A voir également:
- Ouverture intempestive de page internet
- Page d'ouverture google - Guide
- Impossible de supprimer une page word - Guide
- Comment traduire une page internet - Guide
- Gps sans internet - Guide
- Mon pc rame sur internet - Guide
9 réponses
Arfff, ce n'était pas une infection navipromo.
Désactive le contrôle des comptes utilisateurs
(tu le réactiveras après ta désinfection):
* Va dans démarrer puis panneau de configuration
* Double Clique sur l'icône "Comptes d'utilisateurs"
* Clique ensuite sur désactiver et valide.
Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517
https://forum.pcastuces.com/navilog_de_il_mafioso_pour_vista-f31s12.htm
Télécharge Lop S&D.exe sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
* Double-clique dessus pour lancer l'installation
* Puis Clique droit sur le raccourci Lop S&D présent sur ton Bureau pour éxécuter "en tant qu'administrateur"
* Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
Tutorial ( aide ) : http://bibou0007.com/outils-specifiques-f78/tuto-lop-sd-t956.htm
Désactive le contrôle des comptes utilisateurs
(tu le réactiveras après ta désinfection):
* Va dans démarrer puis panneau de configuration
* Double Clique sur l'icône "Comptes d'utilisateurs"
* Clique ensuite sur désactiver et valide.
Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517
https://forum.pcastuces.com/navilog_de_il_mafioso_pour_vista-f31s12.htm
Télécharge Lop S&D.exe sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
* Double-clique dessus pour lancer l'installation
* Puis Clique droit sur le raccourci Lop S&D présent sur ton Bureau pour éxécuter "en tant qu'administrateur"
* Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
Tutorial ( aide ) : http://bibou0007.com/outils-specifiques-f78/tuto-lop-sd-t956.htm
bonsoir
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:79 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 29/12/2008|22:31 )
[ UAC => 1 ]
--------------------\\ Listing des dossiers dans Local
[02/08/2008|10:41] C:\Users\oliviane\AppData\Local\Acer Arcade Live
[20/07/2008|17:37] C:\Users\oliviane\AppData\Local\Acer DVDivine
[24/04/2008|18:00] C:\Users\oliviane\AppData\Local\Adobe
[02/08/2008|13:37] C:\Users\oliviane\AppData\Local\Ahead
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Application Data
[24/07/2008|12:27] C:\Users\oliviane\AppData\Local\Apps
[25/04/2008|21:39] C:\Users\oliviane\AppData\Local\ArcSoft
[29/12/2008|17:48] C:\Users\oliviane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[24/07/2008|20:01] C:\Users\oliviane\AppData\Local\Deployment
[24/07/2008|12:30] C:\Users\oliviane\AppData\Local\Downloaded Installations
[25/04/2008|22:20] C:\Users\oliviane\AppData\Local\GDIPFONTCACHEV1.DAT
[25/04/2008|22:49] C:\Users\oliviane\AppData\Local\Google
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Historique
[29/12/2008|21:11] C:\Users\oliviane\AppData\Local\IconCache.db
[19/10/2008|19:41] C:\Users\oliviane\AppData\Local\IM
[29/11/2008|21:52] C:\Users\oliviane\AppData\Local\Innovative Solutions
[20/07/2008|17:38] C:\Users\oliviane\AppData\Local\MakeDisc
[29/12/2008|21:28] C:\Users\oliviane\AppData\Local\Microsoft
[14/09/2008|14:56] C:\Users\oliviane\AppData\Local\Microsoft Games
[24/04/2008|09:21] C:\Users\oliviane\AppData\Local\PowerCinema
[24/07/2008|20:00] C:\Users\oliviane\AppData\Local\ROUTE 66 Sync
[09/05/2008|23:01] C:\Users\oliviane\AppData\Local\Snapfish Livres de photo
[29/12/2008|22:20] C:\Users\oliviane\AppData\Local\Temp
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Temporary Internet Files
[24/04/2008|17:41] C:\Users\oliviane\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[29/12/2008 09:57][--a------] C:\Windows\tasks\Norton Security Scan for oliviane.job
[26/12/2008 20:56][--a------] C:\Windows\tasks\Norton Internet Security - Analyse systŠme complŠte - oliviane.job
[29/12/2008 21:12][--ah-----] C:\Windows\tasks\SA.DAT
[29/12/2008 21:11][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[03/12/2007|09:42] C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[23/12/2008|23:04] C:\ProgramData\Adobe
