Bonjour , j'ai tout effectué !! j'ai fait l'analyse en mode normal et en mode sans echec !!! beaucoup de problèmes !!!!! peux-tu regarder et me dire s'il te plait !!!!
merci à toi
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1061
Windows 5.1.2600 Service Pack 2
21:03:34 17/08/2008
mbam-log-8-17-2008 (21-03-34).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 118125
Temps écoulé: 1 hour(s), 17 minute(s), 42 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1061
Windows 5.1.2600 Service Pack 2
11:45:18 18/08/2008
mbam-log-8-18-2008 (11-45-18).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 112526
Temps écoulé: 1 hour(s), 18 minute(s), 20 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 192
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Documents and Settings\NetworkService\Documents\eluriz.pif (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\idyfizu.com (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\lavyli.bin (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\nydogin.db (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\potode.pif (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\ulivaw.pif (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\yjub._sy (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\zyfux.inf (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\anesuzenyp.bin (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\igyzih._sy (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\naciveg.reg (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\ubuqicuho.bin (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\zokawi.lib (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\mpr2.dat (Malware.Trace) -> Delete on reboot.
C:\Documents and Settings\NetworkService\svchosts.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Explorer.dll (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\setup.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\admin.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\runmgr.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\ms_tcp.dll (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\xfya.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\oghpd.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\schosst.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\tfm.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\igfxtray.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\sav.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Apps\2.0\srw94.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\imyrasu.pif (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\uwewugotoj.bin (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\tatema.scr (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Cookies\bumo.reg (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Cookies\jababug.inf (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\ycuc.lib (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\bokefa.bat (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\sytetuf.sys (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\vege.ban (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\xyzunore.dl (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\zyfotydyjo.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\etokosyb.scr (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\sec3.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\anok.bat (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\ewabutovah.dl (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\fibaw.ban (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\ybikohe.vbs (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\onyki.lib (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\pyvah.lib (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Cookies\uwux.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Cookies\jiceji._sy (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Cookies\esycire._dl (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Desktopblackbird.jpg (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\DesktopEditorFKWP1.5.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\DesktopEditorFKWP2.0.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Desktopfilemanagerclient.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Desktopfkwp1.5.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Desktopfkwp2.0.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Desktopfwebd.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\DesktopFWebdEditor.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\DesktopTrojan.Win32.BlackBird.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\win.dll (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\svchost.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\lsass.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\smss.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\ctfmon.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\csrss.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\services.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\xacsceib.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\AntiVirusPro.exe.log (Trojan.FakeAlert) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Emails.dat (Stolen.Date) -> Delete on reboot.
C:\Documents and Settings\NetworkService\ntuser.com (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\nww.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\cftmon.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\avsyscare.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\hdip.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\cftmon.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Windowsupdate.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\spool.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\tmp.exe (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\delself.bat (Malware.Trace) -> Delete on reboot.
C:\Documents and Settings\NetworkService\result.txt (Malware.Trace) -> Delete on reboot.
C:\Documents and Settings\NetworkService\install.exe (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\nax.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\NetworkService\balloon.txt (Malware.Trace) -> Delete on reboot.
C:\Documents and Settings\NetworkService\results.txt (Malware.Trace) -> Delete on reboot.
C:\Documents and Settings\NetworkService\My Documents\My Music\My Music.url (Trojan.Zlob) -> Delete on reboot.
C:\Documents and Settings\NetworkService\My Documents\My Pictures\My Pictures.url (Trojan.Zlob) -> Delete on reboot.
C:\Documents and Settings\NetworkService\My Documents\My Videos\My Video.url (Trojan.Zlob) -> Delete on reboot.
C:\Documents and Settings\NetworkService\My Documents\My Documents.url (Trojan.Zlob) -> Delete on reboot.
C:\Documents and Settings\NetworkService\list.txt (Malware.Trace) -> Delete on reboot.
C:\Documents and Settings\NetworkService\ballon.txt (Malware.Trace) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Desktop\iexplor.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\NetworkService\1.exe (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\iexplorer.exe (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\installer.exe (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\lex.exe (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\win32.exe (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\win321.exe (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\wr-1-863 (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\ftpdll.dll (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\NetworkService\xXx.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\NetworkService\win.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\NetworkService\ie_updates3r.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\NetworkService\my documents\work9\bhobj\bhobj.dll (Adware.WebDir) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\dapegog._dl (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\ehypafaka.db (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\nuhe._dl (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\usizer.bin (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\igutymyko.ban (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\ymuxag.com (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Desktop\WinSock.exe (Backdoor.IRCBot) -> Delete on reboot.
C:\Documents and Settings\NetworkService\ntuser.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Tempmbroit.exe (Trojan.FakeAlert) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Cookies\syssp.exe (Fake.Dropped.Malware) -> Delete on reboot.
C:\Documents and Settings\NetworkService\msftp.dll (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temp\_check32.bat (Malware.Trace) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Desktop\msdos.pif (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\csrss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\csrss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\csrss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\csrss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\csrss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\services.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\services.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\services.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\services.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\services.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\smss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\smss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\smss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\smss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\smss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\svchost*.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\svchost*.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\svchost*.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\svchost*.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\svchost*.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\spoolsv.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\spoolsv.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\spoolsv.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\spoolsv.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\spoolsv.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\spoolsv.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\dllhost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\dllhost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\dllhost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\dllhost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\dllhost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\dllhost.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\msiexec.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\msiexec.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\msiexec.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\msiexec.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\msiexec.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\msiexec.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\ctfmon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\ctfmon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\ctfmon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\ctfmon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\ctfmon.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\userinit.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\userinit.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\userinit.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\userinit.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\userinit.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\userinit.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Documents\Settings\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files, REC2\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.