Virus ou pas ?

Résolu
phi60420 Messages postés 169 Statut Membre -  
darkpoet Messages postés 1696 Statut Contributeur sécurité -
Bonjour, je viens d'avoir mon pc qui ne voulais plus ce mettre en marche j'ai essayé en mode sans echec rien a faire meme aevc le cd de xp dedans et puis il est reparti en mode normal avec le cd de xp dedans mais je ne sias pas comment je joint un rapport hijackthis pour que quelqu'un puisse me dire si mon pc est inffecté ou pas je remercie par avance celui qui pourra m'aider

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:46:59, on 27/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\rmctrl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AOLSAV] C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo RX560 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S266.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series sur PC-DE-THOMAS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S29.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [\\Pc-de-thomas\EPSON Stylus Photo RX560 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\DOCUME~1\@\LOCALS~1\Temp\E_S5.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series sur PC-DE-LAETITIA] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S20.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [\\Pc-de-laetitia\EPSON Stylus Photo RX560 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\DOCUME~1\@\LOCALS~1\Temp\E_S9.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [\\Pc-de-laetitia\EPSON Stylus Photo RX560 Series (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\DOCUME~1\@\LOCALS~1\Temp\E_SC.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series sur Pc-de-laetitia (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_SF.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series (Copie 3) sur Pc-de-laetitia (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S12.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series (Copie 1) sur PC-DE-LAETITIA] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_SB.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series sur Pc-de-laetitia (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_SE.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series (Copie 2) sur PC-DE-LAETITIA] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S7.tmp" /EF "HKCU"
O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?70696ede427d4ba48f69a98de8f48e7e
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?70696ede427d4ba48f69a98de8f48e7e
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O9 - Extra button: Capturer ! - {47055D63-DFCD-11d3-8406-00500445A7D0} - C:\Program Files\Goto\MemoWeb 4\IEBtn\Launcher (file missing)
O9 - Extra 'Tools' menuitem: Capturer ce web - {47055D63-DFCD-11d3-8406-00500445A7D0} - C:\Program Files\Goto\MemoWeb 4\IEBtn\Launcher (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.fr/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.fr.aol.com/molbin/shared/mcinsctl/fr/4,0,0,84/mcinsctl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {981D847D-2C06-4FB7-A09C-4F0A48601B2C} (DiagSetup Class) - http://techcity.aol.fr/download/img/DiagSetup.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.fr.aol.com/molbin/shared/mcgdmgr/fr/1,0,0,21/mcgdmgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CD425DEC-7419-4234-B20F-7DA61636C73D}: NameServer = 192.168.30.1
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
A voir également:

33 réponses

darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
0
Utilisateur anonyme
 
Re Phi! Tu aurais pu continuer sur ton topic avec moi! J'attendais là-bas ton log...

Suis ce que te dis darkpoet!

Bonne continuation à vous deux!

A++
0
phi60420 Messages postés 169 Statut Membre 1
 
bonjour et merci de t'interressé a mon probleme voila le rapport que tu as demandé

