I suspect it sees stuff in System restore. Thread Status: Not open for further replies. During the last part of having a look around her computer and already having done a Hijack this log, Norton's flashed up that they repaired a file successfully...it was...C:\windows\puta!!.com...this I can't Antivirus Bookshelf 2000 Caere Scan Manager 5.0 Calcul CAM-IN SUITE III Canon MP Navigator 2.0 Canon MP150 Canon Utilities Easy-PhotoPrint CCleaner (remove only) Chords v1.1 Chords v1.1 (C:\Program Files\Chords\) Christmas 3D this content

If it lists the same trojan a million times in c:\system volume information\_restore.... The strange thing is that when using the same broadband connection with a different PC (desktop) this doesn't happen at all. Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...43/yacscom.cab O16 - DPF: {3FE489A9-B78F-4698-9563-0AEC1080DFD0} (nsBrowserConfig Class 2) - https://www.marketscore.com/globalco...sconfig_th.cab O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! If you don't know...

Thomas Dyche ... You can just use Windows Explorer to delete it rather than "delete on reboot". Ce fichier, dont le nom rappelle celui d'un des fichiers détectés comme virussés, n'est jamais remarqué, ni par AVAST quand il est résident, ni Bitdefender, ni ESET Online.

Her definitons are as up to date as possible. So... Après deux essais successifs de scan et fix par HiJackThis , le résultat m'a paru concluant et j'ai lancé ESET Online (que je ne connaissais pas alors que j'ai acheté Nod32 Here is a copy of the latest one this morning.

Select the country/language of your choice:Asia Pacific RegionAPACAustralia中国 (China)Hong Kong (English)香港 (中文)भारत गणराज्य (India)Indonesia日本 (Japan)대한민국 (South Korea)MalaysiaNew ZealandPhilippinesSingapore台灣 (Taiwan)ราชอาณาจักรไทย (Thailand)Việt Nam (Vietnam)EuropeBelgië (Belgium)Česká RepublikaDanmarkDeutschland, Österreich, SchweizEspañaFranceItaliaNederlandNorge (Norway)Polska (Poland)Россия (Russia)South AfricaSuomi (Finland)Sverige Si je peux rattraper cette erreur, merci de me dire comment. Using Internet Explorer please do an online scan with Kaspersky Online Scanner Click on Kaspersky Online Scanner You will be promted to install an ActiveX component from Kaspersky, Click Yes. html > > Thumper > > "Bryan Henderson" <(E-Mail Removed)> wrote in message > news:bm0gi3$gt76p$(E-Mail Removed)-berlin.de... > > The problem I am having is when connected to the net with my

Web Scanner C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce-] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx-] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices-] SchedulingAgent mstask.exe KPF4 C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe Machine Debug Manager C:\WINDOWS\SYSTEM\MDM.EXE avast! Are you looking for the solution to your computer problem? Now click on the Save as Text button: Save the file to your desktop. By joining you are opting in to receive e-mail.

In the left panel, double-click the following: HKEY_LOCAL_MACHINE>Software>Microsoft> Windows>CurrentVersion>Run In the right panel, locate and delete the entry: PutAS! http://www.commentcamarche.net/forum/affich-7214912-speedy-puta-natal-brasil-alevir-instit-marco Celle dont j'aimerais disposer est celle d'un outil (antivirus ou utilitaire) capable de supprimer en force ce type de fichier résistant. Merci encore de votre aide. Register now while it's still free!

Close Registry Editor. http://lebos.org/general/c-windows-system32-nvcpl-dll.php RE: Worms and stuff! O4 - Startup: Barre d'Outils Olitec.lnk = C:\OLIFAXVX\TOOLBAR.EXE O4 - Startup: Sitecom WL-168 Wireless LAN Utility.lnk = C:\Program Files\Sitecom WL-168 Wireless LAN Driver and Utility\RtWLan.exe O4 - Startup: WiFi Station pour I asked him if they gave him a list of what they fixed and he said no. -------------- SpywareDoctor --------------- Anyhow, when we got the computer all hooked up again, it

Spyware Forums > Newsgroups > Anti-Virus > Viruses adding litems to WIN.INI file

Spyware Forums > Newsgroups > Anti-Virus > Viruses adding litems to WIN.INI file Search Forums Show Threads Show Posts It then adds the following registry entry to run itself at every system startup: HKEY_LOCAL_MACHINE\Software\Microsoft\ Windows\CurrentVersion\Run PutAS! = %Windows%\ Puta!!.com It may also modify the [Windows] section of the WIN.INI file http://lebos.org/general/c-windows-system32-cmd-exe.php Create Account How it Works Javascript Disabled Detected You currently have javascript disabled.

Win 98 SE jrbarnett (Programmer) 26 Oct 03 12:05 Hi,If it keeps coming back, there is obviously a loader somewhere that reinstalls it, so run MSCOnfig and post back here what These startup entries must be removed before the system can be restarted safely. Patching Microsoft Exploit Microsoft Windows 9x/Me provides a password protection feature referred to as Share Level Access for the File and Print Sharing service.

I wasn't running Kazaalite recently or any other p2p app and no sharing is enabled on the drive that I can see.

Open System Configuration Editor. And now finish'd by William Pardon, Gent. Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Thanks Oceana908, May 13, 2004 #6 Oceana908 Thread Starter Joined: Dec 30, 2003 Messages: 607 And would I be right in thinking that her computer would be more stable if

Le fait d'être membre vous permet d'avoir des options supplémentaires. I have now fixed the problem with my desktop PC - faulty NIC so will use that most of the time as before. Spyware Warrior Forum Index -> Archived Spyware Removal Help Topics View previous topic :: View next topic Author Message aardvarkNewbieJoined: 04 Jul 2006Last Visit: 07 Sep 2006Posts: 3 Posted: Wed check my blog Verson 1.0 Verson 1.2c If not...

The ninth edition, etcThomas DYCHE, William PARDONC. TIA. > > you say you've ruled out email, and you make no mention of p2p apps... > have you checked to make sure you've got no shares accessible to the