AUSSI UN PROBLEME AVEC antivirus 2009
Résolu/Fermé
A voir également:
- AUSSI UN PROBLEME AVEC antivirus 2009
- Comodo antivirus - Télécharger - Sécurité
- Panda antivirus - Télécharger - Antivirus & Antimalwares
- Desactiver antivirus windows 10 - Guide
- Bitdefender antivirus gratuit - Télécharger - Antivirus & Antimalwares
- Avast antivirus gratuit - Télécharger - Antivirus & Antimalwares
31 réponses
BONJOUR
J'AI FAIT CE QUE TU AS DEMANDé VOICI MON ARAPPORT AD REMOVER... ya t'il d'autres manip encore a realiser?
--------- Logfile of AD-Remover 1.0.8.0 by C_XX ---------
# START at: 21:06:54 | Dim 28/12/2008 | Microsoft® Windows XP™ SP2 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: SECRETE-BD2021C | USER: kerim Fradj ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
- H:\ (File System: CDFS)
# Internet Explorer v7.0.5730.13
--------- [ RUNNING PROCESSES: 28 ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ntvdm.exe
-----------------------------------
+-----------------------| Boonty/Boonty Games Elements found :
.
+-----------------------| Eorezo Elements found :
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}"
.
[30/03/2008 19:29|d--------] C:\PROGRA~1\EoRezo
[30/03/2008 19:29|d--------] C:\PROGRA~1\EoRezo\EoAdv
[30/03/2008 19:30|d--------] C:\PROGRA~1\EoRezo\EOWEAT~1
[30/03/2008 18:56|--a------] C:\PROGRA~1\EoRezo\EoAdv\eoAdv.url
[25/01/2007 08:22|--a------] C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.OLD
[30/03/2008 19:29|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\cmhost.cyp
[27/06/2007 12:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\CONFME~1.CYP
[27/06/2007 12:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\CONFME~1.OLD
[30/03/2008 19:14|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\db
[30/03/2008 19:24|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\eoStats
[30/03/2008 19:12|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1.CFG
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\host.cyp
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\user.cyp
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\db\cat.cyp
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\eoStats\eoStats.txt
[30/03/2008 19:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\EOWEAT~1.CFG
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\images
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\67_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\67_night.png
[21/08/2006 12:07|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\69_day.png
[21/08/2006 12:07|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\69_night.png
[13/07/2005 15:04|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\70_day.png
[13/07/2005 15:04|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\70_night.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\78_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\78_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\82_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\82_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\83_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\83_night.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\84_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\84_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\85_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\85_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\89_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\89_night.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\back.png
[30/10/2006 11:31|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BA24E2~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~4.PNG
[24/10/2006 09:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~3.PNG
[27/09/2006 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~1.PNG
[27/09/2006 13:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~2.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKPR~1.PNG
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\band.png
[30/06/2005 09:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BAND_S~1.PNG
[10/07/2006 11:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\close.png
[10/07/2006 11:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\CLOSEP~1.PNG
[23/10/2006 10:32|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\DAYPRE~2.PNG
[23/10/2006 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\DAYPRE~1.PNG
[25/10/2006 10:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\earth.png
[04/10/2006 10:21|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\FONDS_~1.PNG
[10/07/2006 11:50|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\help.png
[10/07/2006 11:49|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\HELPPR~1.PNG
[10/07/2006 11:24|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\minimise.png
[10/07/2006 11:23|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\MINIMI~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\next.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\NEXTPR~1.PNG
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\option.png
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\OPTION~1.PNG
[02/10/2006 17:36|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\REFLET~1.PNG
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\SMALL_~1.PNG
[06/11/2006 10:05|--ahs----] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\Thumbs.db
[30/10/2006 12:05|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\67_day.png
[30/10/2006 12:05|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\67_night.png
[02/10/2006 16:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\69_day.png
[02/10/2006 14:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\69_night.png
[06/11/2006 15:18|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\70_day.png
[06/11/2006 15:19|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\70_night.png
[02/10/2006 16:00|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\78_day.png
[02/10/2006 16:00|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\78_night.png
[02/10/2006 15:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\82_day.png
[02/10/2006 15:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\82_night.png
[02/10/2006 15:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\83_day.png
[02/10/2006 15:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\83_night.png
[02/10/2006 15:54|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\84_day.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\84_night.png
[02/10/2006 13:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\85_day.png
[02/10/2006 14:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\85_night.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\89_day.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\89_night.png
[10/01/2007 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\about.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\back.png
[06/11/2006 12:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~4.PNG
[06/11/2006 12:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BADB1B~1.PNG
[24/10/2006 09:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~3.PNG
[27/09/2006 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~1.PNG
[27/09/2006 13:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~2.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKPR~1.PNG
[10/07/2006 11:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\close.png
[10/07/2006 11:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\CLOSEP~1.PNG
[23/10/2006 10:32|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\DAYPRE~2.PNG
[23/10/2006 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\DAYPRE~1.PNG
[25/10/2006 10:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\earth.png
[04/10/2006 10:21|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\FONDS_~1.PNG
[10/07/2006 11:50|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\help.png
[10/07/2006 11:49|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\HELPPR~1.PNG
[10/07/2006 11:24|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\minimise.png
[10/07/2006 11:23|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\MINIMI~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\next.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\NEXTPR~1.PNG
[06/11/2006 12:46|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\option.png
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\OPTION~1.PNG
[02/10/2006 17:36|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\REFLET~1.PNG
[10/01/2007 10:33|--ahs----] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\Thumbs.db
[12/07/2005 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\TXT_14~1.PNG
+-----------------------| Everest Poker Elements found :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker"
.
[07/11/2008 18:46|--a------] C:\LOG_LO~2.TXT
[07/11/2008 18:46|--a------] C:\LOG_LO~1.TXT
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\casino.exe
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\CSTART~1.EXE
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\cstart.exe
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\EVERES~1.EXE
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvbase.dll
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\gvcrt.dll
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\GVGFX-~1.DLL
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvgfx.dll
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvmain.dll
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\gvmain.exe
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\GVNETW~1.DLL
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvsound.dll
[28/10/2008 16:05|d--------] C:\PROGRA~1\EVERES~1\history
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\init.ini
[07/11/2008 19:53|--a------] C:\PROGRA~1\EVERES~1\log.dat
[07/11/2008 18:47|--a------] C:\PROGRA~1\EVERES~1\settings.ini
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\toc_fr.ini
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1\var
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\fonts
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1\data\mp-lobby
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\fonts\kgp-en.ttf
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\data\mp-lobby\fr.gvt
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\data\mp-lobby\shared.gvt
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker\BACKGR~1
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\shared.gvt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\BACKGR~1\default.gvt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\bitmaps.gvt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\MP-POK~1.TXT
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\MP-POK~2.TXT
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\fr
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\country.txt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\language.txt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\ordinal.txt
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\BTN_SC~1.GVT
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\check.art
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\chips.art
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\button.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\carddeal.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\cardflip.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\CHIPCL~1.OGG
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\startup\en
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\startup\fr
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\startup\en\STARTU~1.TXT
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\fr\cstart.txt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\startup\fr\STARTU~1.TXT
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\bitmaps
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\icons
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\sounds
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\bitmaps\SPLASH~1.ART
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\icons\ep.ico
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\sounds\alert.ogg
[21/09/2008 17:38|--a------] C:\PROGRA~1\EVERES~1\history\253.txt
[21/09/2008 17:53|--a------] C:\PROGRA~1\EVERES~1\history\254.txt
[21/09/2008 18:10|--a------] C:\PROGRA~1\EVERES~1\history\255.txt
[22/09/2008 09:43|--a------] C:\PROGRA~1\EVERES~1\history\256.txt
[22/09/2008 10:28|--a------] C:\PROGRA~1\EVERES~1\history\257.txt
[22/09/2008 10:50|--a------] C:\PROGRA~1\EVERES~1\history\258.txt
[22/09/2008 12:27|--a------] C:\PROGRA~1\EVERES~1\history\259.txt
[22/09/2008 12:50|--a------] C:\PROGRA~1\EVERES~1\history\260.txt
[22/09/2008 13:09|--a------] C:\PROGRA~1\EVERES~1\history\261.txt
[22/09/2008 14:44|--a------] C:\PROGRA~1\EVERES~1\history\263.txt
[22/09/2008 15:34|--a------] C:\PROGRA~1\EVERES~1\history\264.txt
[22/09/2008 16:15|--a------] C:\PROGRA~1\EVERES~1\history\265.txt
[23/09/2008 11:27|--a------] C:\PROGRA~1\EVERES~1\history\266.txt
[23/09/2008 11:26|--a------] C:\PROGRA~1\EVERES~1\history\267.txt
[23/09/2008 12:07|--a------] C:\PROGRA~1\EVERES~1\history\268.txt
[23/09/2008 12:20|--a------] C:\PROGRA~1\EVERES~1\history\269.txt
[23/09/2008 12:43|--a------] C:\PROGRA~1\EVERES~1\history\270.txt
[23/09/2008 12:56|--a------] C:\PROGRA~1\EVERES~1\history\271.txt
[24/09/2008 19:15|--a------] C:\PROGRA~1\EVERES~1\history\272.txt
[24/09/2008 19:08|--a------] C:\PROGRA~1\EVERES~1\history\273.txt
[24/09/2008 19:23|--a------] C:\PROGRA~1\EVERES~1\history\274.txt
[24/09/2008 19:45|--a------] C:\PROGRA~1\EVERES~1\history\275.txt
[24/09/2008 20:04|--a------] C:\PROGRA~1\EVERES~1\history\276.txt
[24/09/2008 21:04|--a------] C:\PROGRA~1\EVERES~1\history\277.txt
[25/09/2008 10:52|--a------] C:\PROGRA~1\EVERES~1\history\278.txt
[25/09/2008 10:37|--a------] C:\PROGRA~1\EVERES~1\history\279.txt
[25/09/2008 11:35|--a------] C:\PROGRA~1\EVERES~1\history\280.txt
[25/09/2008 11:20|--a------] C:\PROGRA~1\EVERES~1\history\281.txt
[25/09/2008 11:54|--a------] C:\PROGRA~1\EVERES~1\history\282.txt
[25/09/2008 12:02|--a------] C:\PROGRA~1\EVERES~1\history\283.txt
[25/09/2008 12:56|--a------] C:\PROGRA~1\EVERES~1\history\284.txt
[25/09/2008 13:22|--a------] C:\PROGRA~1\EVERES~1\history\285.txt
[25/09/2008 14:14|--a------] C:\PROGRA~1\EVERES~1\history\286.txt
[25/09/2008 13:32|--a------] C:\PROGRA~1\EVERES~1\history\287.txt
[25/09/2008 14:25|--a------] C:\PROGRA~1\EVERES~1\history\288.txt
[25/09/2008 14:25|--a------] C:\PROGRA~1\EVERES~1\history\289.txt
[25/09/2008 15:18|--a------] C:\PROGRA~1\EVERES~1\history\290.txt
[25/09/2008 15:14|--a------] C:\PROGRA~1\EVERES~1\history\291.txt
[25/09/2008 16:49|--a------] C:\PROGRA~1\EVERES~1\history\292.txt
[25/09/2008 15:28|--a------] C:\PROGRA~1\EVERES~1\history\293.txt
[25/09/2008 21:56|--a------] C:\PROGRA~1\EVERES~1\history\294.txt
[25/09/2008 20:42|--a------] C:\PROGRA~1\EVERES~1\history\295.txt
[28/09/2008 15:09|--a------] C:\PROGRA~1\EVERES~1\history\296.txt
[28/09/2008 16:13|--a------] C:\PROGRA~1\EVERES~1\history\297.txt
[28/09/2008 17:17|--a------] C:\PROGRA~1\EVERES~1\history\298.txt
[29/09/2008 14:12|--a------] C:\PROGRA~1\EVERES~1\history\299.txt
[29/09/2008 14:24|--a------] C:\PROGRA~1\EVERES~1\history\300.txt
[29/09/2008 15:26|--a------] C:\PROGRA~1\EVERES~1\history\301.txt
[29/09/2008 15:33|--a------] C:\PROGRA~1\EVERES~1\history\302.txt
[29/09/2008 15:45|--a------] C:\PROGRA~1\EVERES~1\history\303.txt
[29/09/2008 16:22|--a------] C:\PROGRA~1\EVERES~1\history\304.txt