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2500+ )
BIOS : Version 07.00T
USER : @ ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
Firewall : COMODO Firewall Pro 2.3.035 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:9 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 27/12/2008|19:57 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\AskSBar
C:\Program Files\AskSBar\bar
C:\Program Files\AskSBar\SrchAstt
C:\Program Files\AskSBar\bar\1.bin
C:\Program Files\AskSBar\bar\Cache
C:\Program Files\AskSBar\bar\History
C:\Program Files\AskSBar\bar\Settings
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2HIGHIN.EXE
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2PLUGIN.DLL
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
C:\Program Files\AskSBar\bar\1.bin\NPASKSBR.DLL
C:\Program Files\AskSBar\bar\1.bin\V2RSSMNU.DLL
C:\Program Files\AskSBar\bar\Cache\000FF11D
C:\Program Files\AskSBar\bar\Cache\04C39D11.bin
C:\Program Files\AskSBar\bar\Cache\04C3A455.bin
C:\Program Files\AskSBar\bar\Cache\04C3A927.bin
C:\Program Files\AskSBar\bar\Cache\04C3AE09.bin
C:\Program Files\AskSBar\bar\Cache\04C7A849.bin
C:\Program Files\AskSBar\bar\Cache\04C7B1BF.bin
C:\Program Files\AskSBar\bar\Cache\files.ini
C:\Program Files\AskSBar\bar\History\search2
C:\Program Files\AskSBar\bar\Settings\prevcfg2.htm
C:\Program Files\AskSBar\SrchAstt\1.bin
C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
C:\DOCUME~1\@\APPLIC~1\Dealio
C:\Program Files\KaZaA
C:\Program Files\KaZaA\bdupd.dll
C:\Program Files\KaZaA\broadband.gif
C:\Program Files\KaZaA\broadband2.gif
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\Help
C:\Program Files\KaZaA\kazaa.exe
C:\Program Files\KaZaA\Kazaa.url
C:\Program Files\KaZaA\kzscan.dll
C:\Program Files\KaZaA\linksfolder.ico
C:\Program Files\KaZaA\magnet.exe
C:\Program Files\KaZaA\My Channels
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\plugins
C:\Program Files\KaZaA\plugins.htm
C:\Program Files\KaZaA\Promotions
C:\Program Files\KaZaA\Skins
C:\Program Files\KaZaA\Thumbs.db
C:\Program Files\KaZaA\versions.dat
C:\Program Files\KaZaA\Db\4ova-050129.cab
C:\Program Files\KaZaA\Db\bb.db
C:\Program Files\KaZaA\Db\bb2.db
C:\Program Files\KaZaA\Db\ctx4-040126.cab
C:\Program Files\KaZaA\Db\ctx4-040413b.cab
C:\Program Files\KaZaA\Db\ctx4-041108.cab
C:\Program Files\KaZaA\Db\ctx4-041111.cab
C:\Program Files\KaZaA\Db\ctx4-041223.cab
C:\Program Files\KaZaA\Db\ctx4-050118b.cab
C:\Program Files\KaZaA\Db\ctx4-060124.cab
C:\Program Files\KaZaA\Db\ctx4-060422.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\gr_@.current
C:\Program Files\KaZaA\Db\gr_@.previous
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\ova4-060412.cab
C:\Program Files\KaZaA\Db\str040112.cab
C:\Program Files\KaZaA\Db\tsi4-040126.cab
C:\Program Files\KaZaA\Db\tsi4-040413b.cab
C:\Program Files\KaZaA\Db\tsi4-041101a.cab
C:\Program Files\KaZaA\Db\tsi4-041101b.cab
C:\Program Files\KaZaA\Db\tsi4-041115.cab
C:\Program Files\KaZaA\Db\tsi4-041116.cab
C:\Program Files\KaZaA\Db\tsi4-041221a.cab
C:\Program Files\KaZaA\Db\tsi4-041221b.cab
C:\Program Files\KaZaA\Db\tsi4-050107a.cab
C:\Program Files\KaZaA\Db\tsi4-050107b.cab
C:\Program Files\KaZaA\Db\tsi4-060404a.cab
C:\Program Files\KaZaA\Db\tsi4-060404b.cab
C:\Program Files\KaZaA\Db\tsi4-060422b.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\KaZaA\Help\arrow.gif
C:\Program Files\KaZaA\Help\arrow_sml.gif
C:\Program Files\KaZaA\Help\background.gif
C:\Program Files\KaZaA\Help\h_mykazaa.gif
C:\Program Files\KaZaA\Help\h_myMedia.gif
C:\Program Files\KaZaA\Help\h_myplaylists.gif
C:\Program Files\KaZaA\Help\icon_gold_kap.gif
C:\Program Files\KaZaA\Help\myKapsules.gif
C:\Program Files\KaZaA\Help\mykapsules.htm
C:\Program Files\KaZaA\Help\mykazaa.css
C:\Program Files\KaZaA\Help\mykazaa.htm
C:\Program Files\KaZaA\Help\mymedia.htm
C:\Program Files\KaZaA\Help\myplaylists.htm
C:\Program Files\KaZaA\Help\spacer.gif
C:\Program Files\KaZaA\Help\Thumbs.db
C:\Program Files\KaZaA\My Channels\Bin
C:\Program Files\KaZaA\My Channels\Images
C:\Program Files\KaZaA\My Channels\Bin\dating.kcd
C:\Program Files\KaZaA\My Channels\Bin\emerging_artists.kcd
C:\Program Files\KaZaA\My Channels\Bin\g_spot.kcd
C:\Program Files\KaZaA\My Channels\Bin\onelove_browse.kcd
C:\Program Files\KaZaA\My Channels\Bin\ringtonechannel.kcd
C:\Program Files\KaZaA\My Channels\Bin\rshiphop.kcd
C:\Program Files\KaZaA\My Channels\Bin\skilledgames.kcd
C:\Program Files\KaZaA\My Channels\Images\dating.bmp
C:\Program Files\KaZaA\My Channels\Images\emerging_artists.bmp
C:\Program Files\KaZaA\My Channels\Images\g_spot.bmp
C:\Program Files\KaZaA\My Channels\Images\onelove_browse.bmp
C:\Program Files\KaZaA\My Channels\Images\ringtonechannel.bmp
C:\Program Files\KaZaA\My Channels\Images\rshiphop_browse.bmp
C:\Program Files\KaZaA\My Channels\Images\skilledgames.bmp
C:\Program Files\KaZaA\My Channels\Images\Thumbs.db
C:\Program Files\KaZaA\My Shared Folder\Audio - Alternatie Rock.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Alternative Rock.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Barrington Levy.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Electronica.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Fine Arts Militia Album.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Folk.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Funk.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Hip Hop.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Jazz.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Pop Rock.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Public Enemy Revolverlution Album.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - R&B.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Reggae.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - The Honey Palace Album.kpl
C:\Program Files\KaZaA\My Shared Folder\Electronica - Emerging Artists.kpl
C:\Program Files\KaZaA\My Shared Folder\Funk - Emerging Artists.kpl
C:\Program Files\KaZaA\My Shared Folder\Hip-Hop - Emerging Artists.kpl
C:\Program Files\KaZaA\My Shared Folder\kazaa267_fr.exe
C:\Program Files\KaZaA\My Shared Folder\kmd260_en.exe
C:\Program Files\KaZaA\My Shared Folder\kmd263_fr.exe
C:\Program Files\KaZaA\My Shared Folder\Pop Rock - Emerging Artists.kpl
C:\Program Files\KaZaA\My Shared Folder\R&B - Emerging Artists.kpl
C:\Program Files\KaZaA\plugins\ace.xmd
C:\Program Files\KaZaA\plugins\alz.xmd
C:\Program Files\KaZaA\plugins\arc.xmd
C:\Program Files\KaZaA\plugins\arj.xmd
C:\Program Files\KaZaA\plugins\bach.xmd
C:\Program Files\KaZaA\plugins\bzip2.xmd
C:\Program Files\KaZaA\plugins\cab.xmd
C:\Program Files\KaZaA\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\plugins\ceva_dll.cvd
C:\Program Files\KaZaA\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\plugins\chm.xmd
C:\Program Files\KaZaA\plugins\cpio.xmd
C:\Program Files\KaZaA\plugins\cran.cvd
C:\Program Files\KaZaA\plugins\cran.xmd
C:\Program Files\KaZaA\plugins\dbx.xmd
C:\Program Files\KaZaA\plugins\docfile.xmd
C:\Program Files\KaZaA\plugins\emalware.cvd
C:\Program Files\KaZaA\plugins\emalware.ivd
C:\Program Files\KaZaA\plugins\emalware.xmd
C:\Program Files\KaZaA\plugins\epoc.xmd
C:\Program Files\KaZaA\plugins\gzip.xmd
C:\Program Files\KaZaA\plugins\ha.xmd
C:\Program Files\KaZaA\plugins\hlp.xmd
C:\Program Files\KaZaA\plugins\hpe.cvd
C:\Program Files\KaZaA\plugins\hpe.xmd
C:\Program Files\KaZaA\plugins\hqx.xmd
C:\Program Files\KaZaA\plugins\html.xmd
C:\Program Files\KaZaA\plugins\imp.xmd
C:\Program Files\KaZaA\plugins\inno.xmd
C:\Program Files\KaZaA\plugins\instyler.xmd
C:\Program Files\KaZaA\plugins\iso.xmd
C:\Program Files\KaZaA\plugins\java.cvd
C:\Program Files\KaZaA\plugins\java.xmd
C:\Program Files\KaZaA\plugins\jpeg.xmd
C:\Program Files\KaZaA\plugins\lha.xmd
C:\Program Files\KaZaA\plugins\lnk.xmd
C:\Program Files\KaZaA\plugins\mbox.xmd
C:\Program Files\KaZaA\plugins\mbx.xmd
C:\Program Files\KaZaA\plugins\mdx.xmd
C:\Program Files\KaZaA\plugins\mdx_97.cvd
C:\Program Files\KaZaA\plugins\mdx_97.ivd
C:\Program Files\KaZaA\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\plugins\mime.xmd
C:\Program Files\KaZaA\plugins\mso.xmd
C:\Program Files\KaZaA\plugins\na.cvd
C:\Program Files\KaZaA\plugins\na.xmd
C:\Program Files\KaZaA\plugins\nelf.cvd
C:\Program Files\KaZaA\plugins\nelf.xmd
C:\Program Files\KaZaA\plugins\nsis.xmd
C:\Program Files\KaZaA\plugins\objd.xmd
C:\Program Files\KaZaA\plugins\pdf.xmd
C:\Program Files\KaZaA\plugins\pst.xmd
C:\Program Files\KaZaA\plugins\rar.xmd
C:\Program Files\KaZaA\plugins\rpm.xmd
C:\Program Files\KaZaA\plugins\rtf.xmd
C:\Program Files\KaZaA\plugins\rup.cvd
C:\Program Files\KaZaA\plugins\rup.xmd
C:\Program Files\KaZaA\plugins\sdx.cvd
C:\Program Files\KaZaA\plugins\sdx.ivd
C:\Program Files\KaZaA\plugins\sdx.xmd
C:\Program Files\KaZaA\plugins\sfx.xmd
C:\Program Files\KaZaA\plugins\swf.xmd
C:\Program Files\KaZaA\plugins\tar.xmd
C:\Program Files\KaZaA\plugins\td0.xmd
C:\Program Files\KaZaA\plugins\thebat.xmd
C:\Program Files\KaZaA\plugins\tnef.xmd
C:\Program Files\KaZaA\plugins\unpack.cvd
C:\Program Files\KaZaA\plugins\unpack.ivd
C:\Program Files\KaZaA\plugins\unpack.xmd
C:\Program Files\KaZaA\plugins\update.txt
C:\Program Files\KaZaA\plugins\uudecode.xmd
C:\Program Files\KaZaA\plugins\ve.cvd
C:\Program Files\KaZaA\plugins\ve.ivd
C:\Program Files\KaZaA\plugins\ve.xmd
C:\Program Files\KaZaA\plugins\vedata.cvd
C:\Program Files\KaZaA\plugins\viza.xmd
C:\Program Files\KaZaA\plugins\wise.xmd
C:\Program Files\KaZaA\plugins\xishield.xmd
C:\Program Files\KaZaA\plugins\z.xmd
C:\Program Files\KaZaA\plugins\zip.xmd
C:\Program Files\KaZaA\plugins\zoo.xmd
C:\Program Files\KaZaA\Promotions\DirectTV.url
C:\Program Files\KaZaA\Promotions\Kazaa Shop.url
C:\Program Files\KaZaA\Promotions\Netflix.url
C:\Program Files\KaZaA\Promotions\readme.lnk
C:\Program Files\KaZaA\Skins\Ceramic Biscuit
C:\Program Files\KaZaA\Skins\Orbital Shadows
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_search.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_search_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_search_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_search_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_shop.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_shop_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_shop_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_shop_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_start.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_start_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_start_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_start_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_tell.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_tell_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_tell_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_tell_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_theatre.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_theatre_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_theatre_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_theatre_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_traffic.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_traffic_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_traffic_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_traffic_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_addtoplay.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_addtoplay_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_addtoplay_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_addtoplay_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_next.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_next_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_next_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_next_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_pause.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_play.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_play_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_play_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_play_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_prev.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_prev_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_prev_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_prev_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_slider.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_sliderThumb.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_sliderThumb_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_stop.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_volume.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_volume_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_volume_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_volume_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_download.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_download_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_download_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_download_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_messageuser.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_messageuser_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_messageuser_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_messageuser_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_newsearch.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_newsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_newsearch_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_newsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_searchuser.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_searchuser_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_searchuser_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_searchuser_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_showsearch.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_showsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_showsearch_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_showsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\skin.xml
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_back.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_back_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_back_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_back_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_fwd.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_fwd_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_fwd_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_fwd_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_home.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_home_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_home_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_home_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_refresh.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_refresh_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_refresh_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_refresh_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_stop.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\theatrebar_fullscreen.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\theatrebar_fullscreen_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\theatrebar_fullscreen_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\theatrebar_fullscreen_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\Thumbs.db
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_cancel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_cancel_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_cancel_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_cancel_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_pause.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_resume.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_resume_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_resume_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_resume_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_close.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_close_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_close_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_close_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_maximise.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_maximise_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_maximise_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_maximise_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_minimise.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_minimise_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_minimise_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_minimise_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_restore.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_restore_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_restore_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_restore_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_btm.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_btmLeft.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_btmright.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_left.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_right.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_top.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_topleft.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_topright.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\License.txt
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_peer.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_peer_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_peer_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_peer_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_search.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_search_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_search_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_search_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_shop.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_shop_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_shop_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_shop_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_tell.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_tell_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_tell_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_tell_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_theater.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_theater_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_theater_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_theater_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_traffic.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_traffic_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_traffic_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_traffic_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_web.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_web_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_web_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_web_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_addtoplay.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_addtoplay_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_addtoplay_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_addtoplay_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_next.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_next_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_next_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_next_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_pause.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_play.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_play_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_play_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_play_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_prev.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_prev_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_prev_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_prev_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_slider.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_sliderThumb.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_sliderThumb_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_stop.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_volume.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_volume_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_volume_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_volume_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_closetab.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_closetab_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_closetab_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_closetab_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_download.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_download_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_download_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_download_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_messageuser.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_messageuser_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_messageuser_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_messageuser_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_newsearch.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_newsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_newsearch_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_newsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_searchuser.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_searchuser_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_searchuser_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_searchuser_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_showsearch.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_showsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_showsearch_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_showsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\skin.xml
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_back.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_back_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_back_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_back_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_fwd.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_fwd_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_fwd_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_fwd_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_home.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_home_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_home_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_home_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_refresh.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_refresh_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_refresh_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_refresh_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_stop.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\theatrebar_fullscreen.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\theatrebar_fullscreen_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\theatrebar_fullscreen_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\theatrebar_fullscreen_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\Thumbs.db
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_cancel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_cancel_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_cancel_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_cancel_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_pause.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_resume.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_resume_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_resume_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_resume_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_close.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_close_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_close_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_close_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_maximise.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_maximise_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_maximise_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_maximise_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_minimise.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_minimise_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_minimise_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_minimise_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_restore.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_restore_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_restore_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_restore_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_btm.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_btmLeft.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_btmright.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_left.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_right.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_top.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_topleft.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_topright.bmp
C:\DOCUME~1\@\Bureau\Torrent Search Fichiers récents.url
C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll

-----------\\ Extensions

(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.sfr.fr/"
"Search Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2fbr%2faccess%2fallinone.asp%3f"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr"
"Search Bar"="about:blank"
"default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mdf
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\SH3.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\A LIRE ABSOLUMENT !!!.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1\Architecte3D.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2\Architecte3D_CD2.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\batpro1_100.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\KEYGEN.EXE
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\Serial.txt
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\- CRACK EUROBARRE v1.4.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\1 ETAPE grace au crack v1.4 gagner plus READ ME.doc
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\crack pour Eurobarre.reg
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00.zip
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\Deutsch AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\US AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\programe\Crack
C:\DOCUME~1\@\Mes documents\programe\Crack\AVS.Audio.Tools.v3.5.1.160-RES-crk.rar
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\licence.reg
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\Manager.exe
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\RESURRECTiON.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT\midnight.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\adobelm.dll
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\lisezmoi.txt
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\tw10122.dat

1 - "C:\ToolBar SD\TB_1.txt" - 27/12/2008|19:58 - Option : [1]

-----------\\ Fin du rapport a 19:58:42,82
0
phi60420 Messages postés 169 Statut Membre 1
 
bonjour et merci de t'interressé a mon probleme voila le rapport que tu as demandé

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2500+ )
BIOS : Version 07.00T
USER : @ ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
Firewall : COMODO Firewall Pro 2.3.035 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:9 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 27/12/2008|19:57 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\AskSBar
C:\Program Files\AskSBar\bar
C:\Program Files\AskSBar\SrchAstt
C:\Program Files\AskSBar\bar\1.bin
C:\Program Files\AskSBar\bar\Cache
C:\Program Files\AskSBar\bar\History
C:\Program Files\AskSBar\bar\Settings
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2HIGHIN.EXE
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2PLUGIN.DLL
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
C:\Program Files\AskSBar\bar\1.bin\NPASKSBR.DLL
C:\Program Files\AskSBar\bar\1.bin\V2RSSMNU.DLL
C:\Program Files\AskSBar\bar\Cache\000FF11D
C:\Program Files\AskSBar\bar\Cache\04C39D11.bin
C:\Program Files\AskSBar\bar\Cache\04C3A455.bin
C:\Program Files\AskSBar\bar\Cache\04C3A927.bin
C:\Program Files\AskSBar\bar\Cache\04C3AE09.bin
C:\Program Files\AskSBar\bar\Cache\04C7A849.bin
C:\Program Files\AskSBar\bar\Cache\04C7B1BF.bin
C:\Program Files\AskSBar\bar\Cache\files.ini
C:\Program Files\AskSBar\bar\History\search2
C:\Program Files\AskSBar\bar\Settings\prevcfg2.htm
C:\Program Files\AskSBar\SrchAstt\1.bin
C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
C:\DOCUME~1\@\APPLIC~1\Dealio
C:\Program Files\KaZaA
C:\Program Files\KaZaA\bdupd.dll
C:\Program Files\KaZaA\broadband.gif
C:\Program Files\KaZaA\broadband2.gif
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\Help
C:\Program Files\KaZaA\kazaa.exe
C:\Program Files\KaZaA\Kazaa.url
C:\Program Files\KaZaA\kzscan.dll
C:\Program Files\KaZaA\linksfolder.ico
C:\Program Files\KaZaA\magnet.exe
C:\Program Files\KaZaA\My Channels
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\plugins
C:\Program Files\KaZaA\plugins.htm
C:\Program Files\KaZaA\Promotions
C:\Program Files\KaZaA\Skins
C:\Program Files\KaZaA\Thumbs.db
C:\Program Files\KaZaA\versions.dat
C:\Program Files\KaZaA\Db\4ova-050129.cab
C:\Program Files\KaZaA\Db\bb.db
C:\Program Files\KaZaA\Db\bb2.db
C:\Program Files\KaZaA\Db\ctx4-040126.cab
C:\Program Files\KaZaA\Db\ctx4-040413b.cab
C:\Program Files\KaZaA\Db\ctx4-041108.cab
C:\Program Files\KaZaA\Db\ctx4-041111.cab
C:\Program Files\KaZaA\Db\ctx4-041223.cab
C:\Program Files\KaZaA\Db\ctx4-050118b.cab
C:\Program Files\KaZaA\Db\ctx4-060124.cab
C:\Program Files\KaZaA\Db\ctx4-060422.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\gr_@.current
C:\Program Files\KaZaA\Db\gr_@.previous
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\ova4-060412.cab
C:\Program Files\KaZaA\Db\str040112.cab
C:\Program Files\KaZaA\Db\tsi4-040126.cab
C:\Program Files\KaZaA\Db\tsi4-040413b.cab
C:\Program Files\KaZaA\Db\tsi4-041101a.cab
C:\Program Files\KaZaA\Db\tsi4-041101b.cab
C:\Program Files\KaZaA\Db\tsi4-041115.cab
C:\Program Files\KaZaA\Db\tsi4-041116.cab
C:\Program Files\KaZaA\Db\tsi4-041221a.cab
C:\Program Files\KaZaA\Db\tsi4-041221b.cab
C:\Program Files\KaZaA\Db\tsi4-050107a.cab
C:\Program Files\KaZaA\Db\tsi4-050107b.cab
C:\Program Files\KaZaA\Db\tsi4-060404a.cab
C:\Program Files\KaZaA\Db\tsi4-060404b.cab
C:\Program Files\KaZaA\Db\tsi4-060422b.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\KaZaA\Help\arrow.gif
C:\Program Files\KaZaA\Help\arrow_sml.gif
C:\Program Files\KaZaA\Help\background.gif
C:\Program Files\KaZaA\Help\h_mykazaa.gif
C:\Program Files\KaZaA\Help\h_myMedia.gif
C:\Program Files\KaZaA\Help\h_myplaylists.gif
C:\Program Files\KaZaA\Help\icon_gold_kap.gif
C:\Program Files\KaZaA\Help\myKapsules.gif
C:\Program Files\KaZaA\Help\mykapsules.htm
C:\Program Files\KaZaA\Help\mykazaa.css
C:\Program Files\KaZaA\Help\mykazaa.htm
C:\Program Files\KaZaA\Help\mymedia.htm
C:\Program Files\KaZaA\Help\myplaylists.htm
C:\Program Files\KaZaA\Help\spacer.gif
C:\Program Files\KaZaA\Help\Thumbs.db
C:\Program Files\KaZaA\My Channels\Bin
C:\Program Files\KaZaA\My Channels\Images
C:\Program Files\KaZaA\My Channels\Bin\dating.kcd
C:\Program Files\KaZaA\My Channels\Bin\emerging_artists.kcd
C:\Program Files\KaZaA\My Channels\Bin\g_spot.kcd
C:\Program Files\KaZaA\My Channels\Bin\onelove_browse.kcd
C:\Program Files\KaZaA\My Channels\Bin\ringtonechannel.kcd
C:\Program Files\KaZaA\My Channels\Bin\rshiphop.kcd
C:\Program Files\KaZaA\My Channels\Bin\skilledgames.kcd
C:\Program Files\KaZaA\My Channels\Images\dating.bmp
C:\Program Files\KaZaA\My Channels\Images\emerging_artists.bmp
C:\Program Files\KaZaA\My Channels\Images\g_spot.bmp
C:\Program Files\KaZaA\My Channels\Images\onelove_browse.bmp
C:\Program Files\KaZaA\My Channels\Images\ringtonechannel.bmp
C:\Program Files\KaZaA\My Channels\Images\rshiphop_browse.bmp
C:\Program Files\KaZaA\My Channels\Images\skilledgames.bmp
C:\Program Files\KaZaA\My Channels\Images\Thumbs.db
C:\Program Files\KaZaA\My Shared Folder\Audio - Alternatie Rock.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Alternative Rock.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Barrington Levy.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Electronica.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Fine Arts Militia Album.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Folk.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Funk.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Hip Hop.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Jazz.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Pop Rock.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Public Enemy Revolverlution Album.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - R&B.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Reggae.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - The Honey Palace Album.kpl
C:\Program Files\KaZaA\My Shared Folder\Electronica - Emerging Artists.kpl
C:\Program Files\KaZaA\My Shared Folder\Funk - Emerging Artists.kpl
C:\Program Files\KaZaA\My Shared Folder\Hip-Hop - Emerging Artists.kpl
C:\Program Files\KaZaA\My Shared Folder\kazaa267_fr.exe
C:\Program Files\KaZaA\My Shared Folder\kmd260_en.exe
C:\Program Files\KaZaA\My Shared Folder\kmd263_fr.exe
C:\Program Files\KaZaA\My Shared Folder\Pop Rock - Emerging Artists.kpl
C:\Program Files\KaZaA\My Shared Folder\R&B - Emerging Artists.kpl
C:\Program Files\KaZaA\plugins\ace.xmd
C:\Program Files\KaZaA\plugins\alz.xmd
C:\Program Files\KaZaA\plugins\arc.xmd
C:\Program Files\KaZaA\plugins\arj.xmd
C:\Program Files\KaZaA\plugins\bach.xmd
C:\Program Files\KaZaA\plugins\bzip2.xmd
C:\Program Files\KaZaA\plugins\cab.xmd
C:\Program Files\KaZaA\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\plugins\ceva_dll.cvd
C:\Program Files\KaZaA\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\plugins\chm.xmd
C:\Program Files\KaZaA\plugins\cpio.xmd
C:\Program Files\KaZaA\plugins\cran.cvd
C:\Program Files\KaZaA\plugins\cran.xmd
C:\Program Files\KaZaA\plugins\dbx.xmd
C:\Program Files\KaZaA\plugins\docfile.xmd
C:\Program Files\KaZaA\plugins\emalware.cvd
C:\Program Files\KaZaA\plugins\emalware.ivd
C:\Program Files\KaZaA\plugins\emalware.xmd
C:\Program Files\KaZaA\plugins\epoc.xmd
C:\Program Files\KaZaA\plugins\gzip.xmd
C:\Program Files\KaZaA\plugins\ha.xmd
C:\Program Files\KaZaA\plugins\hlp.xmd
C:\Program Files\KaZaA\plugins\hpe.cvd
C:\Program Files\KaZaA\plugins\hpe.xmd
C:\Program Files\KaZaA\plugins\hqx.xmd
C:\Program Files\KaZaA\plugins\html.xmd
C:\Program Files\KaZaA\plugins\imp.xmd
C:\Program Files\KaZaA\plugins\inno.xmd
C:\Program Files\KaZaA\plugins\instyler.xmd
C:\Program Files\KaZaA\plugins\iso.xmd
C:\Program Files\KaZaA\plugins\java.cvd
C:\Program Files\KaZaA\plugins\java.xmd
C:\Program Files\KaZaA\plugins\jpeg.xmd
C:\Program Files\KaZaA\plugins\lha.xmd
C:\Program Files\KaZaA\plugins\lnk.xmd
C:\Program Files\KaZaA\plugins\mbox.xmd
C:\Program Files\KaZaA\plugins\mbx.xmd
C:\Program Files\KaZaA\plugins\mdx.xmd
C:\Program Files\KaZaA\plugins\mdx_97.cvd
C:\Program Files\KaZaA\plugins\mdx_97.ivd
C:\Program Files\KaZaA\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\plugins\mime.xmd
C:\Program Files\KaZaA\plugins\mso.xmd
C:\Program Files\KaZaA\plugins\na.cvd
C:\Program Files\KaZaA\plugins\na.xmd
C:\Program Files\KaZaA\plugins\nelf.cvd
C:\Program Files\KaZaA\plugins\nelf.xmd
C:\Program Files\KaZaA\plugins\nsis.xmd
C:\Program Files\KaZaA\plugins\objd.xmd
C:\Program Files\KaZaA\plugins\pdf.xmd
C:\Program Files\KaZaA\plugins\pst.xmd
C:\Program Files\KaZaA\plugins\rar.xmd
C:\Program Files\KaZaA\plugins\rpm.xmd
C:\Program Files\KaZaA\plugins\rtf.xmd
C:\Program Files\KaZaA\plugins\rup.cvd
C:\Program Files\KaZaA\plugins\rup.xmd
C:\Program Files\KaZaA\plugins\sdx.cvd
C:\Program Files\KaZaA\plugins\sdx.ivd
C:\Program Files\KaZaA\plugins\sdx.xmd
C:\Program Files\KaZaA\plugins\sfx.xmd
C:\Program Files\KaZaA\plugins\swf.xmd
C:\Program Files\KaZaA\plugins\tar.xmd
C:\Program Files\KaZaA\plugins\td0.xmd
C:\Program Files\KaZaA\plugins\thebat.xmd
C:\Program Files\KaZaA\plugins\tnef.xmd
C:\Program Files\KaZaA\plugins\unpack.cvd
C:\Program Files\KaZaA\plugins\unpack.ivd
C:\Program Files\KaZaA\plugins\unpack.xmd
C:\Program Files\KaZaA\plugins\update.txt
C:\Program Files\KaZaA\plugins\uudecode.xmd
C:\Program Files\KaZaA\plugins\ve.cvd
C:\Program Files\KaZaA\plugins\ve.ivd
C:\Program Files\KaZaA\plugins\ve.xmd
C:\Program Files\KaZaA\plugins\vedata.cvd
C:\Program Files\KaZaA\plugins\viza.xmd
C:\Program Files\KaZaA\plugins\wise.xmd
C:\Program Files\KaZaA\plugins\xishield.xmd
C:\Program Files\KaZaA\plugins\z.xmd
C:\Program Files\KaZaA\plugins\zip.xmd
C:\Program Files\KaZaA\plugins\zoo.xmd
C:\Program Files\KaZaA\Promotions\DirectTV.url
C:\Program Files\KaZaA\Promotions\Kazaa Shop.url
C:\Program Files\KaZaA\Promotions\Netflix.url
C:\Program Files\KaZaA\Promotions\readme.lnk
C:\Program Files\KaZaA\Skins\Ceramic Biscuit
C:\Program Files\KaZaA\Skins\Orbital Shadows
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_search.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_search_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_search_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_search_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_shop.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_shop_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_shop_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_shop_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_start.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_start_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_start_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_start_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_tell.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_tell_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_tell_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_tell_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_theatre.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_theatre_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_theatre_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_theatre_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_traffic.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_traffic_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_traffic_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mainbar_traffic_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_addtoplay.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_addtoplay_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_addtoplay_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_addtoplay_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_next.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_next_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_next_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_next_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_pause.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_play.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_play_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_play_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_play_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_prev.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_prev_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_prev_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_prev_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_slider.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_sliderThumb.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_sliderThumb_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_stop.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_volume.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_volume_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_volume_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\mediabar_volume_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_download.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_download_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_download_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_download_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_messageuser.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_messageuser_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_messageuser_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_messageuser_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_newsearch.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_newsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_newsearch_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_newsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_searchuser.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_searchuser_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_searchuser_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_searchuser_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_showsearch.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_showsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_showsearch_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\searchbar_showsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\skin.xml
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_back.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_back_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_back_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_back_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_fwd.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_fwd_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_fwd_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_fwd_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_home.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_home_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_home_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_home_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_refresh.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_refresh_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_refresh_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_refresh_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_stop.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\startbar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\theatrebar_fullscreen.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\theatrebar_fullscreen_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\theatrebar_fullscreen_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\theatrebar_fullscreen_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\Thumbs.db
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_cancel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_cancel_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_cancel_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_cancel_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_pause.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_resume.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_resume_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_resume_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\trafficbar_resume_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_close.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_close_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_close_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_close_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_maximise.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_maximise_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_maximise_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_maximise_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_minimise.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_minimise_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_minimise_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_minimise_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_restore.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_restore_dis.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_restore_over.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\windowbar_restore_sel.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_btm.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_btmLeft.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_btmright.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_left.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_right.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_top.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_topleft.bmp
C:\Program Files\KaZaA\Skins\Ceramic Biscuit\window_topright.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\License.txt
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_peer.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_peer_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_peer_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_peer_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_search.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_search_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_search_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_search_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_shop.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_shop_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_shop_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_shop_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_tell.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_tell_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_tell_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_tell_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_theater.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_theater_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_theater_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_theater_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_traffic.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_traffic_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_traffic_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_traffic_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_web.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_web_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_web_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mainbar_web_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_addtoplay.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_addtoplay_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_addtoplay_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_addtoplay_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_next.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_next_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_next_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_next_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_pause.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_play.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_play_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_play_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_play_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_prev.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_prev_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_prev_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_prev_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_slider.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_sliderThumb.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_sliderThumb_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_stop.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_volume.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_volume_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_volume_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\mediabar_volume_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_closetab.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_closetab_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_closetab_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_closetab_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_download.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_download_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_download_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_download_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_messageuser.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_messageuser_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_messageuser_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_messageuser_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_newsearch.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_newsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_newsearch_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_newsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_searchuser.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_searchuser_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_searchuser_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_searchuser_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_showsearch.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_showsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_showsearch_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\searchbar_showsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\skin.xml
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_back.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_back_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_back_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_back_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_fwd.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_fwd_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_fwd_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_fwd_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_home.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_home_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_home_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_home_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_refresh.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_refresh_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_refresh_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_refresh_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_stop.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\startbar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\theatrebar_fullscreen.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\theatrebar_fullscreen_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\theatrebar_fullscreen_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\theatrebar_fullscreen_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\Thumbs.db
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_cancel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_cancel_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_cancel_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_cancel_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_pause.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_resume.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_resume_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_resume_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\trafficbar_resume_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_close.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_close_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_close_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_close_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_maximise.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_maximise_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_maximise_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_maximise_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_minimise.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_minimise_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_minimise_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_minimise_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_restore.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_restore_dis.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_restore_over.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\windowbar_restore_sel.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_btm.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_btmLeft.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_btmright.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_left.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_right.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_top.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_topleft.bmp
C:\Program Files\KaZaA\Skins\Orbital Shadows\window_topright.bmp
C:\DOCUME~1\@\Bureau\Torrent Search Fichiers récents.url
C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll

-----------\\ Extensions

(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.sfr.fr/"
"Search Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2fbr%2faccess%2fallinone.asp%3f"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr"
"Search Bar"="about:blank"
"default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mdf
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\SH3.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\A LIRE ABSOLUMENT !!!.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1\Architecte3D.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2\Architecte3D_CD2.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\batpro1_100.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\KEYGEN.EXE
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\Serial.txt
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\- CRACK EUROBARRE v1.4.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\1 ETAPE grace au crack v1.4 gagner plus READ ME.doc
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\crack pour Eurobarre.reg
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00.zip
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\Deutsch AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\US AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\programe\Crack
C:\DOCUME~1\@\Mes documents\programe\Crack\AVS.Audio.Tools.v3.5.1.160-RES-crk.rar
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\licence.reg
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\Manager.exe
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\RESURRECTiON.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT\midnight.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\adobelm.dll
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\lisezmoi.txt
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\tw10122.dat

1 - "C:\ToolBar SD\TB_1.txt" - 27/12/2008|19:58 - Option : [1]

-----------\\ Fin du rapport a 19:58:42,82
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
relance tollbarsd
et choisi option 2
post le rapport ici
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
ensuite
tu passeras smitfraufix et tu poste le rapport,Merci

Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php

le mieux serait que tu désaxctives tes protections résidente "anti-virus et anti-spyware" le temps d'installer smitfraudfix et de faire l'analyse.

et télécharge SmitfraudFix.exe.

Regarde le tuto

Exécute le en choisissant l’option 1
il va générer un rapport

Copie/colle le sur le poste stp.

Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus, ect...) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

une petites démo en vidéo :http://pagesperso-orange.fr/rginformatique/section%20virus/smitfraudfix.htm
0
phi60420 Messages postés 169 Statut Membre 1
 
bonjour je joint les deux rapport que tu as demandé

rapport toolbarsd

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2500+ )
BIOS : Version 07.00T
USER : @ ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
Firewall : COMODO Firewall Pro 2.3.035 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:9 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 28/12/2008|10:45 )

-----------\\ SUPPRESSION

Echec ! - C:\Program Files\AskSBar\bar
Echec ! - C:\Program Files\AskSBar\SrchAstt
Echec ! - C:\Program Files\AskSBar\bar\1.bin
Echec ! - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
Echec ! - C:\Program Files\AskSBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
Supprime! - C:\Program Files\KaZaA\bdupd.dll
Supprime! - C:\Program Files\KaZaA\broadband.gif
Supprime! - C:\Program Files\KaZaA\broadband2.gif
Supprime! - C:\Program Files\KaZaA\Db
Supprime! - C:\Program Files\KaZaA\Help
Supprime! - C:\Program Files\KaZaA\kazaa.exe
Supprime! - C:\Program Files\KaZaA\Kazaa.url
Supprime! - C:\Program Files\KaZaA\kzscan.dll
Supprime! - C:\Program Files\KaZaA\linksfolder.ico
Supprime! - C:\Program Files\KaZaA\magnet.exe
Supprime! - C:\Program Files\KaZaA\My Channels
Supprime! - C:\Program Files\KaZaA\My Shared Folder
Supprime! - C:\Program Files\KaZaA\plugins
Supprime! - C:\Program Files\KaZaA\plugins.htm
Supprime! - C:\Program Files\KaZaA\Promotions
Supprime! - C:\Program Files\KaZaA\Skins
Supprime! - C:\Program Files\KaZaA\Thumbs.db
Supprime! - C:\Program Files\KaZaA\versions.dat
Supprime! - C:\DOCUME~1\@\Bureau\Torrent Search Fichiers récents.url
Supprime! - C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
Echec ! - C:\Program Files\AskSBar
Supprime! - C:\DOCUME~1\@\APPLIC~1\Dealio
Supprime! - C:\Program Files\KaZaA

-----------\\ DEUXIEME PASSAGE

Echec ! - C:\Program Files\AskSBar\bar
Echec ! - C:\Program Files\AskSBar\SrchAstt
Echec ! - C:\Program Files\AskSBar\bar\1.bin
Echec ! - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
Echec ! - C:\Program Files\AskSBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
Echec ! - C:\Program Files\AskSBar

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\AskSBar
C:\Program Files\AskSBar\bar
C:\Program Files\AskSBar\SrchAstt
C:\Program Files\AskSBar\bar\1.bin
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
C:\Program Files\AskSBar\SrchAstt\1.bin
C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

-----------\\ Extensions

(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.sfr.fr/"
"Search Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2fbr%2faccess%2fallinone.asp%3f"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"
"Search Bar"="about:blank"
"default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mdf
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\SH3.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\A LIRE ABSOLUMENT !!!.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1\Architecte3D.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2\Architecte3D_CD2.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\batpro1_100.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\KEYGEN.EXE
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\Serial.txt
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\- CRACK EUROBARRE v1.4.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\1 ETAPE grace au crack v1.4 gagner plus READ ME.doc
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\crack pour Eurobarre.reg
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00.zip
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\Deutsch AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\US AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\programe\Crack
C:\DOCUME~1\@\Mes documents\programe\Crack\AVS.Audio.Tools.v3.5.1.160-RES-crk.rar
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\licence.reg
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\Manager.exe
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\RESURRECTiON.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT\midnight.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\adobelm.dll
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\lisezmoi.txt
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\tw10122.dat

1 - "C:\ToolBar SD\TB_1.txt" - 27/12/2008|19:58 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 28/12/2008|10:48 - Option : [2]

-----------\\ Fin du rapport a 10:48:48,39

SmitFraudFix v2.387

Rapport fait à 10:58:57,21, 28/12/2008
Executé à partir de C:\Documents and Settings\@\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\rmctrl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\@\Bureau\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

»»»»»»»»»»»»»»»»»»»»»»»» C:\

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\@

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\@\LOCALS~1\Temp

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\@\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\@\Favoris

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\Google\googletoolbar1.dll PRESENT !

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"

»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» RK

»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: MSI/Broadcom 440x 10/100 Integrated Controller - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.30.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{5B142AD3-E471-46A9-8BCB-B61710FE7341}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8AF3AB1D-5EFC-4845-BFDC-0145E0A7E9C2}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CCS\Services\Tcpip\..\{CD425DEC-7419-4234-B20F-7DA61636C73D}: NameServer=192.168.30.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{5B142AD3-E471-46A9-8BCB-B61710FE7341}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8AF3AB1D-5EFC-4845-BFDC-0145E0A7E9C2}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS1\Services\Tcpip\..\{CD425DEC-7419-4234-B20F-7DA61636C73D}: NameServer=192.168.30.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{5B142AD3-E471-46A9-8BCB-B61710FE7341}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS2\Services\Tcpip\..\{8AF3AB1D-5EFC-4845-BFDC-0145E0A7E9C2}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS2\Services\Tcpip\..\{CD425DEC-7419-4234-B20F-7DA61636C73D}: NameServer=192.168.30.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{07B94BC6-FD64-44B1-B046-5E2594B6545C}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS3\Services\Tcpip\..\{CAAF31B3-C276-45C0-A309-4AC1A450913A}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

»»»»»»»»»»»»»»»»»»»»»»»» Fin
0
phi60420 Messages postés 169 Statut Membre 1
 
bonjour je joint les deux rapport que tu as demandé

rapport toolbarsd

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2500+ )
BIOS : Version 07.00T
USER : @ ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
Firewall : COMODO Firewall Pro 2.3.035 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:9 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 28/12/2008|10:45 )

-----------\\ SUPPRESSION

Echec ! - C:\Program Files\AskSBar\bar
Echec ! - C:\Program Files\AskSBar\SrchAstt
Echec ! - C:\Program Files\AskSBar\bar\1.bin
Echec ! - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
Echec ! - C:\Program Files\AskSBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
Supprime! - C:\Program Files\KaZaA\bdupd.dll
Supprime! - C:\Program Files\KaZaA\broadband.gif
Supprime! - C:\Program Files\KaZaA\broadband2.gif
Supprime! - C:\Program Files\KaZaA\Db
Supprime! - C:\Program Files\KaZaA\Help
Supprime! - C:\Program Files\KaZaA\kazaa.exe
Supprime! - C:\Program Files\KaZaA\Kazaa.url
Supprime! - C:\Program Files\KaZaA\kzscan.dll
Supprime! - C:\Program Files\KaZaA\linksfolder.ico
Supprime! - C:\Program Files\KaZaA\magnet.exe
Supprime! - C:\Program Files\KaZaA\My Channels
Supprime! - C:\Program Files\KaZaA\My Shared Folder
Supprime! - C:\Program Files\KaZaA\plugins
Supprime! - C:\Program Files\KaZaA\plugins.htm
Supprime! - C:\Program Files\KaZaA\Promotions
Supprime! - C:\Program Files\KaZaA\Skins
Supprime! - C:\Program Files\KaZaA\Thumbs.db
Supprime! - C:\Program Files\KaZaA\versions.dat
Supprime! - C:\DOCUME~1\@\Bureau\Torrent Search Fichiers récents.url
Supprime! - C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
Echec ! - C:\Program Files\AskSBar
Supprime! - C:\DOCUME~1\@\APPLIC~1\Dealio
Supprime! - C:\Program Files\KaZaA

-----------\\ DEUXIEME PASSAGE

Echec ! - C:\Program Files\AskSBar\bar
Echec ! - C:\Program Files\AskSBar\SrchAstt
Echec ! - C:\Program Files\AskSBar\bar\1.bin
Echec ! - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
Echec ! - C:\Program Files\AskSBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
Echec ! - C:\Program Files\AskSBar

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\AskSBar
C:\Program Files\AskSBar\bar
C:\Program Files\AskSBar\SrchAstt
C:\Program Files\AskSBar\bar\1.bin
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
C:\Program Files\AskSBar\SrchAstt\1.bin
C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

-----------\\ Extensions

(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.sfr.fr/"
"Search Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2fbr%2faccess%2fallinone.asp%3f"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"
"Search Bar"="about:blank"
"default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mdf
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\SH3.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\A LIRE ABSOLUMENT !!!.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1\Architecte3D.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2\Architecte3D_CD2.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\batpro1_100.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\KEYGEN.EXE
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\Serial.txt
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\- CRACK EUROBARRE v1.4.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\1 ETAPE grace au crack v1.4 gagner plus READ ME.doc
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\crack pour Eurobarre.reg
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00.zip
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\Deutsch AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\US AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\programe\Crack
C:\DOCUME~1\@\Mes documents\programe\Crack\AVS.Audio.Tools.v3.5.1.160-RES-crk.rar
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\licence.reg
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\Manager.exe
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\RESURRECTiON.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT\midnight.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\adobelm.dll
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\lisezmoi.txt
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\tw10122.dat

1 - "C:\ToolBar SD\TB_1.txt" - 27/12/2008|19:58 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 28/12/2008|10:48 - Option : [2]

-----------\\ Fin du rapport a 10:48:48,39

SmitFraudFix v2.387

Rapport fait à 10:58:57,21, 28/12/2008
Executé à partir de C:\Documents and Settings\@\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\rmctrl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\@\Bureau\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

»»»»»»»»»»»»»»»»»»»»»»»» C:\

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\@

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\@\LOCALS~1\Temp

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\@\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\@\Favoris

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\Google\googletoolbar1.dll PRESENT !