[24/04/2008|11:07] C:\ProgramData\Ahead
[02/11/2006|14:02] C:\ProgramData\Application Data
[25/04/2008|22:07] C:\ProgramData\ArcSoft
[18/05/2008|09:32] C:\ProgramData\Azureus
[24/04/2008|09:17] C:\ProgramData\Bureau
[24/04/2008|10:59] C:\ProgramData\CanonBJ
[20/07/2008|17:38] C:\ProgramData\CyberLink
[02/11/2006|14:02] C:\ProgramData\Desktop
[02/11/2006|14:02] C:\ProgramData\Documents
[24/04/2008|09:31] C:\ProgramData\eSobi
[24/04/2008|09:17] C:\ProgramData\Favoris
[02/11/2006|14:02] C:\ProgramData\Favorites
[25/04/2008|09:20] C:\ProgramData\Google
[29/12/2008|11:51] C:\ProgramData\Google Updater
[24/04/2008|12:54] C:\ProgramData\IM
[24/04/2008|12:53] C:\ProgramData\IncrediMail
[10/05/2008|18:35] C:\ProgramData\LightScribe
[24/04/2008|09:17] C:\ProgramData\Menu D‚marrer
[09/05/2008|18:38] C:\ProgramData\Microsoft
[03/12/2007|09:41] C:\ProgramData\Microsoft Help
[24/04/2008|09:17] C:\ProgramData\ModŠles
[13/06/2008|22:58] C:\ProgramData\Nero
[28/12/2008|22:51] C:\ProgramData\Nouncloseclose.sb95u
[29/12/2008|19:51] C:\ProgramData\Nouncloseclose.u79ej
[29/12/2008|19:51] C:\ProgramData\Nouncloseclose.wy4y37
[20/12/2008|00:11] C:\ProgramData\NVIDIA
[27/06/2008|13:03] C:\ProgramData\OceanMedia
[29/12/2008|19:51] C:\ProgramData\Okay meta anti lite
[29/12/2008|19:51] C:\ProgramData\Plan Lite Chin.k5j4z84
[22/07/2008|20:47] C:\ProgramData\PlayFirst
[06/06/2008|13:50] C:\ProgramData\PlayPond
[09/05/2008|18:34] C:\ProgramData\Snapfish Livres de photo
[02/11/2006|14:02] C:\ProgramData\Start Menu
[28/12/2008|22:51] C:\ProgramData\surf cash remote.2cuff
[28/12/2008|23:22] C:\ProgramData\Symantec
[22/07/2008|21:25] C:\ProgramData\TEMP
[02/11/2006|14:02] C:\ProgramData\Templates
[29/12/2008|19:51] C:\ProgramData\The Send
[05/11/2008|21:46] C:\ProgramData\yahoo!
[19/12/2008|23:54] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[24/04/2008|19:02] C:\Program Files\7-Zip
[03/12/2007|10:08] C:\Program Files\Acer Arcade Live
[23/07/2008|10:56] C:\Program Files\Acer GameZone
[09/03/2008|05:30] C:\Program Files\Acer Inc
[03/12/2007|09:42] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[23/12/2008|23:04] C:\Program Files\Adobe
[15/08/2008|12:41] C:\Program Files\Ahead
[25/04/2008|21:37] C:\Program Files\ArcSoft
[02/08/2008|13:29] C:\Program Files\AskTBar
[09/03/2008|05:28] C:\Program Files\ATI
[28/12/2008|15:13] C:\Program Files\Azureus
[26/07/2008|14:26] C:\Program Files\CCleaner
[02/08/2008|13:53] C:\Program Files\CDBurnerXP
[24/07/2008|19:59] C:\Program Files\Common Files
[03/12/2007|09:59] C:\Program Files\CyberLink
[24/04/2008|18:03] C:\Program Files\directx
[29/12/2008|19:51] C:\Program Files\DivoCodec
[03/12/2007|10:08] C:\Program Files\eSobi
[24/04/2008|09:17] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[07/05/2008|21:01] C:\Program Files\Future Pinball
[25/07/2008|22:29] C:\Program Files\Google
[29/12/2008|18:29] C:\Program Files\GRETECH
[23/07/2008|10:55] C:\Program Files\Incredijeux
[11/08/2008|20:14] C:\Program Files\IncrediMail
[29/11/2008|21:52] C:\Program Files\Innovative Solutions
[08/10/2008|19:35] C:\Program Files\InstallShield Installation Information
[20/07/2008|18:12] C:\Program Files\Internet Explorer
[25/04/2008|09:20] C:\Program Files\Java
[29/12/2008|19:48] C:\Program Files\K-Lite Codec Pack
[02/11/2006|13:37] C:\Program Files\Microsoft Games
[03/12/2007|09:42] C:\Program Files\Microsoft Office
[03/12/2007|09:42] C:\Program Files\Microsoft Works
[03/12/2007|09:39] C:\Program Files\Microsoft.NET
[20/07/2008|18:12] C:\Program Files\Movie Maker
[02/11/2006|13:37] C:\Program Files\MSBuild
[03/12/2007|09:06] C:\Program Files\MSXML 4.0
[29/12/2008|21:28] C:\Program Files\Navilog1
[24/04/2008|10:48] C:\Program Files\Neuf
[03/12/2007|09:47] C:\Program Files\NewTech Infosystems
[30/09/2008|18:13] C:\Program Files\Norton Internet Security
[28/12/2008|23:23] C:\Program Files\Norton Security Scan
[24/04/2008|17:39] C:\Program Files\OpenOffice.org 2.4
[15/10/2008|18:48] C:\Program Files\OptimCr‚dit
[25/04/2008|22:02] C:\Program Files\Panasonic
[25/04/2008|22:49] C:\Program Files\Picasa2
[07/05/2008|21:16] C:\Program Files\Plus!