[29/09/2008 16:12|--a------] C:\PROGRA~1\EVERES~1\history\305.txt
[29/09/2008 16:38|--a------] C:\PROGRA~1\EVERES~1\history\306.txt
[29/09/2008 18:29|--a------] C:\PROGRA~1\EVERES~1\history\307.txt
[29/09/2008 18:44|--a------] C:\PROGRA~1\EVERES~1\history\308.txt
[04/10/2008 12:54|--a------] C:\PROGRA~1\EVERES~1\history\309.txt
[04/10/2008 12:52|--a------] C:\PROGRA~1\EVERES~1\history\310.txt
[04/10/2008 13:56|--a------] C:\PROGRA~1\EVERES~1\history\311.txt
[04/10/2008 17:59|--a------] C:\PROGRA~1\EVERES~1\history\312.txt
[04/10/2008 18:36|--a------] C:\PROGRA~1\EVERES~1\history\313.txt
[04/10/2008 21:36|--a------] C:\PROGRA~1\EVERES~1\history\314.txt
[04/10/2008 22:13|--a------] C:\PROGRA~1\EVERES~1\history\315.txt
[05/10/2008 17:43|--a------] C:\PROGRA~1\EVERES~1\history\316.txt
[05/10/2008 16:51|--a------] C:\PROGRA~1\EVERES~1\history\317.txt
[05/10/2008 21:38|--a------] C:\PROGRA~1\EVERES~1\history\318.txt
[06/10/2008 11:08|--a------] C:\PROGRA~1\EVERES~1\history\319.txt
[06/10/2008 11:24|--a------] C:\PROGRA~1\EVERES~1\history\320.txt
[06/10/2008 12:10|--a------] C:\PROGRA~1\EVERES~1\history\321.txt
[06/10/2008 15:13|--a------] C:\PROGRA~1\EVERES~1\history\322.txt
[08/10/2008 11:07|--a------] C:\PROGRA~1\EVERES~1\history\323.txt
[08/10/2008 10:06|--a------] C:\PROGRA~1\EVERES~1\history\324.txt
[08/10/2008 11:24|--a------] C:\PROGRA~1\EVERES~1\history\325.txt
[08/10/2008 12:01|--a------] C:\PROGRA~1\EVERES~1\history\326.txt
[08/10/2008 11:38|--a------] C:\PROGRA~1\EVERES~1\history\327.txt
[08/10/2008 12:29|--a------] C:\PROGRA~1\EVERES~1\history\328.txt
[08/10/2008 12:44|--a------] C:\PROGRA~1\EVERES~1\history\329.txt
[08/10/2008 15:16|--a------] C:\PROGRA~1\EVERES~1\history\330.txt
[08/10/2008 15:35|--a------] C:\PROGRA~1\EVERES~1\history\331.txt
[08/10/2008 16:58|--a------] C:\PROGRA~1\EVERES~1\history\332.txt
[08/10/2008 17:14|--a------] C:\PROGRA~1\EVERES~1\history\333.txt
[08/10/2008 17:36|--a------] C:\PROGRA~1\EVERES~1\history\334.txt
[08/10/2008 18:57|--a------] C:\PROGRA~1\EVERES~1\history\335.txt
[08/10/2008 18:06|--a------] C:\PROGRA~1\EVERES~1\history\336.txt
[08/10/2008 22:00|--a------] C:\PROGRA~1\EVERES~1\history\337.txt
[08/10/2008 22:16|--a------] C:\PROGRA~1\EVERES~1\history\338.txt
[09/10/2008 09:30|--a------] C:\PROGRA~1\EVERES~1\history\339.txt
[09/10/2008 09:33|--a------] C:\PROGRA~1\EVERES~1\history\340.txt
[09/10/2008 09:40|--a------] C:\PROGRA~1\EVERES~1\history\341.txt
[09/10/2008 09:45|--a------] C:\PROGRA~1\EVERES~1\history\342.txt
[09/10/2008 10:23|--a------] C:\PROGRA~1\EVERES~1\history\344.txt
[09/10/2008 10:22|--a------] C:\PROGRA~1\EVERES~1\history\345.txt
[09/10/2008 13:47|--a------] C:\PROGRA~1\EVERES~1\history\346.txt
[09/10/2008 14:19|--a------] C:\PROGRA~1\EVERES~1\history\347.txt
[09/10/2008 15:17|--a------] C:\PROGRA~1\EVERES~1\history\348.txt
[09/10/2008 16:47|--a------] C:\PROGRA~1\EVERES~1\history\349.txt
[09/10/2008 15:45|--a------] C:\PROGRA~1\EVERES~1\history\350.txt
[09/10/2008 16:34|--a------] C:\PROGRA~1\EVERES~1\history\351.txt
[09/10/2008 18:00|--a------] C:\PROGRA~1\EVERES~1\history\352.txt
[09/10/2008 17:47|--a------] C:\PROGRA~1\EVERES~1\history\353.txt
[09/10/2008 18:32|--a------] C:\PROGRA~1\EVERES~1\history\354.txt
[09/10/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\history\355.txt
[09/10/2008 18:54|--a------] C:\PROGRA~1\EVERES~1\history\356.txt
[09/10/2008 19:12|--a------] C:\PROGRA~1\EVERES~1\history\357.txt
[10/10/2008 15:19|--a------] C:\PROGRA~1\EVERES~1\history\358.txt
[10/10/2008 14:45|--a------] C:\PROGRA~1\EVERES~1\history\359.txt
[10/10/2008 15:48|--a------] C:\PROGRA~1\EVERES~1\history\360.txt
[10/10/2008 16:32|--a------] C:\PROGRA~1\EVERES~1\history\361.txt
[12/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\362.txt
[12/10/2008 20:28|--a------] C:\PROGRA~1\EVERES~1\history\363.txt
[12/10/2008 21:26|--a------] C:\PROGRA~1\EVERES~1\history\364.txt
[12/10/2008 21:55|--a------] C:\PROGRA~1\EVERES~1\history\365.txt
[13/10/2008 18:33|--a------] C:\PROGRA~1\EVERES~1\history\366.txt
[13/10/2008 22:07|--a------] C:\PROGRA~1\EVERES~1\history\367.txt
[15/10/2008 23:22|--a------] C:\PROGRA~1\EVERES~1\history\368.txt
[15/10/2008 22:54|--a------] C:\PROGRA~1\EVERES~1\history\369.txt
[15/10/2008 23:58|--a------] C:\PROGRA~1\EVERES~1\history\370.txt
[16/10/2008 22:45|--a------] C:\PROGRA~1\EVERES~1\history\371.txt
[16/10/2008 22:49|--a------] C:\PROGRA~1\EVERES~1\history\372.txt
[17/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\373.txt
[17/10/2008 22:22|--a------] C:\PROGRA~1\EVERES~1\history\374.txt
[19/10/2008 17:36|--a------] C:\PROGRA~1\EVERES~1\history\375.txt
[19/10/2008 17:04|--a------] C:\PROGRA~1\EVERES~1\history\376.txt
[19/10/2008 20:05|--a------] C:\PROGRA~1\EVERES~1\history\377.txt
[19/10/2008 20:32|--a------] C:\PROGRA~1\EVERES~1\history\378.txt
[19/10/2008 21:53|--a------] C:\PROGRA~1\EVERES~1\history\379.txt
[21/10/2008 21:33|--a------] C:\PROGRA~1\EVERES~1\history\380.txt
[21/10/2008 21:43|--a------] C:\PROGRA~1\EVERES~1\history\381.txt
[22/10/2008 19:10|--a------] C:\PROGRA~1\EVERES~1\history\382.txt
[22/10/2008 19:28|--a------] C:\PROGRA~1\EVERES~1\history\383.txt
[23/10/2008 20:27|--a------] C:\PROGRA~1\EVERES~1\history\384.txt
[23/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\385.txt
[28/10/2008 16:30|--a------] C:\PROGRA~1\EVERES~1\history\386.txt
[07/11/2008 18:48|--a------] C:\PROGRA~1\EVERES~1\var\CONTEN~1.DAT
[02/04/2008 14:47|d--------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1
[02/04/2008 14:47|--a------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1\EVERES~1.LNK
[02/04/2008 14:47|--a------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1\UNINST~1.LNK
+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements found :
.
+-----------------------| It's TV Elements found :
"HKEY_CURRENT_USER\Software\ItsLabel\ItsTV"
"HKEY_LOCAL_MACHINE\SOFTWARE\ItsLabel"
"HKEY_USERS\S-1-5-21-527237240-688789844-725345543-1005\Software\ItsLabel"
.
[30/03/2008 19:28|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel
[30/03/2008 19:28|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel\ItsTV
[26/04/2007 17:54|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel\ItsTV\itsTV.xml
+-----------------------| Sweetim Elements found :
.
+-----------------------| ADDED SCAN :
+--[HKEY_CURRENT_USER\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
+--[HKEY_LOCAL_MACHINE\..\Run]
vspdfprsrv.exe REG_SZ C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe --background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\backWeb-8876480.exe
EM_EXEC REG_SZ C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
+--[HKEY_USERS\.DEFAULT\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]
Start Page : hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]
Start Page : hxxp://go.microsoft.com/fwlink/?LinkId=69157
+---------------------------------------------------------------------------+
- "C:\AD-report-Scan-28.12.2008.log" (~27967 bytes)
# END at: 21:07:14 | 28/12/2008 - Time elapsed: 19.8 seconds
+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 392 lines ]
+---------------------------------------------------------------------------+
J'AI FAIT CE QUE TU AS DEMANDé VOICI MON ARAPPORT AD REMOVER... ya t'il d'autres manip encore a realiser?
--------- Logfile of AD-Remover 1.0.8.0 by C_XX ---------
# START at: 21:06:54 | Dim 28/12/2008 | Microsoft® Windows XP™ SP2 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: SECRETE-BD2021C | USER: kerim Fradj ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
- H:\ (File System: CDFS)
# Internet Explorer v7.0.5730.13
--------- [ RUNNING PROCESSES: 28 ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ntvdm.exe
-----------------------------------
+-----------------------| Boonty/Boonty Games Elements found :
.
+-----------------------| Eorezo Elements found :
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}"
.
[30/03/2008 19:29|d--------] C:\PROGRA~1\EoRezo
[30/03/2008 19:29|d--------] C:\PROGRA~1\EoRezo\EoAdv
[30/03/2008 19:30|d--------] C:\PROGRA~1\EoRezo\EOWEAT~1
[30/03/2008 18:56|--a------] C:\PROGRA~1\EoRezo\EoAdv\eoAdv.url
[25/01/2007 08:22|--a------] C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.OLD
[30/03/2008 19:29|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\cmhost.cyp
[27/06/2007 12:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\CONFME~1.CYP
[27/06/2007 12:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\CONFME~1.OLD
[30/03/2008 19:14|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\db
[30/03/2008 19:24|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\eoStats
[30/03/2008 19:12|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1.CFG
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\host.cyp
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\user.cyp
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\db\cat.cyp
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\eoStats\eoStats.txt
[30/03/2008 19:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\EOWEAT~1.CFG
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\images
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\67_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\67_night.png
[21/08/2006 12:07|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\69_day.png
[21/08/2006 12:07|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\69_night.png
[13/07/2005 15:04|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\70_day.png
[13/07/2005 15:04|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\70_night.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\78_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\78_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\82_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\82_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\83_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\83_night.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\84_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\84_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\85_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\85_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\89_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\89_night.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\back.png
[30/10/2006 11:31|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BA24E2~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~4.PNG
[24/10/2006 09:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~3.PNG
[27/09/2006 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~1.PNG
[27/09/2006 13:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~2.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKPR~1.PNG
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\band.png
[30/06/2005 09:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BAND_S~1.PNG
[10/07/2006 11:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\close.png
[10/07/2006 11:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\CLOSEP~1.PNG
[23/10/2006 10:32|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\DAYPRE~2.PNG
[23/10/2006 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\DAYPRE~1.PNG
[25/10/2006 10:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\earth.png
[04/10/2006 10:21|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\FONDS_~1.PNG
[10/07/2006 11:50|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\help.png
[10/07/2006 11:49|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\HELPPR~1.PNG
[10/07/2006 11:24|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\minimise.png
[10/07/2006 11:23|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\MINIMI~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\next.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\NEXTPR~1.PNG
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\option.png
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\OPTION~1.PNG
[02/10/2006 17:36|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\REFLET~1.PNG
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\SMALL_~1.PNG
[06/11/2006 10:05|--ahs----] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\Thumbs.db
[30/10/2006 12:05|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\67_day.png
[30/10/2006 12:05|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\67_night.png
[02/10/2006 16:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\69_day.png
[02/10/2006 14:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\69_night.png
[06/11/2006 15:18|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\70_day.png
[06/11/2006 15:19|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\70_night.png
[02/10/2006 16:00|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\78_day.png
[02/10/2006 16:00|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\78_night.png
[02/10/2006 15:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\82_day.png
[02/10/2006 15:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\82_night.png
[02/10/2006 15:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\83_day.png
[02/10/2006 15:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\83_night.png
[02/10/2006 15:54|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\84_day.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\84_night.png
[02/10/2006 13:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\85_day.png
[02/10/2006 14:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\85_night.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\89_day.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\89_night.png
[10/01/2007 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\about.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\back.png
[06/11/2006 12:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~4.PNG
[06/11/2006 12:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BADB1B~1.PNG
[24/10/2006 09:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~3.PNG
[27/09/2006 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~1.PNG
[27/09/2006 13:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~2.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKPR~1.PNG
[10/07/2006 11:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\close.png
[10/07/2006 11:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\CLOSEP~1.PNG
[23/10/2006 10:32|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\DAYPRE~2.PNG
[23/10/2006 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\DAYPRE~1.PNG
[25/10/2006 10:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\earth.png
[04/10/2006 10:21|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\FONDS_~1.PNG
[10/07/2006 11:50|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\help.png
[10/07/2006 11:49|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\HELPPR~1.PNG
[10/07/2006 11:24|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\minimise.png
[10/07/2006 11:23|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\MINIMI~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\next.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\NEXTPR~1.PNG
[06/11/2006 12:46|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\option.png
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\OPTION~1.PNG
[02/10/2006 17:36|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\REFLET~1.PNG
[10/01/2007 10:33|--ahs----] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\Thumbs.db
[12/07/2005 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\TXT_14~1.PNG
+-----------------------| Everest Poker Elements found :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker"
.