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"

»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» RK

»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: MSI/Broadcom 440x 10/100 Integrated Controller - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.30.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{5B142AD3-E471-46A9-8BCB-B61710FE7341}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8AF3AB1D-5EFC-4845-BFDC-0145E0A7E9C2}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CCS\Services\Tcpip\..\{CD425DEC-7419-4234-B20F-7DA61636C73D}: NameServer=192.168.30.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{5B142AD3-E471-46A9-8BCB-B61710FE7341}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8AF3AB1D-5EFC-4845-BFDC-0145E0A7E9C2}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS1\Services\Tcpip\..\{CD425DEC-7419-4234-B20F-7DA61636C73D}: NameServer=192.168.30.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{5B142AD3-E471-46A9-8BCB-B61710FE7341}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS2\Services\Tcpip\..\{8AF3AB1D-5EFC-4845-BFDC-0145E0A7E9C2}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS2\Services\Tcpip\..\{CD425DEC-7419-4234-B20F-7DA61636C73D}: NameServer=192.168.30.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{07B94BC6-FD64-44B1-B046-5E2594B6545C}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS3\Services\Tcpip\..\{CAAF31B3-C276-45C0-A309-4AC1A450913A}: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

»»»»»»»»»»»»»»»»»»»»»»»» Fin
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
post un nouvel hijackthis svp
0
phi60420 Messages postés 169 Statut Membre 1
 
re voila le nouveau rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:41:18, on 28/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\rmctrl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AOLSAV] C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo RX560 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S266.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series sur PC-DE-THOMAS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S29.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [\\Pc-de-thomas\EPSON Stylus Photo RX560 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\DOCUME~1\@\LOCALS~1\Temp\E_S5.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series sur PC-DE-LAETITIA] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S20.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [\\Pc-de-laetitia\EPSON Stylus Photo RX560 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\DOCUME~1\@\LOCALS~1\Temp\E_S9.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [\\Pc-de-laetitia\EPSON Stylus Photo RX560 Series (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\DOCUME~1\@\LOCALS~1\Temp\E_SC.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series sur Pc-de-laetitia (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_SF.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series (Copie 3) sur Pc-de-laetitia (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S12.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series (Copie 1) sur PC-DE-LAETITIA] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_SB.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series sur Pc-de-laetitia (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_SE.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX560 Series (Copie 2) sur PC-DE-LAETITIA] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINDOWS\TEMP\E_S7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?70696ede427d4ba48f69a98de8f48e7e
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?70696ede427d4ba48f69a98de8f48e7e
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O9 - Extra button: Capturer ! - {47055D63-DFCD-11d3-8406-00500445A7D0} - C:\Program Files\Goto\MemoWeb 4\IEBtn\Launcher (file missing)
O9 - Extra 'Tools' menuitem: Capturer ce web - {47055D63-DFCD-11d3-8406-00500445A7D0} - C:\Program Files\Goto\MemoWeb 4\IEBtn\Launcher (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.fr/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.fr.aol.com/molbin/shared/mcinsctl/fr/4,0,0,84/mcinsctl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {981D847D-2C06-4FB7-A09C-4F0A48601B2C} (DiagSetup Class) - http://techcity.aol.fr/download/img/DiagSetup.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.fr.aol.com/molbin/shared/mcgdmgr/fr/1,0,0,21/mcgdmgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CD425DEC-7419-4234-B20F-7DA61636C73D}: NameServer = 192.168.30.1
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

. sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
. enregistres le sur le bureau
. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
. si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
. Une fois la mise à jour terminée,fermes Malwarebytes
. redemarres en mode sans échec pour savoir comment au cas ou tu ne saurrais pas regarde plus bas
. une fois en mode sans echec tu double-cliques sur l'icône de malwarebytes
. une fois ouvert rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, cliques sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés)

. cliques sur Supprimer la sélection

. Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. redemarre le pc
. une fois redémarré en mode normal double-cliques sur malwarebytes
. rends toi dans l'onglet rapport/log
. tu cliques dessus pour l'afficher une fois affiché
. tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
. tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller

Si tu as besoin d'aide regarde ces tutoriels :
https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

(attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)
passe une 1 ere fois en mode normal puis essai le mode sans echec
0
phi60420 Messages postés 169 Statut Membre 1
 
re impossible de redemaree en mode sans echec
0
Utilisateur anonyme
 
Salut!!

Tu peux passer Malwarebytes en normal, pas de soucis!

A++
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
passe une 1 ere fois en mode normal puis essai le mode sans echec
deja marqué post 11
post le raport du mode normal svp
0
phi60420 Messages postés 169 Statut Membre 1
 
voila il me marque ca verification du systeme de fichier sur C.
le type de systeme de fichier est NTFS
L'integrite de l'un de vos disque doit etre verifier CHKDSK est en train de verifier les fichjers j'ai remis le CD installe xp et jai pu ouvrir en mode sans echec jai ouvert Malwarebytes et des que le rapport est pres je te l'envoi
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
super
0
phi60420 Messages postés 169 Statut Membre 1
 
re voila enfin le rapportMalwarebytes' Anti-Malware 1.31
Version de la base de données: 1456
Windows 5.1.2600 Service Pack 3

28/12/2008 18:35:44
mbam-log-2008-12-28 (18-35-44).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 128416
Temps écoulé: 2 hour(s), 13 minute(s), 1 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 24
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\torrentmanager.webmanager (Trojan.Lop) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\torrentmanager.webmanager.1 (Trojan.Lop) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df1c8e21-4045-4d67-b528-335f1a4f0de9} (Adware.Navipromo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{32341e7e-c319-46de-91d0-e30bb1a3caba} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b4a78d29-52b1-4a7b-bac0-1471bedf9836} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04f414e9-e352-4bc3-963d-7bfe5a5f31a9} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07c9cfc7-de33-4a0c-9ffb-cdfba843b157} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0878f049-d33e-45e0-a157-c36a6683cf25} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3616f4b5-f6ad-4e67-966a-c218673648a0} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5f4d3335-3194-4167-85ae-e7325f2695ef} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{87c1805d-c5ae-4455-ab39-e245bb516136} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{95460abd-946a-46ff-9f56-268718323eee} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cb5d474e-a510-40a4-b5a4-838933bcba64} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e114cd5b-17ce-4807-890e-7b1edf9f2e5e} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e19ab99f-aec4-4b40-a5ca-f69d22522d77} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e7ae1661-ebeb-492b-ae0d-860df24174c6} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ec4afbf3-4540-4306-af10-4cac509ea16b} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fa1d6d8f-c6ed-4752-8512-a33283240130} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fbf65a16-c9ab-465e-aece-d2d9d5ab5e60} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d5792aa9-d373-4039-8670-2cdab6a71f15} (Trojan.Lop) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\BitDownload (Trojan.Lop) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550p (Rootkit.Agent) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

▶ Double-clique dessus pour lancer l'installation

▶ Puis double-clique sur le raccourci Lop S&D présent sur ton bureau

▶ Séléctionne la langue souhaitée

▶ Puis choisis l'Option 1 ( Recherche )

▶ Patiente jusqu'à la fin du scan

▶ Poste le rapport généré ( C:lopR.txt )
0
phi60420 Messages postés 169 Statut Membre 1
 
voila le rapport

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2500+ )
BIOS : Version 07.00T
USER : @ ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
Firewall : COMODO Firewall Pro 2.3.035 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:9 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 28/12/2008|19:19 )

