\ci.dll\[UPX]" file.
11/04/2009 20:34:14 PALAT 3824 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\PALAT\Bureau\Raccourcis Bureau non utilisés\InternetGameBox\InternetGameBox.exe" file.
11/04/2009 21:15:13 PALAT 3824 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Office2007\Office7.iso\COOLGHOST_LISEZMOI.EXE" file.
11/04/2009 21:16:57 PALAT 3824 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Office2007.part13.rar\coolghost_Lisezmoi.exe" file.
11/04/2009 21:46:58 PALAT 3824 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Recycled\Dc26.iso\COOLGHOST_LISEZMOI.EXE" file.
11/04/2009 21:48:55 PALAT 3824 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Recycled\Dc28.rar\coolghost_Lisezmoi.exe" file.
11/04/2009 21:49:14 PALAT 3824 Sign of "Win32:SkiMorph [Cryp]" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP570\A0127458.exe" file.
11/04/2009 21:51:15 PALAT 3824 Sign of "Win32:SkiMorph [Cryp]" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP620\A0135301.exe" file.
11/04/2009 21:51:26 PALAT 3824 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP626\A0135524.exe" file.
11/04/2009 21:52:17 PALAT 3824 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP650\A0138713.exe" file.
11/04/2009 22:01:46 PALAT 3824 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\system32\awttrOHX.dll" file.
11/04/2009 22:03:14 PALAT 3824 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\system32\efcDVLBu.dll" file.
11/04/2009 22:03:55 PALAT 3824 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\system32\opnOeEwT.dll" file.
16/04/2009 22:55:51 SYSTEM 1540 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
17/04/2009 02:55:54 SYSTEM 1540 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
17/04/2009 06:55:58 SYSTEM 1540 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
18/04/2009 10:52:41 SYSTEM 1548 Sign of "VBS:Malware-gen" has been found in "http://toppromooffer.com/vsmfr/adv/1/?a=cspyock-sst&l=373&f=cs_2472625704&ex=1&ed=2&h=&sub=csp&prodabbr=3P_UVSMIT\{gzip}" file.
20/04/2009 23:40:47 SERVICE LOCAL 1544 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\INSOLITES.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\INSOLITES.PPS) returning error, 00000005.
20/04/2009 23:40:47 SERVICE LOCAL 1544 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\LEPLUSGROSLEPLUSLONGG.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\LEPLUSGROSLEPLUSLONGG.PPS) returning error, 00000005.
20/04/2009 23:40:47 SERVICE LOCAL 1544 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\LESNOUNOURSDUBONHEUR.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\LESNOUNOURSDUBONHEUR.PPS) returning error, 00000005.
20/04/2009 23:40:47 SERVICE LOCAL 1544 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\MARIAGE ANGLAIS2.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\MARIAGE ANGLAIS2.PPS) returning error, 00000005.
22/04/2009 14:44:36 SYSTEM 1548 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
01/05/2009 07:45:53 SYSTEM 1532 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
04/05/2009 21:02:52 PALAT 1544 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\DOCUME~1\PALAT\LOCALS~1\Temp\_A00F290DC5F.exe" file.
10/05/2009 07:16:09 SYSTEM 1548 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\SYSTEM32\__C00DBFF.DAT" file.
10/05/2009 08:11:02 SYSTEM 1548 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\system32\__c00DBFF.dat" file.
10/05/2009 08:11:14 SYSTEM 1548 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\system32\__c00DBFF.dat" file.
10/05/2009 08:11:25 SYSTEM 1548 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\WINDOWS\system32\__c00DBFF.dat" file.
13/05/2009 00:34:50 SYSTEM 1532 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\WINDOWS\SoftwareDistribution\Download\cd4745a6b5a95e2f1cdc6e69b95de17d\BIT5FD.tmp (C:\WINDOWS\SoftwareDistribution\Download\cd4745a6b5a95e2f1cdc6e69b95de17d\BIT5FD.tmp) returning error, 00000026.
16/05/2009 08:50:39 SYSTEM 1532 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR 2008\STRING_2009_01-BH.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR 2008\STRING_2009_01-BH.PPS) returning error, 00000005.
16/05/2009 08:50:39 SYSTEM 1532 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR 2008\UN_ARABE_ARRIVE-PARIS-JOJO-CE.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR 2008\UN_ARABE_ARRIVE-PARIS-JOJO-CE.PPS) returning error, 00000005.
16/05/2009 08:50:39 SYSTEM 1532 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\1097_QUITTE.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\1097_QUITTE.PPS) returning error, 00000005.
16/05/2009 08:50:39 SYSTEM 1532 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\5.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\5.PPS) returning error, 00000005.
16/05/2009 08:50:39 SYSTEM 1532 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\8BONNESRAISONS.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\8BONNESRAISONS.PPS) returning error, 00000005.