[07/11/2008 18:46|--a------] C:\LOG_LO~2.TXT
[07/11/2008 18:46|--a------] C:\LOG_LO~1.TXT
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\casino.exe
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\CSTART~1.EXE
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\cstart.exe
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\EVERES~1.EXE
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvbase.dll
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\gvcrt.dll
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\GVGFX-~1.DLL
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvgfx.dll
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvmain.dll
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\gvmain.exe
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\GVNETW~1.DLL
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvsound.dll
[28/10/2008 16:05|d--------] C:\PROGRA~1\EVERES~1\history
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\init.ini
[07/11/2008 19:53|--a------] C:\PROGRA~1\EVERES~1\log.dat
[07/11/2008 18:47|--a------] C:\PROGRA~1\EVERES~1\settings.ini
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\toc_fr.ini
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1\var
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\fonts
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1\data\mp-lobby
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\fonts\kgp-en.ttf
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\data\mp-lobby\fr.gvt
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\data\mp-lobby\shared.gvt
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker\BACKGR~1
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\shared.gvt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\BACKGR~1\default.gvt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\bitmaps.gvt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\MP-POK~1.TXT
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\MP-POK~2.TXT
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\fr
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\country.txt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\language.txt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\ordinal.txt
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\BTN_SC~1.GVT
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\check.art
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\chips.art
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\button.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\carddeal.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\cardflip.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\CHIPCL~1.OGG
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\startup\en
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\startup\fr
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\startup\en\STARTU~1.TXT
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\fr\cstart.txt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\startup\fr\STARTU~1.TXT
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\bitmaps
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\icons
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\sounds
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\bitmaps\SPLASH~1.ART
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\icons\ep.ico
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\sounds\alert.ogg
[21/09/2008 17:38|--a------] C:\PROGRA~1\EVERES~1\history\253.txt
[21/09/2008 17:53|--a------] C:\PROGRA~1\EVERES~1\history\254.txt
[21/09/2008 18:10|--a------] C:\PROGRA~1\EVERES~1\history\255.txt
[22/09/2008 09:43|--a------] C:\PROGRA~1\EVERES~1\history\256.txt
[22/09/2008 10:28|--a------] C:\PROGRA~1\EVERES~1\history\257.txt
[22/09/2008 10:50|--a------] C:\PROGRA~1\EVERES~1\history\258.txt
[22/09/2008 12:27|--a------] C:\PROGRA~1\EVERES~1\history\259.txt
[22/09/2008 12:50|--a------] C:\PROGRA~1\EVERES~1\history\260.txt
[22/09/2008 13:09|--a------] C:\PROGRA~1\EVERES~1\history\261.txt
[22/09/2008 14:44|--a------] C:\PROGRA~1\EVERES~1\history\263.txt
[22/09/2008 15:34|--a------] C:\PROGRA~1\EVERES~1\history\264.txt
[22/09/2008 16:15|--a------] C:\PROGRA~1\EVERES~1\history\265.txt
[23/09/2008 11:27|--a------] C:\PROGRA~1\EVERES~1\history\266.txt
[23/09/2008 11:26|--a------] C:\PROGRA~1\EVERES~1\history\267.txt
[23/09/2008 12:07|--a------] C:\PROGRA~1\EVERES~1\history\268.txt
[23/09/2008 12:20|--a------] C:\PROGRA~1\EVERES~1\history\269.txt
[23/09/2008 12:43|--a------] C:\PROGRA~1\EVERES~1\history\270.txt
[23/09/2008 12:56|--a------] C:\PROGRA~1\EVERES~1\history\271.txt
[24/09/2008 19:15|--a------] C:\PROGRA~1\EVERES~1\history\272.txt
[24/09/2008 19:08|--a------] C:\PROGRA~1\EVERES~1\history\273.txt
[24/09/2008 19:23|--a------] C:\PROGRA~1\EVERES~1\history\274.txt
[24/09/2008 19:45|--a------] C:\PROGRA~1\EVERES~1\history\275.txt
[24/09/2008 20:04|--a------] C:\PROGRA~1\EVERES~1\history\276.txt
[24/09/2008 21:04|--a------] C:\PROGRA~1\EVERES~1\history\277.txt
[25/09/2008 10:52|--a------] C:\PROGRA~1\EVERES~1\history\278.txt
[25/09/2008 10:37|--a------] C:\PROGRA~1\EVERES~1\history\279.txt
[25/09/2008 11:35|--a------] C:\PROGRA~1\EVERES~1\history\280.txt
[25/09/2008 11:20|--a------] C:\PROGRA~1\EVERES~1\history\281.txt
[25/09/2008 11:54|--a------] C:\PROGRA~1\EVERES~1\history\282.txt
[25/09/2008 12:02|--a------] C:\PROGRA~1\EVERES~1\history\283.txt
[25/09/2008 12:56|--a------] C:\PROGRA~1\EVERES~1\history\284.txt
[25/09/2008 13:22|--a------] C:\PROGRA~1\EVERES~1\history\285.txt
[25/09/2008 14:14|--a------] C:\PROGRA~1\EVERES~1\history\286.txt
[25/09/2008 13:32|--a------] C:\PROGRA~1\EVERES~1\history\287.txt
[25/09/2008 14:25|--a------] C:\PROGRA~1\EVERES~1\history\288.txt
[25/09/2008 14:25|--a------] C:\PROGRA~1\EVERES~1\history\289.txt
[25/09/2008 15:18|--a------] C:\PROGRA~1\EVERES~1\history\290.txt
[25/09/2008 15:14|--a------] C:\PROGRA~1\EVERES~1\history\291.txt
[25/09/2008 16:49|--a------] C:\PROGRA~1\EVERES~1\history\292.txt
[25/09/2008 15:28|--a------] C:\PROGRA~1\EVERES~1\history\293.txt
[25/09/2008 21:56|--a------] C:\PROGRA~1\EVERES~1\history\294.txt
[25/09/2008 20:42|--a------] C:\PROGRA~1\EVERES~1\history\295.txt
[28/09/2008 15:09|--a------] C:\PROGRA~1\EVERES~1\history\296.txt
[28/09/2008 16:13|--a------] C:\PROGRA~1\EVERES~1\history\297.txt
[28/09/2008 17:17|--a------] C:\PROGRA~1\EVERES~1\history\298.txt
[29/09/2008 14:12|--a------] C:\PROGRA~1\EVERES~1\history\299.txt
[29/09/2008 14:24|--a------] C:\PROGRA~1\EVERES~1\history\300.txt
[29/09/2008 15:26|--a------] C:\PROGRA~1\EVERES~1\history\301.txt
[29/09/2008 15:33|--a------] C:\PROGRA~1\EVERES~1\history\302.txt
[29/09/2008 15:45|--a------] C:\PROGRA~1\EVERES~1\history\303.txt
[29/09/2008 16:22|--a------] C:\PROGRA~1\EVERES~1\history\304.txt
[29/09/2008 16:12|--a------] C:\PROGRA~1\EVERES~1\history\305.txt
[29/09/2008 16:38|--a------] C:\PROGRA~1\EVERES~1\history\306.txt
[29/09/2008 18:29|--a------] C:\PROGRA~1\EVERES~1\history\307.txt
[29/09/2008 18:44|--a------] C:\PROGRA~1\EVERES~1\history\308.txt
[04/10/2008 12:54|--a------] C:\PROGRA~1\EVERES~1\history\309.txt
[04/10/2008 12:52|--a------] C:\PROGRA~1\EVERES~1\history\310.txt
[04/10/2008 13:56|--a------] C:\PROGRA~1\EVERES~1\history\311.txt
[04/10/2008 17:59|--a------] C:\PROGRA~1\EVERES~1\history\312.txt
[04/10/2008 18:36|--a------] C:\PROGRA~1\EVERES~1\history\313.txt
[04/10/2008 21:36|--a------] C:\PROGRA~1\EVERES~1\history\314.txt
[04/10/2008 22:13|--a------] C:\PROGRA~1\EVERES~1\history\315.txt
[05/10/2008 17:43|--a------] C:\PROGRA~1\EVERES~1\history\316.txt
[05/10/2008 16:51|--a------] C:\PROGRA~1\EVERES~1\history\317.txt
[05/10/2008 21:38|--a------] C:\PROGRA~1\EVERES~1\history\318.txt
[06/10/2008 11:08|--a------] C:\PROGRA~1\EVERES~1\history\319.txt
[06/10/2008 11:24|--a------] C:\PROGRA~1\EVERES~1\history\320.txt
[06/10/2008 12:10|--a------] C:\PROGRA~1\EVERES~1\history\321.txt
[06/10/2008 15:13|--a------] C:\PROGRA~1\EVERES~1\history\322.txt
[08/10/2008 11:07|--a------] C:\PROGRA~1\EVERES~1\history\323.txt
[08/10/2008 10:06|--a------] C:\PROGRA~1\EVERES~1\history\324.txt
[08/10/2008 11:24|--a------] C:\PROGRA~1\EVERES~1\history\325.txt
[08/10/2008 12:01|--a------] C:\PROGRA~1\EVERES~1\history\326.txt
[08/10/2008 11:38|--a------] C:\PROGRA~1\EVERES~1\history\327.txt
[08/10/2008 12:29|--a------] C:\PROGRA~1\EVERES~1\history\328.txt
[08/10/2008 12:44|--a------] C:\PROGRA~1\EVERES~1\history\329.txt
[08/10/2008 15:16|--a------] C:\PROGRA~1\EVERES~1\history\330.txt
[08/10/2008 15:35|--a------] C:\PROGRA~1\EVERES~1\history\331.txt
[08/10/2008 16:58|--a------] C:\PROGRA~1\EVERES~1\history\332.txt
[08/10/2008 17:14|--a------] C:\PROGRA~1\EVERES~1\history\333.txt
[08/10/2008 17:36|--a------] C:\PROGRA~1\EVERES~1\history\334.txt
[08/10/2008 18:57|--a------] C:\PROGRA~1\EVERES~1\history\335.txt
[08/10/2008 18:06|--a------] C:\PROGRA~1\EVERES~1\history\336.txt
[08/10/2008 22:00|--a------] C:\PROGRA~1\EVERES~1\history\337.txt
[08/10/2008 22:16|--a------] C:\PROGRA~1\EVERES~1\history\338.txt
[09/10/2008 09:30|--a------] C:\PROGRA~1\EVERES~1\history\339.txt
[09/10/2008 09:33|--a------] C:\PROGRA~1\EVERES~1\history\340.txt
[09/10/2008 09:40|--a------] C:\PROGRA~1\EVERES~1\history\341.txt
[09/10/2008 09:45|--a------] C:\PROGRA~1\EVERES~1\history\342.txt
[09/10/2008 10:23|--a------] C:\PROGRA~1\EVERES~1\history\344.txt
[09/10/2008 10:22|--a------] C:\PROGRA~1\EVERES~1\history\345.txt
[09/10/2008 13:47|--a------] C:\PROGRA~1\EVERES~1\history\346.txt
[09/10/2008 14:19|--a------] C:\PROGRA~1\EVERES~1\history\347.txt
[09/10/2008 15:17|--a------] C:\PROGRA~1\EVERES~1\history\348.txt
[09/10/2008 16:47|--a------] C:\PROGRA~1\EVERES~1\history\349.txt
[09/10/2008 15:45|--a------] C:\PROGRA~1\EVERES~1\history\350.txt
[09/10/2008 16:34|--a------] C:\PROGRA~1\EVERES~1\history\351.txt
[09/10/2008 18:00|--a------] C:\PROGRA~1\EVERES~1\history\352.txt
[09/10/2008 17:47|--a------] C:\PROGRA~1\EVERES~1\history\353.txt
[09/10/2008 18:32|--a------] C:\PROGRA~1\EVERES~1\history\354.txt
[09/10/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\history\355.txt
[09/10/2008 18:54|--a------] C:\PROGRA~1\EVERES~1\history\356.txt
[09/10/2008 19:12|--a------] C:\PROGRA~1\EVERES~1\history\357.txt
[10/10/2008 15:19|--a------] C:\PROGRA~1\EVERES~1\history\358.txt
[10/10/2008 14:45|--a------] C:\PROGRA~1\EVERES~1\history\359.txt
[10/10/2008 15:48|--a------] C:\PROGRA~1\EVERES~1\history\360.txt
[10/10/2008 16:32|--a------] C:\PROGRA~1\EVERES~1\history\361.txt
[12/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\362.txt
[12/10/2008 20:28|--a------] C:\PROGRA~1\EVERES~1\history\363.txt
[12/10/2008 21:26|--a------] C:\PROGRA~1\EVERES~1\history\364.txt
[12/10/2008 21:55|--a------] C:\PROGRA~1\EVERES~1\history\365.txt
[13/10/2008 18:33|--a------] C:\PROGRA~1\EVERES~1\history\366.txt
[13/10/2008 22:07|--a------] C:\PROGRA~1\EVERES~1\history\367.txt
[15/10/2008 23:22|--a------] C:\PROGRA~1\EVERES~1\history\368.txt
[15/10/2008 22:54|--a------] C:\PROGRA~1\EVERES~1\history\369.txt
[15/10/2008 23:58|--a------] C:\PROGRA~1\EVERES~1\history\370.txt
[16/10/2008 22:45|--a------] C:\PROGRA~1\EVERES~1\history\371.txt
[16/10/2008 22:49|--a------] C:\PROGRA~1\EVERES~1\history\372.txt