[03/12/2007|09:34] C:\Program Files\Realtek
[02/11/2006|13:37] C:\Program Files\Reference Assemblies
[24/07/2008|19:59] C:\Program Files\ROUTE 66
[24/04/2008|18:03] C:\Program Files\Roxio
[21/10/2008|21:21] C:\Program Files\sina
[09/05/2008|18:34] C:\Program Files\Snapfish Livres de photo
[30/05/2008|22:15] C:\Program Files\Symantec
[24/04/2008|19:11] C:\Program Files\TVAnts
[02/11/2006|14:01] C:\Program Files\Uninstall Information
[24/04/2008|18:12] C:\Program Files\VideoLAN
[20/07/2008|18:12] C:\Program Files\Windows Calendar
[20/07/2008|18:12] C:\Program Files\Windows Collaboration
[20/07/2008|18:12] C:\Program Files\Windows Defender
[20/07/2008|18:12] C:\Program Files\Windows Journal
[20/07/2008|18:12] C:\Program Files\Windows Mail
[20/07/2008|18:12] C:\Program Files\Windows Media Player
[24/04/2008|09:17] C:\Program Files\Windows NT
[20/07/2008|18:12] C:\Program Files\Windows Photo Gallery
[20/07/2008|18:12] C:\Program Files\Windows Sidebar
[05/11/2008|21:46] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[24/04/2008|18:03] C:\Program Files\Common Files\Adaptec Shared
[23/12/2008|23:04] C:\Program Files\Common Files\Adobe
[15/08/2008|12:41] C:\Program Files\Common Files\Ahead
[25/04/2008|21:38] C:\Program Files\Common Files\ArcSoft
[03/12/2007|09:39] C:\Program Files\Common Files\DESIGNER
[03/12/2007|09:59] C:\Program Files\Common Files\InstallShield
[24/04/2008|17:38] C:\Program Files\Common Files\Java
[03/12/2007|09:47] C:\Program Files\Common Files\LightScribe
[03/12/2007|09:41] C:\Program Files\Common Files\microsoft shared
[03/12/2007|09:46] C:\Program Files\Common Files\muvee Technologies
[02/08/2008|13:18] C:\Program Files\Common Files\Nero
[03/12/2007|09:47] C:\Program Files\Common Files\NewTech Infosystems
[23/07/2008|10:48] C:\Program Files\Common Files\Oberon Media
[24/07/2008|19:59] C:\Program Files\Common Files\ROUTE 66
[24/04/2008|18:04] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[28/12/2008|23:23] C:\Program Files\Common Files\Symantec Shared
[20/07/2008|18:12] C:\Program Files\Common Files\System
--------------------\\ Process
( 75 Processes )
iexplore.exe ~ [PID:4020]
iexplore.exe ~ [PID:3480]
iexplore.exe ~ [PID:5952]
IEXPLORE.EXE ~ [PID:4924]
IEXPLORE.EXE ~ [PID:2240]
--------------------\\ Recherche avec S_Lop
C:\ProgramData\Nouncloseclose.sb95u
C:\ProgramData\Nouncloseclose.u79ej
C:\ProgramData\surf cash remote.2cuff
C:\ProgramData\Nouncloseclose.wy4y37
C:\ProgramData\Plan Lite Chin.k5j4z84
C:\Users\oliviane\AppData\Local\Temp\bis75B6.exe
C:\Users\oliviane\AppData\Local\Temp\bisAB37.exe
C:\ProgramData\THESEN~1
C:\ProgramData\THESEN~1\DvdEnc.exe
C:\ProgramData\THESEN~1\ifpqogra.exe
C:\ProgramData\THESEN~1\ptapehxi.exe
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\ProgramData\Okay meta anti lite
C:\ProgramData\Okay meta anti lite\Dupe Deaf.dat
C:\ProgramData\Okay meta anti lite\Dupe Deaf.exe
C:\ProgramData\Okay meta anti lite\Roam view.dat
C:\ProgramData\Okay meta anti lite\Roam view.exe
C:\Users\oliviane\AppData\Local\Temp\DivoCodec.zip
C:\Users\oliviane\AppData\Local\Temp\minime.exe
C:\Users\oliviane\AppData\Local\Temp\HtmlControl.dll
C:\Users\oliviane\AppData\Local\Temp\codec_dv.bmp
C:\Users\oliviane\AppData\Local\Temp\DivoCodec.zip
C:\Users\oliviane\AppData\Local\Temp\NSISPromotion.dll
C:\Program Files\DivoCodec
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\stupidlinkup]
"DisplayName"="CiD Help"
"UninstallString"="C:\\PROGRA~2\\THESEN~1\\DvdEnc.exe -uninstall"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"atom poll"="\"C:\\ProgramData\\Nouncloseclose.wy4y37\""