--------------------\\ Listing des dossiers dans APPLIC~1

[19/05/2008|10:55] C:\DOCUME~1\@\APPLIC~1\@
[04/12/2008|18:30] C:\DOCUME~1\@\APPLIC~1\Adobe
[08/05/2008|15:41] C:\DOCUME~1\@\APPLIC~1\AdobeUM
[01/06/2004|19:18] C:\DOCUME~1\@\APPLIC~1\AOL
[03/05/2008|11:54] C:\DOCUME~1\@\APPLIC~1\Application Data
[22/12/2003|22:35] C:\DOCUME~1\@\APPLIC~1\Arcsoft
[23/12/2008|17:22] C:\DOCUME~1\@\APPLIC~1\AVS4YOU
[26/06/2008|17:12] C:\DOCUME~1\@\APPLIC~1\Azureus
[14/02/2007|14:22] C:\DOCUME~1\@\APPLIC~1\BitDownload
[04/12/2008|18:23] C:\DOCUME~1\@\APPLIC~1\Canneverbe_Limited
[15/12/2006|09:59] C:\DOCUME~1\@\APPLIC~1\Canon
[16/07/2008|20:52] C:\DOCUME~1\@\APPLIC~1\Comodo
[22/12/2003|18:38] C:\DOCUME~1\@\APPLIC~1\CyberLink
[04/12/2008|22:03] C:\DOCUME~1\@\APPLIC~1\DeepBurner
[11/02/2008|10:18] C:\DOCUME~1\@\APPLIC~1\DivX
[07/09/2004|08:30] C:\DOCUME~1\@\APPLIC~1\DMCache
[23/05/2008|03:55] C:\DOCUME~1\@\APPLIC~1\Documents and Settings
[05/06/2008|17:23] C:\DOCUME~1\@\APPLIC~1\dvdcss
[21/05/2007|17:13] C:\DOCUME~1\@\APPLIC~1\EPSON
[28/06/2008|10:24] C:\DOCUME~1\@\APPLIC~1\GetRightToGo
[04/05/2007|15:36] C:\DOCUME~1\@\APPLIC~1\Google
[22/10/2005|18:42] C:\DOCUME~1\@\APPLIC~1\GTek
[28/12/2006|14:51] C:\DOCUME~1\@\APPLIC~1\Help
[04/01/2004|15:58] C:\DOCUME~1\@\APPLIC~1\Identities
[22/12/2003|17:18] C:\DOCUME~1\@\APPLIC~1\InterTrust
[12/12/2008|18:13] C:\DOCUME~1\@\APPLIC~1\LimeWire
[22/06/2006|17:55] C:\DOCUME~1\@\APPLIC~1\Macromedia
[13/06/2008|15:07] C:\DOCUME~1\@\APPLIC~1\Malwarebytes
[01/03/2008|13:42] C:\DOCUME~1\@\APPLIC~1\Media Player Classic
[18/12/2008|23:09] C:\DOCUME~1\@\APPLIC~1\Microsoft
[07/12/2008|12:59] C:\DOCUME~1\@\APPLIC~1\Mozilla
[26/01/2008|23:15] C:\DOCUME~1\@\APPLIC~1\MP-Manager
[22/01/2005|18:26] C:\DOCUME~1\@\APPLIC~1\MSN6
[28/12/2006|07:41] C:\DOCUME~1\@\APPLIC~1\NetMedia Providers
[28/12/2006|07:41] C:\DOCUME~1\@\APPLIC~1\Publish Providers
[16/06/2008|22:29] C:\DOCUME~1\@\APPLIC~1\Real
[22/12/2003|17:21] C:\DOCUME~1\@\APPLIC~1\ScanSoft
[28/12/2006|07:41] C:\DOCUME~1\@\APPLIC~1\Sony
[03/07/2008|11:37] C:\DOCUME~1\@\APPLIC~1\Sony Corporation
[11/06/2007|19:27] C:\DOCUME~1\@\APPLIC~1\Sun
[13/12/2003|13:48] C:\DOCUME~1\@\APPLIC~1\Symantec
[17/06/2008|07:33] C:\DOCUME~1\@\APPLIC~1\Talkback
[17/04/2004|17:45] C:\DOCUME~1\@\APPLIC~1\Ulead Systems
[17/12/2008|18:53] C:\DOCUME~1\@\APPLIC~1\Uniblue
[13/10/2007|12:08] C:\DOCUME~1\@\APPLIC~1\UPLOADTRUST
[01/03/2008|13:31] C:\DOCUME~1\@\APPLIC~1\vlc
[07/10/2007|10:36] C:\DOCUME~1\@\APPLIC~1\Windows Desktop Search
[01/06/2004|19:16] C:\DOCUME~1\@\APPLIC~1\You've Got Pictures Screensaver

[30/11/2007|08:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[18/12/2008|09:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[24/10/2008|17:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[06/05/2007|10:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
[16/06/2008|21:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[23/12/2008|17:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[26/06/2008|16:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
[16/07/2008|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo
[13/12/2003|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[20/12/2008|16:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EPSON
[13/10/2007|10:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\flag ace stupid data
[23/11/2008|10:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[28/12/2008|18:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[22/10/2005|18:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GTek
[22/12/2008|23:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[20/08/2004|18:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[13/06/2008|15:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[17/06/2008|13:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[12/06/2007|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[18/12/2008|09:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[22/12/2003|18:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[13/10/2007|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\oozereadmedriveknob
[13/12/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Player Metaboli
[22/04/2004|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[22/12/2003|22:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[16/06/2008|22:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[22/12/2003|22:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanAppDataDir
[17/01/2004|12:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanWizard
[19/03/2006|09:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[19/06/2008|17:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[21/08/2007|09:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Two Idol Wave Flag
[27/12/2006|19:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[17/04/2004|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[01/06/2004|19:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[16/08/2006|11:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[26/08/2006|10:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[14/12/2007|19:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[30/11/2007|08:17] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[25/02/2008|16:43] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[25/02/2008|16:43] C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
[14/04/2006|18:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\Macromedia
[22/03/2008|10:34] C:\DOCUME~1\LOCALS~1\APPLIC~1\Media Player Classic
[18/06/2008|06:26] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[10/02/2008|21:58] C:\DOCUME~1\LOCALS~1\APPLIC~1\Real
[13/10/2007|12:08] C:\DOCUME~1\LOCALS~1\APPLIC~1\UPLOADTRUST

[06/10/2007|10:11] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[06/10/2007|10:11] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[25/01/2006|13:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[28/12/2008 19:01][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[28/12/2008 18:38][--a------] C:\WINDOWS\tasks\Symantec NetDetect.job
[28/12/2008 18:38][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[13/12/2003|14:04] C:\Program Files\Adabas
[18/12/2008|09:13] C:\Program Files\Adobe
[13/10/2007|12:08] C:\Program Files\Adverts
[30/06/2008|16:54] C:\Program Files\AGEIA Technologies
[04/12/2008|19:21] C:\Program Files\Ahead
[31/12/2003|09:11] C:\Program Files\Alawar
[09/05/2006|17:47] C:\Program Files\Alcohol Soft
[29/03/2006|11:52] C:\Program Files\Anuman Interactive
[06/05/2007|10:37] C:\Program Files\AOL
[24/10/2008|17:54] C:\Program Files\AOL 9.0
[26/12/2005|19:16] C:\Program Files\AOL 9.0b
[24/10/2008|17:53] C:\Program Files\AOL Compagnon
[24/10/2008|17:52] C:\Program Files\AOL Toolbar
[22/12/2003|17:20] C:\Program Files\ArcSoft
[26/06/2008|16:51] C:\Program Files\AskSBar
[16/12/2008|15:38] C:\Program Files\Astonsoft
[31/10/2008|22:23] C:\Program Files\AtomixMP3
[16/06/2008|21:23] C:\Program Files\Avira
[23/12/2008|17:21] C:\Program Files\AVS4YOU
[22/03/2006|14:54] C:\Program Files\AVSMedia
[26/06/2008|17:13] C:\Program Files\Azureus
[17/03/2007|19:54] C:\Program Files\Boonty
[17/03/2007|19:54] C:\Program Files\BoontyGames
[04/07/2008|07:25] C:\Program Files\Canon
[18/06/2008|06:00] C:\Program Files\CCleaner
[21/12/2006|09:49] C:\Program Files\CDRIPMP3
[13/12/2003|11:23] C:\Program Files\C-Media 3D Audio
[06/06/2008|16:42] C:\Program Files\Codec Pack - All In 1
[16/06/2008|22:01] C:\Program Files\Common Files
[16/07/2008|20:48] C:\Program Files\Comodo
[13/12/2003|10:45] C:\Program Files\ComPlus Applications
[13/12/2003|13:48] C:\Program Files\CyberLink
[28/06/2008|17:34] C:\Program Files\Dactylo
[08/07/2008|02:17] C:\Program Files\data
[29/07/2004|15:17] C:\Program Files\directx
[16/06/2008|22:22] C:\Program Files\DivX
[02/05/2006|18:47] C:\Program Files\Eazel
[01/05/2006|18:04] C:\Program Files\eMule
[05/06/2005|10:17] C:\Program Files\Enigma Software Productions
[27/12/2006|19:10] C:\Program Files\epson
[27/12/2006|19:09] C:\Program Files\EPSON Print CD
[24/10/2008|17:50] C:\Program Files\Fichiers communs
[27/03/2006|11:11] C:\Program Files\Free Audio Pack
[21/06/2008|07:31] C:\Program Files\FYI
[07/08/2005|08:23] C:\Program Files\GameSpy Arcade
[06/04/2005|18:08] C:\Program Files\GOA
[19/06/2008|22:35] C:\Program Files\Google
[17/04/2004|17:32] C:\Program Files\Goto
[13/12/2003|12:02] C:\Program Files\HighMAT CD Writing Wizard
[04/07/2008|07:26] C:\Program Files\Hijackthis Version Fran‡aise
[16/12/2008|15:43] C:\Program Files\InstallShield Installation Information
[04/06/2005|22:56] C:\Program Files\InterActual
[07/09/2004|08:42] C:\Program Files\Internet Download Manager
[12/12/2008|03:16] C:\Program Files\Internet Explorer
[07/12/2008|12:42] C:\Program Files\Java
[12/11/2007|22:51] C:\Program Files\JeCreeMaCuisineAvecLeroyMerlin
[01/03/2008|13:36] C:\Program Files\K-Lite Codec Pack
[17/10/2004|16:01] C:\Program Files\Kodak
[22/12/2008|23:31] C:\Program Files\Lavalys
[17/04/2004|17:30] C:\Program Files\Lavasoft
[01/06/2004|19:16] C:\Program Files\Learn2.com
[12/11/2007|22:56] C:\Program Files\Logitech
[22/12/2008|23:09] C:\Program Files\ma-config.com
[10/07/2007|21:34] C:\Program Files\MaCuisineLapeyre
[13/12/2003|13:46] C:\Program Files\MadOnion.com
[28/12/2008|15:53] C:\Program Files\Malwarebytes' Anti-Malware
[16/08/2008|10:55] C:\Program Files\Messenger
[02/09/2008|21:25] C:\Program Files\Messenger Plus! Live
[24/04/2006|19:39] C:\Program Files\Micro Application
[13/12/2003|10:47] C:\Program Files\microsoft frontpage
[19/12/2008|01:51] C:\Program Files\Microsoft Office
[06/10/2007|10:12] C:\Program Files\Microsoft SQL Server Compact Edition
[20/11/2004|13:49] C:\Program Files\Microsoft.NET
[13/08/2006|13:14] C:\Program Files\MindScape
[25/06/2008|18:46] C:\Program Files\Movie Maker
[27/12/2008|23:22] C:\Program Files\Mozilla Firefox
[26/01/2008|23:06] C:\Program Files\MPMAN
[03/12/2008|22:16] C:\Program Files\MSBuild
[19/12/2008|01:51] C:\Program Files\MSECache
[25/06/2008|18:46] C:\Program Files\msn
[13/12/2003|10:44] C:\Program Files\MSN Gaming Zone
[19/11/2006|03:03] C:\Program Files\MSXML 4.0
[17/10/2005|21:17] C:\Program Files\Multiplication Facts
[17/04/2004|17:37] C:\Program Files\MUSK Codec Pack v4
[03/10/2007|17:32] C:\Program Files\Navman
[25/06/2008|18:42] C:\Program Files\NetMeeting
[18/12/2008|10:23] C:\Program Files\Neuf
[30/12/2003|14:15] C:\Program Files\Nullsoft
[25/06/2008|18:42] C:\Program Files\Outlook Express
[20/03/2006|17:45] C:\Program Files\Oxilog
[29/11/2006|20:09] C:\Program Files\PAN vision
[23/12/2008|14:37] C:\Program Files\Photo Story 3 for Windows
[04/10/2008|10:28] C:\Program Files\Picasa2
[13/12/2008|15:50] C:\Program Files\Player Metaboli
[24/10/2008|17:52] C:\Program Files\QuickTime
[17/03/2006|11:17] C:\Program Files\QuickZip
[24/10/2008|17:51] C:\Program Files\Real
[03/12/2008|22:16] C:\Program Files\Reference Assemblies
[05/04/2005|18:22] C:\Program Files\Rockstar Games
[22/12/2003|17:21] C:\Program Files\ScanSoft
[13/12/2003|10:46] C:\Program Files\Services en ligne
[17/04/2004|16:15] C:\Program Files\Sierra On-Line
[15/03/2008|22:19] C:\Program Files\SimTractor 3.5
[13/12/2003|12:58] C:\Program Files\SiSoftware
[20/03/2006|16:38] C:\Program Files\SLD Codec Pack
[02/07/2008|20:58] C:\Program Files\Sony
[28/12/2006|07:32] C:\Program Files\Sony Setup
[16/06/2008|21:15] C:\Program Files\Spybot - Search & Destroy
[15/12/2007|14:08] C:\Program Files\Starcraft
[12/11/2007|23:00] C:\Program Files\StarOffice6.0
[25/06/2008|22:09] C:\Program Files\Sun
[19/03/2006|09:31] C:\Program Files\Symantec
[07/12/2005|19:10] C:\Program Files\TechCity Solutions
[02/04/2006|19:09] C:\Program Files\Ten Thumbs Typing Tutor 4.1
[22/11/2008|22:21] C:\Program Files\THQ
[27/12/2008|18:46] C:\Program Files\Trend Micro
[10/01/2007|10:29] C:\Program Files\Tropico
[10/01/2007|10:06] C:\Program Files\Ubi Soft
[13/12/2003|11:56] C:\Program Files\Uninstall Information
[05/08/2007|11:24] C:\Program Files\UPLOADTRUST
[01/03/2008|13:25] C:\Program Files\VideoLAN
[30/12/2003|14:15] C:\Program Files\Viewpoint
[08/06/2008|19:19] C:\Program Files\Virtools Web Player 3.5
[26/05/2006|10:22] C:\Program Files\Virtual Magnifying Glass
[22/11/2008|14:46] C:\Program Files\VirtualDJ
[04/12/2008|23:17] C:\Program Files\VirtualDub
[04/12/2008|23:20] C:\Program Files\VirtualDub-1.7.0
[03/05/2004|14:22] C:\Program Files\Webteh
[06/10/2007|10:10] C:\Program Files\Windows Desktop Search
[28/02/2008|03:01] C:\Program Files\Windows Live
[14/12/2008|16:35] C:\Program Files\Windows Live Safety Center
[31/10/2007|03:01] C:\Program Files\Windows Live Toolbar
[03/01/2007|13:04] C:\Program Files\Windows Media Connect 2
[15/11/2008|09:25] C:\Program Files\Windows Media Player
[25/06/2008|18:42] C:\Program Files\Windows NT
[14/08/2004|12:21] C:\Program Files\WindowsUpdate
[16/03/2006|18:56] C:\Program Files\Winfall Publishing
[07/02/2004|11:14] C:\Program Files\WinRAR
[08/03/2005|20:43] C:\Program Files\WinZip
[13/12/2003|10:47] C:\Program Files\xerox
[01/04/2006|06:39] C:\Program Files\Xolox
[03/02/2008|19:12] C:\Program Files\X-OOM
[01/03/2008|13:34] C:\Program Files\XviD
[16/06/2008|22:40] C:\Program Files\Yahoo!