[17/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\373.txt
[17/10/2008 22:22|--a------] C:\PROGRA~1\EVERES~1\history\374.txt
[19/10/2008 17:36|--a------] C:\PROGRA~1\EVERES~1\history\375.txt
[19/10/2008 17:04|--a------] C:\PROGRA~1\EVERES~1\history\376.txt
[19/10/2008 20:05|--a------] C:\PROGRA~1\EVERES~1\history\377.txt
[19/10/2008 20:32|--a------] C:\PROGRA~1\EVERES~1\history\378.txt
[19/10/2008 21:53|--a------] C:\PROGRA~1\EVERES~1\history\379.txt
[21/10/2008 21:33|--a------] C:\PROGRA~1\EVERES~1\history\380.txt
[21/10/2008 21:43|--a------] C:\PROGRA~1\EVERES~1\history\381.txt
[22/10/2008 19:10|--a------] C:\PROGRA~1\EVERES~1\history\382.txt
[22/10/2008 19:28|--a------] C:\PROGRA~1\EVERES~1\history\383.txt
[23/10/2008 20:27|--a------] C:\PROGRA~1\EVERES~1\history\384.txt
[23/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\385.txt
[28/10/2008 16:30|--a------] C:\PROGRA~1\EVERES~1\history\386.txt
[07/11/2008 18:48|--a------] C:\PROGRA~1\EVERES~1\var\CONTEN~1.DAT
[02/04/2008 14:47|d--------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1
[02/04/2008 14:47|--a------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1\EVERES~1.LNK
[02/04/2008 14:47|--a------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1\UNINST~1.LNK
+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements found :
.
+-----------------------| It's TV Elements found :
"HKEY_CURRENT_USER\Software\ItsLabel\ItsTV"
"HKEY_LOCAL_MACHINE\SOFTWARE\ItsLabel"
"HKEY_USERS\S-1-5-21-527237240-688789844-725345543-1005\Software\ItsLabel"
.
[30/03/2008 19:28|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel
[30/03/2008 19:28|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel\ItsTV
[26/04/2007 17:54|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel\ItsTV\itsTV.xml
+-----------------------| Sweetim Elements found :
.
+-----------------------| ADDED SCAN :
+--[HKEY_CURRENT_USER\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
+--[HKEY_LOCAL_MACHINE\..\Run]
vspdfprsrv.exe REG_SZ C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe --background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\backWeb-8876480.exe
EM_EXEC REG_SZ C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
+--[HKEY_USERS\.DEFAULT\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]
Start Page : hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]
Start Page : hxxp://go.microsoft.com/fwlink/?LinkId=69157
+---------------------------------------------------------------------------+
- "C:\AD-report-Scan-28.12.2008.log" (~27967 bytes)
# END at: 21:07:14 | 28/12/2008 - Time elapsed: 19.8 seconds
+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 392 lines ]
+---------------------------------------------------------------------------+
BONJOUR
J'AI FAIT CE QUE TU AS DEMANDé VOICI MON ARAPPORT AD REMOVER... ya t'il d'autres manip encore a realiser?
--------- Logfile of AD-Remover 1.0.8.0 by C_XX ---------
# START at: 21:06:54 | Dim 28/12/2008 | Microsoft® Windows XP™ SP2 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: SECRETE-BD2021C | USER: kerim Fradj ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
- H:\ (File System: CDFS)
# Internet Explorer v7.0.5730.13
--------- [ RUNNING PROCESSES: 28 ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ntvdm.exe
-----------------------------------
+-----------------------| Boonty/Boonty Games Elements found :
.
+-----------------------| Eorezo Elements found :
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}"
.
[30/03/2008 19:29|d--------] C:\PROGRA~1\EoRezo
[30/03/2008 19:29|d--------] C:\PROGRA~1\EoRezo\EoAdv
[30/03/2008 19:30|d--------] C:\PROGRA~1\EoRezo\EOWEAT~1
[30/03/2008 18:56|--a------] C:\PROGRA~1\EoRezo\EoAdv\eoAdv.url
[25/01/2007 08:22|--a------] C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.OLD
[30/03/2008 19:29|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\cmhost.cyp
[27/06/2007 12:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\CONFME~1.CYP
[27/06/2007 12:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\CONFME~1.OLD
[30/03/2008 19:14|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\db
[30/03/2008 19:24|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\eoStats
[30/03/2008 19:12|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1.CFG
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\host.cyp
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\user.cyp
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\db\cat.cyp
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\eoStats\eoStats.txt
[30/03/2008 19:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\EOWEAT~1.CFG
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\images
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\67_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\67_night.png
[21/08/2006 12:07|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\69_day.png
[21/08/2006 12:07|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\69_night.png
[13/07/2005 15:04|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\70_day.png
[13/07/2005 15:04|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\70_night.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\78_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\78_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\82_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\82_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\83_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\83_night.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\84_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\84_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\85_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\85_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\89_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\89_night.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\back.png
[30/10/2006 11:31|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BA24E2~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~4.PNG
[24/10/2006 09:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~3.PNG
[27/09/2006 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~1.PNG
[27/09/2006 13:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~2.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKPR~1.PNG
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\band.png
[30/06/2005 09:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BAND_S~1.PNG
[10/07/2006 11:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\close.png
[10/07/2006 11:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\CLOSEP~1.PNG
[23/10/2006 10:32|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\DAYPRE~2.PNG
[23/10/2006 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\DAYPRE~1.PNG
[25/10/2006 10:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\earth.png
[04/10/2006 10:21|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\FONDS_~1.PNG
[10/07/2006 11:50|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\help.png
[10/07/2006 11:49|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\HELPPR~1.PNG
[10/07/2006 11:24|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\minimise.png
[10/07/2006 11:23|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\MINIMI~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\next.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\NEXTPR~1.PNG
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\option.png
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\OPTION~1.PNG
[02/10/2006 17:36|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\REFLET~1.PNG
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\SMALL_~1.PNG
[06/11/2006 10:05|--ahs----] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\Thumbs.db
[30/10/2006 12:05|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\67_day.png
[30/10/2006 12:05|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\67_night.png
[02/10/2006 16:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\69_day.png
[02/10/2006 14:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\69_night.png
[06/11/2006 15:18|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\70_day.png
[06/11/2006 15:19|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\70_night.png
[02/10/2006 16:00|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\78_day.png
[02/10/2006 16:00|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\78_night.png
[02/10/2006 15:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\82_day.png
[02/10/2006 15:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\82_night.png
[02/10/2006 15:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\83_day.png
[02/10/2006 15:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\83_night.png
[02/10/2006 15:54|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\84_day.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\84_night.png
[02/10/2006 13:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\85_day.png
[02/10/2006 14:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\85_night.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\89_day.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\89_night.png
[10/01/2007 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\about.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\back.png
[06/11/2006 12:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~4.PNG
[06/11/2006 12:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BADB1B~1.PNG
[24/10/2006 09:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~3.PNG
[27/09/2006 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~1.PNG
[27/09/2006 13:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~2.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKPR~1.PNG
[10/07/2006 11:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\close.png
[10/07/2006 11:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\CLOSEP~1.PNG
[23/10/2006 10:32|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\DAYPRE~2.PNG
[23/10/2006 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\DAYPRE~1.PNG
[25/10/2006 10:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\earth.png
[04/10/2006 10:21|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\FONDS_~1.PNG
[10/07/2006 11:50|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\help.png
[10/07/2006 11:49|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\HELPPR~1.PNG
[10/07/2006 11:24|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\minimise.png
[10/07/2006 11:23|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\MINIMI~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\next.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\NEXTPR~1.PNG
[06/11/2006 12:46|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\option.png
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\OPTION~1.PNG
[02/10/2006 17:36|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\REFLET~1.PNG
[10/01/2007 10:33|--ahs----] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\Thumbs.db
[12/07/2005 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\TXT_14~1.PNG
+-----------------------| Everest Poker Elements found :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker"
.