"ANTI LITE TITLE DEBUG"="\"C:\\ProgramData\\Plan Lite Chin.k5j4z84\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 22:32:04
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\Documents\blocN\crack.txt
C:\Users\oliviane\Downloads\Nouveau dossier\KeyGen.exe
C:\Users\oliviane\Favorites\equivalent\Keygen Office 2007 Plus.url
C:\Users\oliviane\Favorites\equivalent\Nero 8 Crack Exe Torrent.url
C:\Users\oliviane\Favorites\equivalent\WWW.CRACKS.AM - the oldest and largest source of cracks, patches, keygens and serials - since 1999!.url
[F:223][D:11]-> C:\Users\oliviane\AppData\Local\Temp
[F:133][D:1]-> C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies
[F:136][D:5]-> C:\Users\oliviane\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:5][D:3]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 29/12/2008|22:32 - Option : [1]
--------------------\\ Fin du rapport a 22:32:55
[ UAC => 1 ]
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:79 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 29/12/2008|22:31 )
[ UAC => 1 ]
--------------------\\ Listing des dossiers dans Local
[02/08/2008|10:41] C:\Users\oliviane\AppData\Local\Acer Arcade Live
[20/07/2008|17:37] C:\Users\oliviane\AppData\Local\Acer DVDivine
[24/04/2008|18:00] C:\Users\oliviane\AppData\Local\Adobe
[02/08/2008|13:37] C:\Users\oliviane\AppData\Local\Ahead
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Application Data
[24/07/2008|12:27] C:\Users\oliviane\AppData\Local\Apps
[25/04/2008|21:39] C:\Users\oliviane\AppData\Local\ArcSoft
[29/12/2008|17:48] C:\Users\oliviane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[24/07/2008|20:01] C:\Users\oliviane\AppData\Local\Deployment
[24/07/2008|12:30] C:\Users\oliviane\AppData\Local\Downloaded Installations
[25/04/2008|22:20] C:\Users\oliviane\AppData\Local\GDIPFONTCACHEV1.DAT
[25/04/2008|22:49] C:\Users\oliviane\AppData\Local\Google
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Historique
[29/12/2008|21:11] C:\Users\oliviane\AppData\Local\IconCache.db
[19/10/2008|19:41] C:\Users\oliviane\AppData\Local\IM
[29/11/2008|21:52] C:\Users\oliviane\AppData\Local\Innovative Solutions
[20/07/2008|17:38] C:\Users\oliviane\AppData\Local\MakeDisc
[29/12/2008|21:28] C:\Users\oliviane\AppData\Local\Microsoft
[14/09/2008|14:56] C:\Users\oliviane\AppData\Local\Microsoft Games
[24/04/2008|09:21] C:\Users\oliviane\AppData\Local\PowerCinema
[24/07/2008|20:00] C:\Users\oliviane\AppData\Local\ROUTE 66 Sync
[09/05/2008|23:01] C:\Users\oliviane\AppData\Local\Snapfish Livres de photo
[29/12/2008|22:20] C:\Users\oliviane\AppData\Local\Temp
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Temporary Internet Files
[24/04/2008|17:41] C:\Users\oliviane\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[29/12/2008 09:57][--a------] C:\Windows\tasks\Norton Security Scan for oliviane.job
[26/12/2008 20:56][--a------] C:\Windows\tasks\Norton Internet Security - Analyse systŠme complŠte - oliviane.job
[29/12/2008 21:12][--ah-----] C:\Windows\tasks\SA.DAT
[29/12/2008 21:11][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[03/12/2007|09:42] C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[23/12/2008|23:04] C:\ProgramData\Adobe
[24/04/2008|11:07] C:\ProgramData\Ahead
[02/11/2006|14:02] C:\ProgramData\Application Data
[25/04/2008|22:07] C:\ProgramData\ArcSoft
[18/05/2008|09:32] C:\ProgramData\Azureus
[24/04/2008|09:17] C:\ProgramData\Bureau
[24/04/2008|10:59] C:\ProgramData\CanonBJ
[20/07/2008|17:38] C:\ProgramData\CyberLink
[02/11/2006|14:02] C:\ProgramData\Desktop
[02/11/2006|14:02] C:\ProgramData\Documents
[24/04/2008|09:31] C:\ProgramData\eSobi
[24/04/2008|09:17] C:\ProgramData\Favoris