16/05/2009 08:50:39 SYSTEM 1532 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\AUBADE_HORS_SERIE.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\AUBADE_HORS_SERIE.PPS) returning error, 00000005.
16/05/2009 08:50:39 SYSTEM 1532 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\CODEPARENTAL.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\CODEPARENTAL.PPS) returning error, 00000005.
21/05/2009 16:44:56 SYSTEM 1528 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2009_0521\DSCF0806.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2009_0521\DSCF0806.JPG) returning error, 00000005.
21/05/2009 16:44:56 SYSTEM 1528 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2009_0521\DSCF0807.JPG (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\MES IMAGES\FINEPIXVIEWERS\2009_0521\DSCF0807.JPG) returning error, 00000005.
18/06/2009 23:27:28 SYSTEM 1528 Function setifaceUpdateFiles() has failed. Return code is 0xC0000142, dwRes is C0000142.
18/06/2009 23:27:38 SYSTEM 1528 An error has occured while attempting to update. Please check the logs.
19/06/2009 05:09:51 SYSTEM 1528 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
19/06/2009 05:10:11 SYSTEM 1528 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
19/06/2009 05:10:21 SYSTEM 1528 An error has occured while attempting to update. Please check the logs.
06/07/2009 20:00:56 PALAT 1520 Sign of "WMA:Wimad [Drp]" has been found in "C:\Program Files\eMule\Temp\002.part" file.
06/07/2009 20:03:58 PALAT 1520 Sign of "WMA:Wimad [Drp]" has been found in "C:\Program Files\eMule\Temp\010.part" file.
06/07/2009 20:07:20 PALAT 1520 Sign of "WMA:Wimad [Drp]" has been found in "C:\Program Files\eMule\Temp\009.part" file.
08/07/2009 23:58:35 PALAT 3128 Sign of "Win32:ConHook-DF [Trj]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temp\WER74da.dir00\iexplore.exe.hdmp" file.
09/07/2009 07:15:16 PALAT 3128 Sign of "NSIS:FakeAV-B [Trj]" has been found in "C:\Documents and Settings\PALAT\Local Settings\Temporary Internet Files\Content.IE5\JK8GK9AK\vsmfr_free_setup[1].exe\nsis.hdr" file.
09/07/2009 07:24:21 PALAT 3128 Sign of "HTML:RedirME-inf [Trj]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\sonnerie portable rihanna mp3.html" file.
09/07/2009 07:25:30 PALAT 3128 Sign of "HTML:RedirME-inf [Trj]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\sonnerie telephone portable u2 mp3.html" file.
09/07/2009 07:25:39 PALAT 3128 Sign of "HTML:RedirME-inf [Trj]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\sonnerie telephone portable u2 music.html" file.
09/07/2009 07:25:43 PALAT 3128 Sign of "WMA:Wimad [Drp]" has been found in "C:\Documents and Settings\PALAT\Mes documents\LimeWire\Saved\zaza fournier.mp3" file.
09/07/2009 07:37:53 PALAT 3128 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Office2007\Office7.iso\COOLGHOST_LISEZMOI.EXE" file.
09/07/2009 08:45:29 PALAT 3128 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\eMule\Incoming\(2008 Tour Edition) l' odyssée de la vie.fr .exe\Setup_00.exe\GL1.exe" file.
09/07/2009 09:35:46 PALAT 3128 Sign of "WMA:Wimad [Drp]" has been found in "C:\Program Files\eMule\Incoming\odyssée de la vie.fr documentaire [multilanguage].avi" file.
09/07/2009 14:48:11 PALAT 3128 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Recycled\Dc26.iso\COOLGHOST_LISEZMOI.EXE" file.
09/07/2009 18:14:20 PALAT 3128 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP650\A0138714.dll" file.
09/07/2009 18:15:07 PALAT 3128 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP650\A0138715.dll" file.
09/07/2009 18:15:21 PALAT 3128 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP650\A0138716.dll" file.
09/07/2009 18:20:48 PALAT 3128 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP678\A0155052.exe" file.
09/07/2009 18:41:24 PALAT 3128 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{A322724A-406E-4CB8-9A25-2AB814EC6F7C}\RP736\A0175368.exe\Setup_00.exe\GL1.exe" file.
10/07/2009 22:53:49 PALAT 1532 Sign of "WMA:Wimad [Drp]" has been found in "C:\Program Files\eMule\Temp\001.part" file.
11/07/2009 09:43:22 SERVICE LOCAL 1524 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\CODEPARENTAL.PPS (C:\DOCUMENTS AND SETTINGS\PALAT\MES DOCUMENTS\HUMOUR,DIVERS\CODEPARENTAL.PPS) returning error, 00000005.
13/07/2009 14:52:14 SYSTEM 1504 Sign of "Win32:Mutant-BK [Trj]" has been found in "C:\documents and settings\palat\local settings\application data\gqsgeua.dat" file.
MERCI DE VOTRE AIDE