[07/11/2008 18:46|--a------] C:\LOG_LO~2.TXT
[07/11/2008 18:46|--a------] C:\LOG_LO~1.TXT
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\casino.exe
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\CSTART~1.EXE
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\cstart.exe
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\EVERES~1.EXE
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvbase.dll
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\gvcrt.dll
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\GVGFX-~1.DLL
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvgfx.dll
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvmain.dll
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\gvmain.exe
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\GVNETW~1.DLL
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvsound.dll
[28/10/2008 16:05|d--------] C:\PROGRA~1\EVERES~1\history
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\init.ini
[07/11/2008 19:53|--a------] C:\PROGRA~1\EVERES~1\log.dat
[07/11/2008 18:47|--a------] C:\PROGRA~1\EVERES~1\settings.ini
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\toc_fr.ini
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1\var
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\fonts
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1\data\mp-lobby
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\fonts\kgp-en.ttf
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\data\mp-lobby\fr.gvt
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\data\mp-lobby\shared.gvt
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker\BACKGR~1
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\shared.gvt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\BACKGR~1\default.gvt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\bitmaps.gvt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\MP-POK~1.TXT
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\MP-POK~2.TXT
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\fr
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\country.txt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\language.txt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\ordinal.txt
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\BTN_SC~1.GVT
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\check.art
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\chips.art
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\button.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\carddeal.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\cardflip.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\CHIPCL~1.OGG
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\startup\en
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\startup\fr
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\startup\en\STARTU~1.TXT
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\fr\cstart.txt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\startup\fr\STARTU~1.TXT
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\bitmaps
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\icons
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\sounds
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\bitmaps\SPLASH~1.ART
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\icons\ep.ico
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\sounds\alert.ogg
[21/09/2008 17:38|--a------] C:\PROGRA~1\EVERES~1\history\253.txt
[21/09/2008 17:53|--a------] C:\PROGRA~1\EVERES~1\history\254.txt
[21/09/2008 18:10|--a------] C:\PROGRA~1\EVERES~1\history\255.txt
[22/09/2008 09:43|--a------] C:\PROGRA~1\EVERES~1\history\256.txt
[22/09/2008 10:28|--a------] C:\PROGRA~1\EVERES~1\history\257.txt
[22/09/2008 10:50|--a------] C:\PROGRA~1\EVERES~1\history\258.txt
[22/09/2008 12:27|--a------] C:\PROGRA~1\EVERES~1\history\259.txt
[22/09/2008 12:50|--a------] C:\PROGRA~1\EVERES~1\history\260.txt
[22/09/2008 13:09|--a------] C:\PROGRA~1\EVERES~1\history\261.txt
[22/09/2008 14:44|--a------] C:\PROGRA~1\EVERES~1\history\263.txt
[22/09/2008 15:34|--a------] C:\PROGRA~1\EVERES~1\history\264.txt
[22/09/2008 16:15|--a------] C:\PROGRA~1\EVERES~1\history\265.txt
[23/09/2008 11:27|--a------] C:\PROGRA~1\EVERES~1\history\266.txt
[23/09/2008 11:26|--a------] C:\PROGRA~1\EVERES~1\history\267.txt
[23/09/2008 12:07|--a------] C:\PROGRA~1\EVERES~1\history\268.txt
[23/09/2008 12:20|--a------] C:\PROGRA~1\EVERES~1\history\269.txt
[23/09/2008 12:43|--a------] C:\PROGRA~1\EVERES~1\history\270.txt
[23/09/2008 12:56|--a------] C:\PROGRA~1\EVERES~1\history\271.txt
[24/09/2008 19:15|--a------] C:\PROGRA~1\EVERES~1\history\272.txt
[24/09/2008 19:08|--a------] C:\PROGRA~1\EVERES~1\history\273.txt
[24/09/2008 19:23|--a------] C:\PROGRA~1\EVERES~1\history\274.txt
[24/09/2008 19:45|--a------] C:\PROGRA~1\EVERES~1\history\275.txt
[24/09/2008 20:04|--a------] C:\PROGRA~1\EVERES~1\history\276.txt
[24/09/2008 21:04|--a------] C:\PROGRA~1\EVERES~1\history\277.txt
[25/09/2008 10:52|--a------] C:\PROGRA~1\EVERES~1\history\278.txt
[25/09/2008 10:37|--a------] C:\PROGRA~1\EVERES~1\history\279.txt
[25/09/2008 11:35|--a------] C:\PROGRA~1\EVERES~1\history\280.txt
[25/09/2008 11:20|--a------] C:\PROGRA~1\EVERES~1\history\281.txt
[25/09/2008 11:54|--a------] C:\PROGRA~1\EVERES~1\history\282.txt
[25/09/2008 12:02|--a------] C:\PROGRA~1\EVERES~1\history\283.txt
[25/09/2008 12:56|--a------] C:\PROGRA~1\EVERES~1\history\284.txt
[25/09/2008 13:22|--a------] C:\PROGRA~1\EVERES~1\history\285.txt
[25/09/2008 14:14|--a------] C:\PROGRA~1\EVERES~1\history\286.txt
[25/09/2008 13:32|--a------] C:\PROGRA~1\EVERES~1\history\287.txt
[25/09/2008 14:25|--a------] C:\PROGRA~1\EVERES~1\history\288.txt
[25/09/2008 14:25|--a------] C:\PROGRA~1\EVERES~1\history\289.txt
[25/09/2008 15:18|--a------] C:\PROGRA~1\EVERES~1\history\290.txt
[25/09/2008 15:14|--a------] C:\PROGRA~1\EVERES~1\history\291.txt
[25/09/2008 16:49|--a------] C:\PROGRA~1\EVERES~1\history\292.txt
[25/09/2008 15:28|--a------] C:\PROGRA~1\EVERES~1\history\293.txt
[25/09/2008 21:56|--a------] C:\PROGRA~1\EVERES~1\history\294.txt
[25/09/2008 20:42|--a------] C:\PROGRA~1\EVERES~1\history\295.txt
[28/09/2008 15:09|--a------] C:\PROGRA~1\EVERES~1\history\296.txt
[28/09/2008 16:13|--a------] C:\PROGRA~1\EVERES~1\history\297.txt
[28/09/2008 17:17|--a------] C:\PROGRA~1\EVERES~1\history\298.txt
[29/09/2008 14:12|--a------] C:\PROGRA~1\EVERES~1\history\299.txt
[29/09/2008 14:24|--a------] C:\PROGRA~1\EVERES~1\history\300.txt
[29/09/2008 15:26|--a------] C:\PROGRA~1\EVERES~1\history\301.txt
[29/09/2008 15:33|--a------] C:\PROGRA~1\EVERES~1\history\302.txt
[29/09/2008 15:45|--a------] C:\PROGRA~1\EVERES~1\history\303.txt
[29/09/2008 16:22|--a------] C:\PROGRA~1\EVERES~1\history\304.txt
[29/09/2008 16:12|--a------] C:\PROGRA~1\EVERES~1\history\305.txt
[29/09/2008 16:38|--a------] C:\PROGRA~1\EVERES~1\history\306.txt
[29/09/2008 18:29|--a------] C:\PROGRA~1\EVERES~1\history\307.txt
[29/09/2008 18:44|--a------] C:\PROGRA~1\EVERES~1\history\308.txt
[04/10/2008 12:54|--a------] C:\PROGRA~1\EVERES~1\history\309.txt
[04/10/2008 12:52|--a------] C:\PROGRA~1\EVERES~1\history\310.txt
[04/10/2008 13:56|--a------] C:\PROGRA~1\EVERES~1\history\311.txt
[04/10/2008 17:59|--a------] C:\PROGRA~1\EVERES~1\history\312.txt
[04/10/2008 18:36|--a------] C:\PROGRA~1\EVERES~1\history\313.txt
[04/10/2008 21:36|--a------] C:\PROGRA~1\EVERES~1\history\314.txt
[04/10/2008 22:13|--a------] C:\PROGRA~1\EVERES~1\history\315.txt
[05/10/2008 17:43|--a------] C:\PROGRA~1\EVERES~1\history\316.txt
[05/10/2008 16:51|--a------] C:\PROGRA~1\EVERES~1\history\317.txt
[05/10/2008 21:38|--a------] C:\PROGRA~1\EVERES~1\history\318.txt
[06/10/2008 11:08|--a------] C:\PROGRA~1\EVERES~1\history\319.txt
[06/10/2008 11:24|--a------] C:\PROGRA~1\EVERES~1\history\320.txt
[06/10/2008 12:10|--a------] C:\PROGRA~1\EVERES~1\history\321.txt
[06/10/2008 15:13|--a------] C:\PROGRA~1\EVERES~1\history\322.txt
[08/10/2008 11:07|--a------] C:\PROGRA~1\EVERES~1\history\323.txt
[08/10/2008 10:06|--a------] C:\PROGRA~1\EVERES~1\history\324.txt
[08/10/2008 11:24|--a------] C:\PROGRA~1\EVERES~1\history\325.txt
[08/10/2008 12:01|--a------] C:\PROGRA~1\EVERES~1\history\326.txt
[08/10/2008 11:38|--a------] C:\PROGRA~1\EVERES~1\history\327.txt
[08/10/2008 12:29|--a------] C:\PROGRA~1\EVERES~1\history\328.txt
[08/10/2008 12:44|--a------] C:\PROGRA~1\EVERES~1\history\329.txt
[08/10/2008 15:16|--a------] C:\PROGRA~1\EVERES~1\history\330.txt
[08/10/2008 15:35|--a------] C:\PROGRA~1\EVERES~1\history\331.txt
[08/10/2008 16:58|--a------] C:\PROGRA~1\EVERES~1\history\332.txt
[08/10/2008 17:14|--a------] C:\PROGRA~1\EVERES~1\history\333.txt
[08/10/2008 17:36|--a------] C:\PROGRA~1\EVERES~1\history\334.txt
[08/10/2008 18:57|--a------] C:\PROGRA~1\EVERES~1\history\335.txt
[08/10/2008 18:06|--a------] C:\PROGRA~1\EVERES~1\history\336.txt
[08/10/2008 22:00|--a------] C:\PROGRA~1\EVERES~1\history\337.txt
[08/10/2008 22:16|--a------] C:\PROGRA~1\EVERES~1\history\338.txt
[09/10/2008 09:30|--a------] C:\PROGRA~1\EVERES~1\history\339.txt
[09/10/2008 09:33|--a------] C:\PROGRA~1\EVERES~1\history\340.txt
[09/10/2008 09:40|--a------] C:\PROGRA~1\EVERES~1\history\341.txt
[09/10/2008 09:45|--a------] C:\PROGRA~1\EVERES~1\history\342.txt
[09/10/2008 10:23|--a------] C:\PROGRA~1\EVERES~1\history\344.txt
[09/10/2008 10:22|--a------] C:\PROGRA~1\EVERES~1\history\345.txt
[09/10/2008 13:47|--a------] C:\PROGRA~1\EVERES~1\history\346.txt
[09/10/2008 14:19|--a------] C:\PROGRA~1\EVERES~1\history\347.txt
[09/10/2008 15:17|--a------] C:\PROGRA~1\EVERES~1\history\348.txt
[09/10/2008 16:47|--a------] C:\PROGRA~1\EVERES~1\history\349.txt
[09/10/2008 15:45|--a------] C:\PROGRA~1\EVERES~1\history\350.txt
[09/10/2008 16:34|--a------] C:\PROGRA~1\EVERES~1\history\351.txt
[09/10/2008 18:00|--a------] C:\PROGRA~1\EVERES~1\history\352.txt
[09/10/2008 17:47|--a------] C:\PROGRA~1\EVERES~1\history\353.txt
[09/10/2008 18:32|--a------] C:\PROGRA~1\EVERES~1\history\354.txt
[09/10/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\history\355.txt
[09/10/2008 18:54|--a------] C:\PROGRA~1\EVERES~1\history\356.txt
[09/10/2008 19:12|--a------] C:\PROGRA~1\EVERES~1\history\357.txt
[10/10/2008 15:19|--a------] C:\PROGRA~1\EVERES~1\history\358.txt
[10/10/2008 14:45|--a------] C:\PROGRA~1\EVERES~1\history\359.txt
[10/10/2008 15:48|--a------] C:\PROGRA~1\EVERES~1\history\360.txt
[10/10/2008 16:32|--a------] C:\PROGRA~1\EVERES~1\history\361.txt
[12/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\362.txt
[12/10/2008 20:28|--a------] C:\PROGRA~1\EVERES~1\history\363.txt
[12/10/2008 21:26|--a------] C:\PROGRA~1\EVERES~1\history\364.txt
[12/10/2008 21:55|--a------] C:\PROGRA~1\EVERES~1\history\365.txt
[13/10/2008 18:33|--a------] C:\PROGRA~1\EVERES~1\history\366.txt
[13/10/2008 22:07|--a------] C:\PROGRA~1\EVERES~1\history\367.txt
[15/10/2008 23:22|--a------] C:\PROGRA~1\EVERES~1\history\368.txt
[15/10/2008 22:54|--a------] C:\PROGRA~1\EVERES~1\history\369.txt
[15/10/2008 23:58|--a------] C:\PROGRA~1\EVERES~1\history\370.txt
[16/10/2008 22:45|--a------] C:\PROGRA~1\EVERES~1\history\371.txt
[16/10/2008 22:49|--a------] C:\PROGRA~1\EVERES~1\history\372.txt
[17/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\373.txt
[17/10/2008 22:22|--a------] C:\PROGRA~1\EVERES~1\history\374.txt
[19/10/2008 17:36|--a------] C:\PROGRA~1\EVERES~1\history\375.txt
[19/10/2008 17:04|--a------] C:\PROGRA~1\EVERES~1\history\376.txt
[19/10/2008 20:05|--a------] C:\PROGRA~1\EVERES~1\history\377.txt
[19/10/2008 20:32|--a------] C:\PROGRA~1\EVERES~1\history\378.txt
[19/10/2008 21:53|--a------] C:\PROGRA~1\EVERES~1\history\379.txt
[21/10/2008 21:33|--a------] C:\PROGRA~1\EVERES~1\history\380.txt
[21/10/2008 21:43|--a------] C:\PROGRA~1\EVERES~1\history\381.txt
[22/10/2008 19:10|--a------] C:\PROGRA~1\EVERES~1\history\382.txt
[22/10/2008 19:28|--a------] C:\PROGRA~1\EVERES~1\history\383.txt
[23/10/2008 20:27|--a------] C:\PROGRA~1\EVERES~1\history\384.txt
[23/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\385.txt
[28/10/2008 16:30|--a------] C:\PROGRA~1\EVERES~1\history\386.txt
[07/11/2008 18:48|--a------] C:\PROGRA~1\EVERES~1\var\CONTEN~1.DAT
[02/04/2008 14:47|d--------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1
[02/04/2008 14:47|--a------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1\EVERES~1.LNK
[02/04/2008 14:47|--a------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1\UNINST~1.LNK
+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements found :
.