[02/11/2006|14:02] C:\ProgramData\Favorites
[25/04/2008|09:20] C:\ProgramData\Google
[29/12/2008|11:51] C:\ProgramData\Google Updater
[24/04/2008|12:54] C:\ProgramData\IM
[24/04/2008|12:53] C:\ProgramData\IncrediMail
[10/05/2008|18:35] C:\ProgramData\LightScribe
[24/04/2008|09:17] C:\ProgramData\Menu D‚marrer
[09/05/2008|18:38] C:\ProgramData\Microsoft
[03/12/2007|09:41] C:\ProgramData\Microsoft Help
[24/04/2008|09:17] C:\ProgramData\ModŠles
[13/06/2008|22:58] C:\ProgramData\Nero
[28/12/2008|22:51] C:\ProgramData\Nouncloseclose.sb95u
[29/12/2008|19:51] C:\ProgramData\Nouncloseclose.u79ej
[29/12/2008|19:51] C:\ProgramData\Nouncloseclose.wy4y37
[20/12/2008|00:11] C:\ProgramData\NVIDIA
[27/06/2008|13:03] C:\ProgramData\OceanMedia
[29/12/2008|19:51] C:\ProgramData\Okay meta anti lite
[29/12/2008|19:51] C:\ProgramData\Plan Lite Chin.k5j4z84
[22/07/2008|20:47] C:\ProgramData\PlayFirst
[06/06/2008|13:50] C:\ProgramData\PlayPond
[09/05/2008|18:34] C:\ProgramData\Snapfish Livres de photo
[02/11/2006|14:02] C:\ProgramData\Start Menu
[28/12/2008|22:51] C:\ProgramData\surf cash remote.2cuff
[28/12/2008|23:22] C:\ProgramData\Symantec
[22/07/2008|21:25] C:\ProgramData\TEMP
[02/11/2006|14:02] C:\ProgramData\Templates
[29/12/2008|19:51] C:\ProgramData\The Send
[05/11/2008|21:46] C:\ProgramData\yahoo!
[19/12/2008|23:54] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[24/04/2008|19:02] C:\Program Files\7-Zip
[03/12/2007|10:08] C:\Program Files\Acer Arcade Live
[23/07/2008|10:56] C:\Program Files\Acer GameZone
[09/03/2008|05:30] C:\Program Files\Acer Inc
[03/12/2007|09:42] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[23/12/2008|23:04] C:\Program Files\Adobe
[15/08/2008|12:41] C:\Program Files\Ahead
[25/04/2008|21:37] C:\Program Files\ArcSoft
[02/08/2008|13:29] C:\Program Files\AskTBar
[09/03/2008|05:28] C:\Program Files\ATI
[28/12/2008|15:13] C:\Program Files\Azureus
[26/07/2008|14:26] C:\Program Files\CCleaner
[02/08/2008|13:53] C:\Program Files\CDBurnerXP
[24/07/2008|19:59] C:\Program Files\Common Files
[03/12/2007|09:59] C:\Program Files\CyberLink
[24/04/2008|18:03] C:\Program Files\directx
[29/12/2008|19:51] C:\Program Files\DivoCodec
[03/12/2007|10:08] C:\Program Files\eSobi
[24/04/2008|09:17] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[07/05/2008|21:01] C:\Program Files\Future Pinball
[25/07/2008|22:29] C:\Program Files\Google
[29/12/2008|18:29] C:\Program Files\GRETECH
[23/07/2008|10:55] C:\Program Files\Incredijeux
[11/08/2008|20:14] C:\Program Files\IncrediMail
[29/11/2008|21:52] C:\Program Files\Innovative Solutions
[08/10/2008|19:35] C:\Program Files\InstallShield Installation Information
[20/07/2008|18:12] C:\Program Files\Internet Explorer
[25/04/2008|09:20] C:\Program Files\Java
[29/12/2008|19:48] C:\Program Files\K-Lite Codec Pack
[02/11/2006|13:37] C:\Program Files\Microsoft Games
[03/12/2007|09:42] C:\Program Files\Microsoft Office
[03/12/2007|09:42] C:\Program Files\Microsoft Works
[03/12/2007|09:39] C:\Program Files\Microsoft.NET
[20/07/2008|18:12] C:\Program Files\Movie Maker
[02/11/2006|13:37] C:\Program Files\MSBuild
[03/12/2007|09:06] C:\Program Files\MSXML 4.0
[29/12/2008|21:28] C:\Program Files\Navilog1
[24/04/2008|10:48] C:\Program Files\Neuf
[03/12/2007|09:47] C:\Program Files\NewTech Infosystems
[30/09/2008|18:13] C:\Program Files\Norton Internet Security
[28/12/2008|23:23] C:\Program Files\Norton Security Scan
[24/04/2008|17:39] C:\Program Files\OpenOffice.org 2.4
[15/10/2008|18:48] C:\Program Files\OptimCr‚dit
[25/04/2008|22:02] C:\Program Files\Panasonic
[25/04/2008|22:49] C:\Program Files\Picasa2
[07/05/2008|21:16] C:\Program Files\Plus!