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[24/05/2004|15:57] C:\Program Files\Fichiers communs\Adaptec Shared
[18/12/2008|09:13] C:\Program Files\Fichiers communs\Adobe
[20/08/2004|18:04] C:\Program Files\Fichiers communs\Adobe Systems Shared
[24/10/2008|17:51] C:\Program Files\Fichiers communs\AOL
[01/06/2004|19:17] C:\Program Files\Fichiers communs\aolback
[24/10/2008|17:52] C:\Program Files\Fichiers communs\aolshare
[23/12/2008|17:21] C:\Program Files\Fichiers communs\AVSMedia
[20/11/2004|13:50] C:\Program Files\Fichiers communs\DESIGNER
[05/06/2005|10:34] C:\Program Files\Fichiers communs\DirectX
[01/06/2004|19:58] C:\Program Files\Fichiers communs\fljletdl
[27/12/2006|19:17] C:\Program Files\Fichiers communs\InstallShield
[25/06/2008|22:21] C:\Program Files\Fichiers communs\Java
[17/10/2004|16:02] C:\Program Files\Fichiers communs\KODAK
[17/12/2004|19:26] C:\Program Files\Fichiers communs\Labtec
[23/12/2008|17:20] C:\Program Files\Fichiers communs\Microsoft Shared
[13/12/2003|10:45] C:\Program Files\Fichiers communs\MSSoap
[01/06/2004|19:15] C:\Program Files\Fichiers communs\Nullsoft
[13/12/2003|10:38] C:\Program Files\Fichiers communs\ODBC
[24/10/2008|17:51] C:\Program Files\Fichiers communs\Real
[19/04/2006|06:40] C:\Program Files\Fichiers communs\Scanner
[17/01/2004|12:20] C:\Program Files\Fichiers communs\ScanSoft Shared
[13/12/2003|10:45] C:\Program Files\Fichiers communs\Services
[13/12/2003|10:38] C:\Program Files\Fichiers communs\SpeechEngines
[10/05/2007|06:48] C:\Program Files\Fichiers communs\SWF Studio
[25/06/2008|18:42] C:\Program Files\Fichiers communs\System
[12/12/2007|15:14] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[30/06/2008|16:54] C:\Program Files\Fichiers communs\Wise Installation Wizard

--------------------\\ Process

( 47 Processes )

iexplore.exe ~ [PID:3860]

--------------------\\ Recherche avec S_Lop

C:\DOCUME~1\@\APPLIC~1\UPLOAD~1

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\ALLUSE~1\APPLIC~1\flag ace stupid data
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Two Idol Wave Flag
C:\DOCUME~1\@\APPLIC~1\Bitdownload
C:\Program Files\Adverts
C:\DOCUME~1\@\APPLIC~1\BitDownload
C:\DOCUME~1\@\APPLIC~1\BitDownload\Data
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\BitDownload
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\BitDownload\BitDownload.lnk
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\BitDownload\Uninstall BitDownload.lnk

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Extra up cash]
"DisplayName"="CiD Help"
"UninstallString"="C:\\DOCUME~1\\@\\APPLIC~1\\UPLOAD~1\\Ping Proxy Hold.exe -uninstall"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-28 19:20:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 338

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mdf
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\NEW.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2005 version complete + KEYGEN\SH3.mds
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\A LIRE ABSOLUMENT !!!.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD1\Architecte3D.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\Architecte3D\CD2\Architecte3D_CD2.zip
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\batpro1_100.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\KEYGEN.EXE
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Architecte 3D 2006 french(Plan Maison Architecture) + crack\temp\Serial.txt
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\- CRACK EUROBARRE v1.4.exe
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\1 ETAPE grace au crack v1.4 gagner plus READ ME.doc
C:\DOCUME~1\@\Bureau\PHILIPPE\facade\eMule\Incoming\Logiciel Salon.Styler.Pro.(coiffure_maquillage)\Fantastique !!!\crack pour Eurobarre.reg
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00
C:\DOCUME~1\@\Mes documents\Cracks architecte 3D00.zip
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\Deutsch AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\Downloads\Metadata\US AVS Audio Tools v3.x crack.exe.xml
C:\DOCUME~1\@\Mes documents\programe\Crack
C:\DOCUME~1\@\Mes documents\programe\Crack\AVS.Audio.Tools.v3.5.1.160-RES-crk.rar
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\licence.reg
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\Manager.exe
C:\DOCUME~1\@\Mes documents\programe\Crack\AVSAUD~1\RESURRECTiON.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\Adobe Photoshop CS V8.0 SafeCast Keygen Only-MiDNiGHT\midnight.nfo
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\adobelm.dll
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\lisezmoi.txt
C:\DOCUME~1\@\Mes documents\programe\Photoshop CS FRENCH\crack\tw10122.dat

[F:3][D:0]-> C:\DOCUME~1\@\LOCALS~1\Temp
[F:6][D:0]-> C:\DOCUME~1\@\Cookies
[F:102][D:4]-> C:\DOCUME~1\@\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 28/12/2008|19:23 - Option : [1]

--------------------\\ Fin du rapport a 19:23:15
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
tu peux regler antivir pour detecter les rootkit
ouvre antivir
va danx configuration
coche mode expert
puiscanner puis recherche
coche la case "recherche de rootkit au demarrage

ensuite il faut desactiver la restauration systeme le temps du redemarrage dans DEMARRER puis TOUS LES PROG
puis ACCESOIRE puis OUTILS SYSTEME puis DANS RESTAURATION SYSTEME aller dans parametre et desactiver la restauration
n oubli pas de la remeter en service meme manip en sens inverse

0