+-----------------------| It's TV Elements found :
"HKEY_CURRENT_USER\Software\ItsLabel\ItsTV"
"HKEY_LOCAL_MACHINE\SOFTWARE\ItsLabel"
"HKEY_USERS\S-1-5-21-527237240-688789844-725345543-1005\Software\ItsLabel"
.
[30/03/2008 19:28|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel
[30/03/2008 19:28|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel\ItsTV
[26/04/2007 17:54|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel\ItsTV\itsTV.xml
+-----------------------| Sweetim Elements found :
.
+-----------------------| ADDED SCAN :
+--[HKEY_CURRENT_USER\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
+--[HKEY_LOCAL_MACHINE\..\Run]
vspdfprsrv.exe REG_SZ C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe --background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\backWeb-8876480.exe
EM_EXEC REG_SZ C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
+--[HKEY_USERS\.DEFAULT\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]
Start Page : hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]
Start Page : hxxp://go.microsoft.com/fwlink/?LinkId=69157
+---------------------------------------------------------------------------+
- "C:\AD-report-Scan-28.12.2008.log" (~27967 bytes)
# END at: 21:07:14 | 28/12/2008 - Time elapsed: 19.8 seconds
+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 392 lines ]
+---------------------------------------------------------------------------+
J'AI FAIT CE QUE TU AS DEMANDé VOICI MON ARAPPORT AD REMOVER... ya t'il d'autres manip encore a realiser?
--------- Logfile of AD-Remover 1.0.8.0 by C_XX ---------
# START at: 21:06:54 | Dim 28/12/2008 | Microsoft® Windows XP™ SP2 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: SECRETE-BD2021C | USER: kerim Fradj ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
- H:\ (File System: CDFS)
# Internet Explorer v7.0.5730.13
--------- [ RUNNING PROCESSES: 28 ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ntvdm.exe
-----------------------------------
+-----------------------| Boonty/Boonty Games Elements found :
.
+-----------------------| Eorezo Elements found :
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}"
.
[30/03/2008 19:29|d--------] C:\PROGRA~1\EoRezo
[30/03/2008 19:29|d--------] C:\PROGRA~1\EoRezo\EoAdv
[30/03/2008 19:30|d--------] C:\PROGRA~1\EoRezo\EOWEAT~1
[30/03/2008 18:56|--a------] C:\PROGRA~1\EoRezo\EoAdv\eoAdv.url
[25/01/2007 08:22|--a------] C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.OLD
[30/03/2008 19:29|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\cmhost.cyp
[27/06/2007 12:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\CONFME~1.CYP
[27/06/2007 12:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\CONFME~1.OLD
[30/03/2008 19:14|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\db
[30/03/2008 19:24|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\eoStats
[30/03/2008 19:12|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1.CFG
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\host.cyp
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\user.cyp
[30/03/2008 19:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\db\cat.cyp
[30/03/2008 19:29|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\eoStats\eoStats.txt
[30/03/2008 19:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\EOWEAT~1.CFG
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\images
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2
[30/03/2008 18:59|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\67_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\67_night.png
[21/08/2006 12:07|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\69_day.png
[21/08/2006 12:07|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\69_night.png
[13/07/2005 15:04|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\70_day.png
[13/07/2005 15:04|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\70_night.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\78_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\78_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\82_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\82_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\83_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\83_night.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\84_day.png
[30/06/2005 13:40|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\84_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\85_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\85_night.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\89_day.png
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\89_night.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\back.png
[30/10/2006 11:31|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BA24E2~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~4.PNG
[24/10/2006 09:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~3.PNG
[27/09/2006 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~1.PNG
[27/09/2006 13:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKGR~2.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BACKPR~1.PNG
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\band.png
[30/06/2005 09:14|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\BAND_S~1.PNG
[10/07/2006 11:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\close.png
[10/07/2006 11:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\CLOSEP~1.PNG
[23/10/2006 10:32|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\DAYPRE~2.PNG
[23/10/2006 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\DAYPRE~1.PNG
[25/10/2006 10:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\earth.png
[04/10/2006 10:21|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\FONDS_~1.PNG
[10/07/2006 11:50|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\help.png
[10/07/2006 11:49|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\HELPPR~1.PNG
[10/07/2006 11:24|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\minimise.png
[10/07/2006 11:23|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\MINIMI~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\next.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\NEXTPR~1.PNG
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\option.png
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\OPTION~1.PNG
[02/10/2006 17:36|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\REFLET~1.PNG
[18/05/2006 13:20|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\SMALL_~1.PNG
[06/11/2006 10:05|--ahs----] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~2\Thumbs.db
[30/10/2006 12:05|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\67_day.png
[30/10/2006 12:05|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\67_night.png
[02/10/2006 16:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\69_day.png
[02/10/2006 14:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\69_night.png
[06/11/2006 15:18|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\70_day.png
[06/11/2006 15:19|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\70_night.png
[02/10/2006 16:00|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\78_day.png
[02/10/2006 16:00|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\78_night.png
[02/10/2006 15:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\82_day.png
[02/10/2006 15:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\82_night.png
[02/10/2006 15:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\83_day.png
[02/10/2006 15:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\83_night.png
[02/10/2006 15:54|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\84_day.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\84_night.png
[02/10/2006 13:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\85_day.png
[02/10/2006 14:12|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\85_night.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\89_day.png
[02/10/2006 15:56|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\89_night.png
[10/01/2007 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\about.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\back.png
[06/11/2006 12:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~4.PNG
[06/11/2006 12:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BADB1B~1.PNG
[24/10/2006 09:58|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~3.PNG
[27/09/2006 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~1.PNG
[27/09/2006 13:57|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKGR~2.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\BACKPR~1.PNG
[10/07/2006 11:38|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\close.png
[10/07/2006 11:37|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\CLOSEP~1.PNG
[23/10/2006 10:32|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\DAYPRE~2.PNG
[23/10/2006 10:33|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\DAYPRE~1.PNG
[25/10/2006 10:59|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\earth.png
[04/10/2006 10:21|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\FONDS_~1.PNG
[10/07/2006 11:50|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\help.png
[10/07/2006 11:49|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\HELPPR~1.PNG
[10/07/2006 11:24|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\minimise.png
[10/07/2006 11:23|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\MINIMI~1.PNG
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\next.png
[30/10/2006 10:01|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\NEXTPR~1.PNG
[06/11/2006 12:46|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\option.png
[31/10/2006 11:45|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\OPTION~1.PNG
[02/10/2006 17:36|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\REFLET~1.PNG
[10/01/2007 10:33|--ahs----] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\Thumbs.db
[12/07/2005 13:55|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\EoRezo\EOWEAT~1\IMAGES~1\TXT_14~1.PNG
+-----------------------| Everest Poker Elements found :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker"
.
[07/11/2008 18:46|--a------] C:\LOG_LO~2.TXT
[07/11/2008 18:46|--a------] C:\LOG_LO~1.TXT
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\casino.exe
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\CSTART~1.EXE
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\cstart.exe
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\EVERES~1.EXE
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvbase.dll
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\gvcrt.dll
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\GVGFX-~1.DLL
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvgfx.dll
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvmain.dll
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\gvmain.exe
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\GVNETW~1.DLL
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\gvsound.dll
[28/10/2008 16:05|d--------] C:\PROGRA~1\EVERES~1\history
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\init.ini
[07/11/2008 19:53|--a------] C:\PROGRA~1\EVERES~1\log.dat
[07/11/2008 18:47|--a------] C:\PROGRA~1\EVERES~1\settings.ini
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\toc_fr.ini
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1\var
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\fonts
[07/11/2008 18:46|d--------] C:\PROGRA~1\EVERES~1\data\mp-lobby
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\fonts\kgp-en.ttf
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\data\mp-lobby\fr.gvt
[07/11/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\data\mp-lobby\shared.gvt
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker\BACKGR~1
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\shared.gvt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\BACKGR~1\default.gvt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\bitmaps.gvt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\MP-POK~1.TXT
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\mp-poker\fr\MP-POK~2.TXT
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\fr
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\country.txt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\language.txt
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\fr\ordinal.txt
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps
[02/04/2008 14:47|d--------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\BTN_SC~1.GVT
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\check.art