[03/12/2007|09:34] C:\Program Files\Realtek
[02/11/2006|13:37] C:\Program Files\Reference Assemblies
[24/07/2008|19:59] C:\Program Files\ROUTE 66
[24/04/2008|18:03] C:\Program Files\Roxio
[21/10/2008|21:21] C:\Program Files\sina
[09/05/2008|18:34] C:\Program Files\Snapfish Livres de photo
[30/05/2008|22:15] C:\Program Files\Symantec
[24/04/2008|19:11] C:\Program Files\TVAnts
[02/11/2006|14:01] C:\Program Files\Uninstall Information
[24/04/2008|18:12] C:\Program Files\VideoLAN
[20/07/2008|18:12] C:\Program Files\Windows Calendar
[20/07/2008|18:12] C:\Program Files\Windows Collaboration
[20/07/2008|18:12] C:\Program Files\Windows Defender
[20/07/2008|18:12] C:\Program Files\Windows Journal
[20/07/2008|18:12] C:\Program Files\Windows Mail
[20/07/2008|18:12] C:\Program Files\Windows Media Player
[24/04/2008|09:17] C:\Program Files\Windows NT
[20/07/2008|18:12] C:\Program Files\Windows Photo Gallery
[20/07/2008|18:12] C:\Program Files\Windows Sidebar
[05/11/2008|21:46] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[24/04/2008|18:03] C:\Program Files\Common Files\Adaptec Shared
[23/12/2008|23:04] C:\Program Files\Common Files\Adobe
[15/08/2008|12:41] C:\Program Files\Common Files\Ahead
[25/04/2008|21:38] C:\Program Files\Common Files\ArcSoft
[03/12/2007|09:39] C:\Program Files\Common Files\DESIGNER
[03/12/2007|09:59] C:\Program Files\Common Files\InstallShield
[24/04/2008|17:38] C:\Program Files\Common Files\Java
[03/12/2007|09:47] C:\Program Files\Common Files\LightScribe
[03/12/2007|09:41] C:\Program Files\Common Files\microsoft shared
[03/12/2007|09:46] C:\Program Files\Common Files\muvee Technologies
[02/08/2008|13:18] C:\Program Files\Common Files\Nero
[03/12/2007|09:47] C:\Program Files\Common Files\NewTech Infosystems
[23/07/2008|10:48] C:\Program Files\Common Files\Oberon Media
[24/07/2008|19:59] C:\Program Files\Common Files\ROUTE 66
[24/04/2008|18:04] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[28/12/2008|23:23] C:\Program Files\Common Files\Symantec Shared
[20/07/2008|18:12] C:\Program Files\Common Files\System
--------------------\\ Process
( 75 Processes )
iexplore.exe ~ [PID:4020]
iexplore.exe ~ [PID:3480]
iexplore.exe ~ [PID:5952]
IEXPLORE.EXE ~ [PID:4924]
IEXPLORE.EXE ~ [PID:2240]
--------------------\\ Recherche avec S_Lop
C:\ProgramData\Nouncloseclose.sb95u
C:\ProgramData\Nouncloseclose.u79ej
C:\ProgramData\surf cash remote.2cuff
C:\ProgramData\Nouncloseclose.wy4y37
C:\ProgramData\Plan Lite Chin.k5j4z84
C:\Users\oliviane\AppData\Local\Temp\bis75B6.exe
C:\Users\oliviane\AppData\Local\Temp\bisAB37.exe
C:\ProgramData\THESEN~1
C:\ProgramData\THESEN~1\DvdEnc.exe
C:\ProgramData\THESEN~1\ifpqogra.exe
C:\ProgramData\THESEN~1\ptapehxi.exe
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\ProgramData\Okay meta anti lite
C:\ProgramData\Okay meta anti lite\Dupe Deaf.dat
C:\ProgramData\Okay meta anti lite\Dupe Deaf.exe
C:\ProgramData\Okay meta anti lite\Roam view.dat
C:\ProgramData\Okay meta anti lite\Roam view.exe
C:\Users\oliviane\AppData\Local\Temp\DivoCodec.zip
C:\Users\oliviane\AppData\Local\Temp\minime.exe
C:\Users\oliviane\AppData\Local\Temp\HtmlControl.dll
C:\Users\oliviane\AppData\Local\Temp\codec_dv.bmp
C:\Users\oliviane\AppData\Local\Temp\DivoCodec.zip
C:\Users\oliviane\AppData\Local\Temp\NSISPromotion.dll
C:\Program Files\DivoCodec
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\stupidlinkup]
"DisplayName"="CiD Help"
"UninstallString"="C:\\PROGRA~2\\THESEN~1\\DvdEnc.exe -uninstall"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"atom poll"="\"C:\\ProgramData\\Nouncloseclose.wy4y37\""