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\bitmaps\chips.art
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\button.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\carddeal.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\cardflip.ogg
[02/04/2008 14:47|--a------] C:\PROGRA~1\EVERES~1\data\shared\shared\sounds\CHIPCL~1.OGG
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\startup\en
[30/08/2008 07:54|d--------] C:\PROGRA~1\EVERES~1\data\startup\fr
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\startup\en\STARTU~1.TXT
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\fr\cstart.txt
[30/08/2008 07:54|--a------] C:\PROGRA~1\EVERES~1\data\startup\fr\STARTU~1.TXT
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\bitmaps
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\icons
[02/04/2008 14:46|d--------] C:\PROGRA~1\EVERES~1\data\startup\shared\sounds
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\bitmaps\SPLASH~1.ART
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\icons\ep.ico
[02/04/2008 14:46|--a------] C:\PROGRA~1\EVERES~1\data\startup\shared\sounds\alert.ogg
[21/09/2008 17:38|--a------] C:\PROGRA~1\EVERES~1\history\253.txt
[21/09/2008 17:53|--a------] C:\PROGRA~1\EVERES~1\history\254.txt
[21/09/2008 18:10|--a------] C:\PROGRA~1\EVERES~1\history\255.txt
[22/09/2008 09:43|--a------] C:\PROGRA~1\EVERES~1\history\256.txt
[22/09/2008 10:28|--a------] C:\PROGRA~1\EVERES~1\history\257.txt
[22/09/2008 10:50|--a------] C:\PROGRA~1\EVERES~1\history\258.txt
[22/09/2008 12:27|--a------] C:\PROGRA~1\EVERES~1\history\259.txt
[22/09/2008 12:50|--a------] C:\PROGRA~1\EVERES~1\history\260.txt
[22/09/2008 13:09|--a------] C:\PROGRA~1\EVERES~1\history\261.txt
[22/09/2008 14:44|--a------] C:\PROGRA~1\EVERES~1\history\263.txt
[22/09/2008 15:34|--a------] C:\PROGRA~1\EVERES~1\history\264.txt
[22/09/2008 16:15|--a------] C:\PROGRA~1\EVERES~1\history\265.txt
[23/09/2008 11:27|--a------] C:\PROGRA~1\EVERES~1\history\266.txt
[23/09/2008 11:26|--a------] C:\PROGRA~1\EVERES~1\history\267.txt
[23/09/2008 12:07|--a------] C:\PROGRA~1\EVERES~1\history\268.txt
[23/09/2008 12:20|--a------] C:\PROGRA~1\EVERES~1\history\269.txt
[23/09/2008 12:43|--a------] C:\PROGRA~1\EVERES~1\history\270.txt
[23/09/2008 12:56|--a------] C:\PROGRA~1\EVERES~1\history\271.txt
[24/09/2008 19:15|--a------] C:\PROGRA~1\EVERES~1\history\272.txt
[24/09/2008 19:08|--a------] C:\PROGRA~1\EVERES~1\history\273.txt
[24/09/2008 19:23|--a------] C:\PROGRA~1\EVERES~1\history\274.txt
[24/09/2008 19:45|--a------] C:\PROGRA~1\EVERES~1\history\275.txt
[24/09/2008 20:04|--a------] C:\PROGRA~1\EVERES~1\history\276.txt
[24/09/2008 21:04|--a------] C:\PROGRA~1\EVERES~1\history\277.txt
[25/09/2008 10:52|--a------] C:\PROGRA~1\EVERES~1\history\278.txt
[25/09/2008 10:37|--a------] C:\PROGRA~1\EVERES~1\history\279.txt
[25/09/2008 11:35|--a------] C:\PROGRA~1\EVERES~1\history\280.txt
[25/09/2008 11:20|--a------] C:\PROGRA~1\EVERES~1\history\281.txt
[25/09/2008 11:54|--a------] C:\PROGRA~1\EVERES~1\history\282.txt
[25/09/2008 12:02|--a------] C:\PROGRA~1\EVERES~1\history\283.txt
[25/09/2008 12:56|--a------] C:\PROGRA~1\EVERES~1\history\284.txt
[25/09/2008 13:22|--a------] C:\PROGRA~1\EVERES~1\history\285.txt
[25/09/2008 14:14|--a------] C:\PROGRA~1\EVERES~1\history\286.txt
[25/09/2008 13:32|--a------] C:\PROGRA~1\EVERES~1\history\287.txt
[25/09/2008 14:25|--a------] C:\PROGRA~1\EVERES~1\history\288.txt
[25/09/2008 14:25|--a------] C:\PROGRA~1\EVERES~1\history\289.txt
[25/09/2008 15:18|--a------] C:\PROGRA~1\EVERES~1\history\290.txt
[25/09/2008 15:14|--a------] C:\PROGRA~1\EVERES~1\history\291.txt
[25/09/2008 16:49|--a------] C:\PROGRA~1\EVERES~1\history\292.txt
[25/09/2008 15:28|--a------] C:\PROGRA~1\EVERES~1\history\293.txt
[25/09/2008 21:56|--a------] C:\PROGRA~1\EVERES~1\history\294.txt
[25/09/2008 20:42|--a------] C:\PROGRA~1\EVERES~1\history\295.txt
[28/09/2008 15:09|--a------] C:\PROGRA~1\EVERES~1\history\296.txt
[28/09/2008 16:13|--a------] C:\PROGRA~1\EVERES~1\history\297.txt
[28/09/2008 17:17|--a------] C:\PROGRA~1\EVERES~1\history\298.txt
[29/09/2008 14:12|--a------] C:\PROGRA~1\EVERES~1\history\299.txt
[29/09/2008 14:24|--a------] C:\PROGRA~1\EVERES~1\history\300.txt
[29/09/2008 15:26|--a------] C:\PROGRA~1\EVERES~1\history\301.txt
[29/09/2008 15:33|--a------] C:\PROGRA~1\EVERES~1\history\302.txt
[29/09/2008 15:45|--a------] C:\PROGRA~1\EVERES~1\history\303.txt
[29/09/2008 16:22|--a------] C:\PROGRA~1\EVERES~1\history\304.txt
[29/09/2008 16:12|--a------] C:\PROGRA~1\EVERES~1\history\305.txt
[29/09/2008 16:38|--a------] C:\PROGRA~1\EVERES~1\history\306.txt
[29/09/2008 18:29|--a------] C:\PROGRA~1\EVERES~1\history\307.txt
[29/09/2008 18:44|--a------] C:\PROGRA~1\EVERES~1\history\308.txt
[04/10/2008 12:54|--a------] C:\PROGRA~1\EVERES~1\history\309.txt
[04/10/2008 12:52|--a------] C:\PROGRA~1\EVERES~1\history\310.txt
[04/10/2008 13:56|--a------] C:\PROGRA~1\EVERES~1\history\311.txt
[04/10/2008 17:59|--a------] C:\PROGRA~1\EVERES~1\history\312.txt
[04/10/2008 18:36|--a------] C:\PROGRA~1\EVERES~1\history\313.txt
[04/10/2008 21:36|--a------] C:\PROGRA~1\EVERES~1\history\314.txt
[04/10/2008 22:13|--a------] C:\PROGRA~1\EVERES~1\history\315.txt
[05/10/2008 17:43|--a------] C:\PROGRA~1\EVERES~1\history\316.txt
[05/10/2008 16:51|--a------] C:\PROGRA~1\EVERES~1\history\317.txt
[05/10/2008 21:38|--a------] C:\PROGRA~1\EVERES~1\history\318.txt
[06/10/2008 11:08|--a------] C:\PROGRA~1\EVERES~1\history\319.txt
[06/10/2008 11:24|--a------] C:\PROGRA~1\EVERES~1\history\320.txt
[06/10/2008 12:10|--a------] C:\PROGRA~1\EVERES~1\history\321.txt
[06/10/2008 15:13|--a------] C:\PROGRA~1\EVERES~1\history\322.txt
[08/10/2008 11:07|--a------] C:\PROGRA~1\EVERES~1\history\323.txt
[08/10/2008 10:06|--a------] C:\PROGRA~1\EVERES~1\history\324.txt
[08/10/2008 11:24|--a------] C:\PROGRA~1\EVERES~1\history\325.txt
[08/10/2008 12:01|--a------] C:\PROGRA~1\EVERES~1\history\326.txt
[08/10/2008 11:38|--a------] C:\PROGRA~1\EVERES~1\history\327.txt
[08/10/2008 12:29|--a------] C:\PROGRA~1\EVERES~1\history\328.txt
[08/10/2008 12:44|--a------] C:\PROGRA~1\EVERES~1\history\329.txt
[08/10/2008 15:16|--a------] C:\PROGRA~1\EVERES~1\history\330.txt
[08/10/2008 15:35|--a------] C:\PROGRA~1\EVERES~1\history\331.txt
[08/10/2008 16:58|--a------] C:\PROGRA~1\EVERES~1\history\332.txt
[08/10/2008 17:14|--a------] C:\PROGRA~1\EVERES~1\history\333.txt
[08/10/2008 17:36|--a------] C:\PROGRA~1\EVERES~1\history\334.txt
[08/10/2008 18:57|--a------] C:\PROGRA~1\EVERES~1\history\335.txt
[08/10/2008 18:06|--a------] C:\PROGRA~1\EVERES~1\history\336.txt
[08/10/2008 22:00|--a------] C:\PROGRA~1\EVERES~1\history\337.txt
[08/10/2008 22:16|--a------] C:\PROGRA~1\EVERES~1\history\338.txt
[09/10/2008 09:30|--a------] C:\PROGRA~1\EVERES~1\history\339.txt
[09/10/2008 09:33|--a------] C:\PROGRA~1\EVERES~1\history\340.txt
[09/10/2008 09:40|--a------] C:\PROGRA~1\EVERES~1\history\341.txt
[09/10/2008 09:45|--a------] C:\PROGRA~1\EVERES~1\history\342.txt
[09/10/2008 10:23|--a------] C:\PROGRA~1\EVERES~1\history\344.txt
[09/10/2008 10:22|--a------] C:\PROGRA~1\EVERES~1\history\345.txt
[09/10/2008 13:47|--a------] C:\PROGRA~1\EVERES~1\history\346.txt
[09/10/2008 14:19|--a------] C:\PROGRA~1\EVERES~1\history\347.txt
[09/10/2008 15:17|--a------] C:\PROGRA~1\EVERES~1\history\348.txt
[09/10/2008 16:47|--a------] C:\PROGRA~1\EVERES~1\history\349.txt
[09/10/2008 15:45|--a------] C:\PROGRA~1\EVERES~1\history\350.txt
[09/10/2008 16:34|--a------] C:\PROGRA~1\EVERES~1\history\351.txt
[09/10/2008 18:00|--a------] C:\PROGRA~1\EVERES~1\history\352.txt
[09/10/2008 17:47|--a------] C:\PROGRA~1\EVERES~1\history\353.txt
[09/10/2008 18:32|--a------] C:\PROGRA~1\EVERES~1\history\354.txt
[09/10/2008 18:46|--a------] C:\PROGRA~1\EVERES~1\history\355.txt
[09/10/2008 18:54|--a------] C:\PROGRA~1\EVERES~1\history\356.txt
[09/10/2008 19:12|--a------] C:\PROGRA~1\EVERES~1\history\357.txt
[10/10/2008 15:19|--a------] C:\PROGRA~1\EVERES~1\history\358.txt
[10/10/2008 14:45|--a------] C:\PROGRA~1\EVERES~1\history\359.txt
[10/10/2008 15:48|--a------] C:\PROGRA~1\EVERES~1\history\360.txt
[10/10/2008 16:32|--a------] C:\PROGRA~1\EVERES~1\history\361.txt
[12/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\362.txt
[12/10/2008 20:28|--a------] C:\PROGRA~1\EVERES~1\history\363.txt
[12/10/2008 21:26|--a------] C:\PROGRA~1\EVERES~1\history\364.txt
[12/10/2008 21:55|--a------] C:\PROGRA~1\EVERES~1\history\365.txt
[13/10/2008 18:33|--a------] C:\PROGRA~1\EVERES~1\history\366.txt
[13/10/2008 22:07|--a------] C:\PROGRA~1\EVERES~1\history\367.txt
[15/10/2008 23:22|--a------] C:\PROGRA~1\EVERES~1\history\368.txt
[15/10/2008 22:54|--a------] C:\PROGRA~1\EVERES~1\history\369.txt
[15/10/2008 23:58|--a------] C:\PROGRA~1\EVERES~1\history\370.txt
[16/10/2008 22:45|--a------] C:\PROGRA~1\EVERES~1\history\371.txt
[16/10/2008 22:49|--a------] C:\PROGRA~1\EVERES~1\history\372.txt
[17/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\373.txt
[17/10/2008 22:22|--a------] C:\PROGRA~1\EVERES~1\history\374.txt
[19/10/2008 17:36|--a------] C:\PROGRA~1\EVERES~1\history\375.txt
[19/10/2008 17:04|--a------] C:\PROGRA~1\EVERES~1\history\376.txt
[19/10/2008 20:05|--a------] C:\PROGRA~1\EVERES~1\history\377.txt
[19/10/2008 20:32|--a------] C:\PROGRA~1\EVERES~1\history\378.txt
[19/10/2008 21:53|--a------] C:\PROGRA~1\EVERES~1\history\379.txt
[21/10/2008 21:33|--a------] C:\PROGRA~1\EVERES~1\history\380.txt
[21/10/2008 21:43|--a------] C:\PROGRA~1\EVERES~1\history\381.txt
[22/10/2008 19:10|--a------] C:\PROGRA~1\EVERES~1\history\382.txt
[22/10/2008 19:28|--a------] C:\PROGRA~1\EVERES~1\history\383.txt
[23/10/2008 20:27|--a------] C:\PROGRA~1\EVERES~1\history\384.txt
[23/10/2008 20:41|--a------] C:\PROGRA~1\EVERES~1\history\385.txt
[28/10/2008 16:30|--a------] C:\PROGRA~1\EVERES~1\history\386.txt
[07/11/2008 18:48|--a------] C:\PROGRA~1\EVERES~1\var\CONTEN~1.DAT
[02/04/2008 14:47|d--------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1
[02/04/2008 14:47|--a------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1\EVERES~1.LNK
[02/04/2008 14:47|--a------] C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EVERES~1\UNINST~1.LNK
+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements found :
.
+-----------------------| It's TV Elements found :
"HKEY_CURRENT_USER\Software\ItsLabel\ItsTV"
"HKEY_LOCAL_MACHINE\SOFTWARE\ItsLabel"
"HKEY_USERS\S-1-5-21-527237240-688789844-725345543-1005\Software\ItsLabel"
.
[30/03/2008 19:28|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel
[30/03/2008 19:28|d--------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel\ItsTV
[26/04/2007 17:54|--a------] C:\DOCUME~1\KERIMF~1\APPLIC~1\ItsLabel\ItsTV\itsTV.xml
+-----------------------| Sweetim Elements found :
.
+-----------------------| ADDED SCAN :
+--[HKEY_CURRENT_USER\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
+--[HKEY_LOCAL_MACHINE\..\Run]
vspdfprsrv.exe REG_SZ C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe --background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\backWeb-8876480.exe
EM_EXEC REG_SZ C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
+--[HKEY_USERS\.DEFAULT\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]
Start Page : hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]
Start Page : hxxp://go.microsoft.com/fwlink/?LinkId=69157
+---------------------------------------------------------------------------+
- "C:\AD-report-Scan-28.12.2008.log" (~27967 bytes)
# END at: 21:07:14 | 28/12/2008 - Time elapsed: 19.8 seconds
+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 392 lines ]
+---------------------------------------------------------------------------+
darkpoet
Messages postés
1654
Date d'inscription
jeudi 29 mai 2008
Statut
Contributeur sécurité
Dernière intervention
10 mars 2014
62
28 déc. 2008 à 21:37
28 déc. 2008 à 21:37
/!\ Déconnecte-toi et ferme toutes applications en cours /!\
? Double-clique sur AD-Remover pour le lancer : au menu principal, choisis l'option B.
? Coche à l'écran de sélection :
http://sd-1.archive-host.com/membres/up/16506160323759868/Capturer-ADR.JPG
Suppression Boonty/BoontyGames (Si trouvé)
Suppression Eorezo (Si trouvé)
Suppression Everest Poker (Si trouvé)
Suppression Funwebproduct/MyWay/MyWebsearch (Si trouvé)
Suppression Messenger Skinner (Si trouvé)
Suppression Sweetim (Si trouvé)
? Puis choisis S, le programme va travailler.
? Poste le rapport qui apparaît à la fin.
(Le rapport est sauvegardé aussi sous C:\Ad-report.log)
/!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\
? Double-clique sur AD-Remover pour le lancer : au menu principal, choisis l'option B.
? Coche à l'écran de sélection :
http://sd-1.archive-host.com/membres/up/16506160323759868/Capturer-ADR.JPG
Suppression Boonty/BoontyGames (Si trouvé)
Suppression Eorezo (Si trouvé)
Suppression Everest Poker (Si trouvé)
Suppression Funwebproduct/MyWay/MyWebsearch (Si trouvé)
Suppression Messenger Skinner (Si trouvé)
Suppression Sweetim (Si trouvé)
? Puis choisis S, le programme va travailler.
? Poste le rapport qui apparaît à la fin.
(Le rapport est sauvegardé aussi sous C:\Ad-report.log)
/!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\
darkpoet
Messages postés
1654
Date d'inscription
jeudi 29 mai 2008
Statut
Contributeur sécurité
Dernière intervention
10 mars 2014
62
28 déc. 2008 à 22:04
28 déc. 2008 à 22:04
abandonne pas on est au bout
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
voila c'est fait... ca servait a quoi tout ca? et quand je poste un rapport toi tu en fait quoi?
j'ai une autre question aussi j'ai un antivirus qui s"appelle AVAST je l'ai laissé quand je faisait mes manip c'est pas grave? et maintenant que malwarbyres et AD remover sont sur mon bureau c'est pas icompatible avc mon antivirus? EST CE QUe ce sont des antivirus ou c autre chose... en tt cas merci de m'aider... c'est ton metier ou c'est benevolement? bref je tape discute... voici mon rapport
--------- Logfile of AD-Remover 1.0.8.0 by C_XX ---------
*** Limited to ***
Boonty/BoontyGames
Eorezo
Everest Poker
Funwebproduct/MyWay/MyWebsearch
It's TV
Sweetim
******************
# START at: 22:07:08 | Dim 28/12/2008 | Microsoft® Windows XP™ SP2 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Clean | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: SECRETE-BD2021C | USER: kerim Fradj ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
- H:\ (File System: CDFS)
# Internet Explorer v7.0.5730.13
--------- [ RUNNING PROCESSES: 38 ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\WINDOWS\system32\ntvdm.exe
-----------------------------------
(!) ---- IE start pages reset
+-----------------------| Boonty/Boonty Games Elements Deleted :
.
+-----------------------| Eorezo Elements Deleted :
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}"
.
[30/03/2008 19:29|d--------] C:\Program Files\EoRezo
[30/03/2008 19:29|d--------] C:\Documents and Settings\kerim Fradj\Application Data\EoRezo
+-----------------------| Everest Poker Elements Deleted :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker"
.
[07/11/2008 18:46|--a------] C:\LOG_LO~2.TXT
[07/11/2008 18:46|--a------] C:\LOG_LO~1.TXT
[07/11/2008 18:46|d--------] C:\Program Files\Everest Poker
[02/04/2008 14:47|d--------] C:\Documents and Settings\All Users\MENUDM~1\PROGRA~1\Everest Poker
+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Deleted :
.
+-----------------------| It's TV Elements Deleted :
"HKEY_CURRENT_USER\Software\ItsLabel\ItsTV"
"HKEY_LOCAL_MACHINE\SOFTWARE\ItsLabel"
"HKEY_USERS\S-1-5-21-527237240-688789844-725345543-1005\Software\ItsLabel"
.
[30/03/2008 19:28|d--------] C:\Documents and Settings\kerim Fradj\Application Data\ItsLabel
+-----------------------| Sweetim Elements Deleted :
.
(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.
+-----------------------| ADDED SCAN :
+--[HKEY_CURRENT_USER\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
+--[HKEY_LOCAL_MACHINE\..\Run]
vspdfprsrv.exe REG_SZ C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe --background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\backWeb-8876480.exe
EM_EXEC REG_SZ C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
+--[HKEY_USERS\.DEFAULT\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]
Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]
Start Page : hxxp://fr.msn.com/
+---------------------------------------------------------------------------+
- "C:\AD-report-Clean-28.12.2008.log" (~5239 bytes)
- "C:\AD-report-Scan-28.12.2008.log" (~28303 bytes)
# END at: 22:15:56 | 28/12/2008 - Time elapsed: 8 minutes, 48 seconds
+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 110 lines ]
+---------------------------------------------------------------------------+
j'ai une autre question aussi j'ai un antivirus qui s"appelle AVAST je l'ai laissé quand je faisait mes manip c'est pas grave? et maintenant que malwarbyres et AD remover sont sur mon bureau c'est pas icompatible avc mon antivirus? EST CE QUe ce sont des antivirus ou c autre chose... en tt cas merci de m'aider... c'est ton metier ou c'est benevolement? bref je tape discute... voici mon rapport
--------- Logfile of AD-Remover 1.0.8.0 by C_XX ---------
*** Limited to ***
Boonty/BoontyGames
Eorezo
Everest Poker
Funwebproduct/MyWay/MyWebsearch
It's TV
Sweetim
******************
# START at: 22:07:08 | Dim 28/12/2008 | Microsoft® Windows XP™ SP2 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Clean | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: SECRETE-BD2021C | USER: kerim Fradj ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
- H:\ (File System: CDFS)
# Internet Explorer v7.0.5730.13
--------- [ RUNNING PROCESSES: 38 ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\WINDOWS\system32\ntvdm.exe
-----------------------------------
(!) ---- IE start pages reset
+-----------------------| Boonty/Boonty Games Elements Deleted :
.
+-----------------------| Eorezo Elements Deleted :
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}"
.
[30/03/2008 19:29|d--------] C:\Program Files\EoRezo
[30/03/2008 19:29|d--------] C:\Documents and Settings\kerim Fradj\Application Data\EoRezo
+-----------------------| Everest Poker Elements Deleted :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker"
.
[07/11/2008 18:46|--a------] C:\LOG_LO~2.TXT
[07/11/2008 18:46|--a------] C:\LOG_LO~1.TXT
[07/11/2008 18:46|d--------] C:\Program Files\Everest Poker
[02/04/2008 14:47|d--------] C:\Documents and Settings\All Users\MENUDM~1\PROGRA~1\Everest Poker
+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Deleted :
.
+-----------------------| It's TV Elements Deleted :
"HKEY_CURRENT_USER\Software\ItsLabel\ItsTV"
"HKEY_LOCAL_MACHINE\SOFTWARE\ItsLabel"
"HKEY_USERS\S-1-5-21-527237240-688789844-725345543-1005\Software\ItsLabel"
.
[30/03/2008 19:28|d--------] C:\Documents and Settings\kerim Fradj\Application Data\ItsLabel
+-----------------------| Sweetim Elements Deleted :
.
(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.
+-----------------------| ADDED SCAN :
+--[HKEY_CURRENT_USER\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
+--[HKEY_LOCAL_MACHINE\..\Run]
vspdfprsrv.exe REG_SZ C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe --background
LDM REG_SZ C:\Program Files\Desktop Messenger\8876480\Program\backWeb-8876480.exe
EM_EXEC REG_SZ C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
+--[HKEY_USERS\.DEFAULT\..\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]
Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]
Start Page : hxxp://fr.msn.com/
+---------------------------------------------------------------------------+
- "C:\AD-report-Clean-28.12.2008.log" (~5239 bytes)
- "C:\AD-report-Scan-28.12.2008.log" (~28303 bytes)
# END at: 22:15:56 | 28/12/2008 - Time elapsed: 8 minutes, 48 seconds
+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 110 lines ]
+---------------------------------------------------------------------------+
darkpoet
Messages postés
1654
Date d'inscription
jeudi 29 mai 2008
Statut
Contributeur sécurité
Dernière intervention
10 mars 2014
62
28 déc. 2008 à 22:27
28 déc. 2008 à 22:27
les raports servent a reperer les virus ou malware et les differents outil que je t ai fait utilisé les eradique
pour ton antivirus je te conseil de virer avast pour avira antivir qui est gratuit mais 1000 fois plus efficace que avast
site pour telecharger avira antivir : https://www.01net.com/
il reste a enlever tout les outils que l on a utilisé fait ceci puis je te laisse tranquille
Télécharge ToolsCleaner sur ton bureau.
-->
https://www.commentcamarche.net/telecharger/ 34055291 toolscleaner
# Clique sur "Recherche" et laisse le scan agir ...
# Clique sur "Suppression" pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
ensuite
Télécharges : - CCleaner (n'installe pas la barre d'outil Yahoo)
https://www.pcastuces.com/logitheque/ccleaner.htm
Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).
Un tuto ( aide ):
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
---> Utilisation:
! déconnectes toi et fermes toutes applications en cours !
* vas dans "nettoyeur" : fait analyse puis nettoyage
* vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )
pour ton antivirus je te conseil de virer avast pour avira antivir qui est gratuit mais 1000 fois plus efficace que avast
site pour telecharger avira antivir : https://www.01net.com/
il reste a enlever tout les outils que l on a utilisé fait ceci puis je te laisse tranquille
Télécharge ToolsCleaner sur ton bureau.
-->
https://www.commentcamarche.net/telecharger/ 34055291 toolscleaner
# Clique sur "Recherche" et laisse le scan agir ...
# Clique sur "Suppression" pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
ensuite
Télécharges : - CCleaner (n'installe pas la barre d'outil Yahoo)
https://www.pcastuces.com/logitheque/ccleaner.htm
Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).
Un tuto ( aide ):
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
---> Utilisation:
! déconnectes toi et fermes toutes applications en cours !
* vas dans "nettoyeur" : fait analyse puis nettoyage
* vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
28 déc. 2008 à 23:28
28 déc. 2008 à 23:28
bonjour l'adresse est mal saisi je te remets la procédure
Tu désinstalles les outils utilisés avec Toolscleaner2 lui tu le supprimeras de sur le bureau manuellement ainsi que le rapport généré qui est dans ton disque dur système sous le nom de " TCleaner "
Télécharge toolscleaner sur ton Bureau : http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
. Double-cliques sur ToolsCleaner2 "l'as de carreau" et laisse le travailler
. Cliques sur Recherche et laisse le scan se terminer. attention ça peut parraitre long
. Cliques sur Suppression pour finaliser.
. Tu peux, si tu le souhaites, te servir des Options facultatives.
. Clique sur Quitter, pour que le rapport puisse se créer.
. Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse
Tu désinstalles les outils utilisés avec Toolscleaner2 lui tu le supprimeras de sur le bureau manuellement ainsi que le rapport généré qui est dans ton disque dur système sous le nom de " TCleaner "
Télécharge toolscleaner sur ton Bureau : http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
. Double-cliques sur ToolsCleaner2 "l'as de carreau" et laisse le travailler
. Cliques sur Recherche et laisse le scan se terminer. attention ça peut parraitre long
. Cliques sur Suppression pour finaliser.
. Tu peux, si tu le souhaites, te servir des Options facultatives.
. Clique sur Quitter, pour que le rapport puisse se créer.
. Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse
merci voila le rapport
et je vais suivre tes conseils et changer dantivirus aprés que tt ca est fini...
[ Rapport ToolsCleaner version 2.2.9 (par A.Rothstein & dj QUIOU) ]
-->- Recherche:
C:\Rsit: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\kerim Fradj\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\HJTInstall.exe: trouvé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\SmitFraudFix.exe: trouvé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\Rsit.exe: trouvé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\SmitFraudfix: trouvé !
C:\Program Files\Ad-remover\TOOLS\NIRCMD.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\kerim Fradj\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\HJTInstall.exe: supprimé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\SmitFraudFix.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\Rsit.exe: supprimé !
C:\Program Files\Ad-remover\TOOLS\NIRCMD.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\SmitFraudfix: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
et je vais suivre tes conseils et changer dantivirus aprés que tt ca est fini...
[ Rapport ToolsCleaner version 2.2.9 (par A.Rothstein & dj QUIOU) ]
-->- Recherche:
C:\Rsit: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\kerim Fradj\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\HJTInstall.exe: trouvé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\SmitFraudFix.exe: trouvé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\Rsit.exe: trouvé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\SmitFraudfix: trouvé !
C:\Program Files\Ad-remover\TOOLS\NIRCMD.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\kerim Fradj\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\HJTInstall.exe: supprimé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\SmitFraudFix.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\Rsit.exe: supprimé !
C:\Program Files\Ad-remover\TOOLS\NIRCMD.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\kerim Fradj\Mes documents\Evelyne DELEURENCE\SmitFraudfix: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
darkpoet
Messages postés
1654
Date d'inscription
jeudi 29 mai 2008
Statut
Contributeur sécurité
Dernière intervention
10 mars 2014
62
29 déc. 2008 à 17:39
29 déc. 2008 à 17:39
ok c bon pour moi bonne continuation clic resolu