"ANTI LITE TITLE DEBUG"="\"C:\\ProgramData\\Plan Lite Chin.k5j4z84\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 22:32:04
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\Documents\blocN\crack.txt
C:\Users\oliviane\Downloads\Nouveau dossier\KeyGen.exe
C:\Users\oliviane\Favorites\equivalent\Keygen Office 2007 Plus.url
C:\Users\oliviane\Favorites\equivalent\Nero 8 Crack Exe Torrent.url
C:\Users\oliviane\Favorites\equivalent\WWW.CRACKS.AM - the oldest and largest source of cracks, patches, keygens and serials - since 1999!.url
[F:223][D:11]-> C:\Users\oliviane\AppData\Local\Temp
[F:133][D:1]-> C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies
[F:136][D:5]-> C:\Users\oliviane\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:5][D:3]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 29/12/2008|22:32 - Option : [1]
--------------------\\ Fin du rapport a 22:32:55
[ UAC => 1 ]
Supprime tes cracks, pas étonnant que tu sois infecté :
C:\Users\oliviane\Documents\blocN\crack.txt
C:\Users\oliviane\Downloads\Nouveau dossier\KeyGen.exe
C:\Users\oliviane\Favorites\equivalent\Keygen Office 2007 Plus.url
C:\Users\oliviane\Favorites\equivalent\Nero 8 Crack Exe Torrent.url
C:\Users\oliviane\Favorites\equivalent\WWW.CRACKS.AM - the oldest and largest source of cracks, patches, keygens and serials - since 1999!.url
Relance Lop S&D
* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)
C:\Users\oliviane\Documents\blocN\crack.txt
C:\Users\oliviane\Downloads\Nouveau dossier\KeyGen.exe
C:\Users\oliviane\Favorites\equivalent\Keygen Office 2007 Plus.url
C:\Users\oliviane\Favorites\equivalent\Nero 8 Crack Exe Torrent.url
C:\Users\oliviane\Favorites\equivalent\WWW.CRACKS.AM - the oldest and largest source of cracks, patches, keygens and serials - since 1999!.url
Relance Lop S&D
* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)
encore merci
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:79 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 29/12/2008|22:41 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\ProgramData\Okay meta anti lite\Dupe Deaf.dat
Supprime! - C:\ProgramData\Okay meta anti lite\Dupe Deaf.exe
Supprime! - C:\ProgramData\Okay meta anti lite\Roam view.dat
Supprime! - C:\ProgramData\Okay meta anti lite\Roam view.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\DivoCodec.zip
Supprime! - C:\Users\oliviane\AppData\Local\Temp\minime.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\HtmlControl.dll
Supprime! - C:\Users\oliviane\AppData\Local\Temp\codec_dv.bmp
Supprime! - C:\Users\oliviane\AppData\Local\Temp\NSISPromotion.dll
Supprime! - C:\ProgramData\Nouncloseclose.sb95u
Supprime! - C:\ProgramData\Nouncloseclose.u79ej
Supprime! - C:\ProgramData\surf cash remote.2cuff
Supprime! - C:\ProgramData\Nouncloseclose.wy4y37
Supprime! - C:\ProgramData\Plan Lite Chin.k5j4z84
Supprime! - C:\Users\oliviane\AppData\Local\Temp\bis75B6.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\bisAB37.exe
Supprime! - C:\ProgramData\THESEN~1\DvdEnc.exe
Supprime! - C:\ProgramData\THESEN~1\ifpqogra.exe
Supprime! - C:\ProgramData\THESEN~1\ptapehxi.exe
Supprime! - C:\ProgramData\Okay meta anti lite
Supprime! - C:\Program Files\DivoCodec
Supprime! - C:\ProgramData\THESEN~1
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[02/08/2008|10:41] C:\Users\oliviane\AppData\Local\Acer Arcade Live
[20/07/2008|17:37] C:\Users\oliviane\AppData\Local\Acer DVDivine
[24/04/2008|18:00] C:\Users\oliviane\AppData\Local\Adobe
[02/08/2008|13:37] C:\Users\oliviane\AppData\Local\Ahead
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Application Data
[24/07/2008|12:27] C:\Users\oliviane\AppData\Local\Apps
[25/04/2008|21:39] C:\Users\oliviane\AppData\Local\ArcSoft
[29/12/2008|17:48] C:\Users\oliviane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[24/07/2008|20:01] C:\Users\oliviane\AppData\Local\Deployment
[24/07/2008|12:30] C:\Users\oliviane\AppData\Local\Downloaded Installations
[25/04/2008|22:20] C:\Users\oliviane\AppData\Local\GDIPFONTCACHEV1.DAT
[25/04/2008|22:49] C:\Users\oliviane\AppData\Local\Google
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Historique
[29/12/2008|21:11] C:\Users\oliviane\AppData\Local\IconCache.db
[19/10/2008|19:41] C:\Users\oliviane\AppData\Local\IM
[29/11/2008|21:52] C:\Users\oliviane\AppData\Local\Innovative Solutions
[20/07/2008|17:38] C:\Users\oliviane\AppData\Local\MakeDisc
[29/12/2008|21:28] C:\Users\oliviane\AppData\Local\Microsoft
[14/09/2008|14:56] C:\Users\oliviane\AppData\Local\Microsoft Games
[24/04/2008|09:21] C:\Users\oliviane\AppData\Local\PowerCinema
[24/07/2008|20:00] C:\Users\oliviane\AppData\Local\ROUTE 66 Sync
[09/05/2008|23:01] C:\Users\oliviane\AppData\Local\Snapfish Livres de photo
[29/12/2008|22:42] C:\Users\oliviane\AppData\Local\Temp
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Temporary Internet Files
[24/04/2008|17:41] C:\Users\oliviane\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[29/12/2008 09:57][--a------] C:\Windows\tasks\Norton Security Scan for oliviane.job
[26/12/2008 20:56][--a------] C:\Windows\tasks\Norton Internet Security - Analyse systŠme complŠte - oliviane.job
[29/12/2008 21:12][--ah-----] C:\Windows\tasks\SA.DAT
[29/12/2008 21:11][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[03/12/2007|09:42] C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[23/12/2008|23:04] C:\ProgramData\Adobe
[24/04/2008|11:07] C:\ProgramData\Ahead
[02/11/2006|14:02] C:\ProgramData\Application Data
[25/04/2008|22:07] C:\ProgramData\ArcSoft
[18/05/2008|09:32] C:\ProgramData\Azureus
[24/04/2008|09:17] C:\ProgramData\Bureau
[24/04/2008|10:59] C:\ProgramData\CanonBJ
[20/07/2008|17:38] C:\ProgramData\CyberLink
[02/11/2006|14:02] C:\ProgramData\Desktop
[02/11/2006|14:02] C:\ProgramData\Documents
[24/04/2008|09:31] C:\ProgramData\eSobi
[24/04/2008|09:17] C:\ProgramData\Favoris
[02/11/2006|14:02] C:\ProgramData\Favorites
[25/04/2008|09:20] C:\ProgramData\Google
[29/12/2008|11:51] C:\ProgramData\Google Updater
[24/04/2008|12:54] C:\ProgramData\IM
[24/04/2008|12:53] C:\ProgramData\IncrediMail
[10/05/2008|18:35] C:\ProgramData\LightScribe
[24/04/2008|09:17] C:\ProgramData\Menu D‚marrer
[09/05/2008|18:38] C:\ProgramData\Microsoft
[03/12/2007|09:41] C:\ProgramData\Microsoft Help
[24/04/2008|09:17] C:\ProgramData\ModŠles
[13/06/2008|22:58] C:\ProgramData\Nero
[20/12/2008|00:11] C:\ProgramData\NVIDIA
[27/06/2008|13:03] C:\ProgramData\OceanMedia
[22/07/2008|20:47] C:\ProgramData\PlayFirst
[06/06/2008|13:50] C:\ProgramData\PlayPond
[09/05/2008|18:34] C:\ProgramData\Snapfish Livres de photo
[02/11/2006|14:02] C:\ProgramData\Start Menu
[28/12/2008|23:22] C:\ProgramData\Symantec
[22/07/2008|21:25] C:\ProgramData\TEMP
[02/11/2006|14:02] C:\ProgramData\Templates
[05/11/2008|21:46] C:\ProgramData\yahoo!
[19/12/2008|23:54] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[24/04/2008|19:02] C:\Program Files\7-Zip
[03/12/2007|10:08] C:\Program Files\Acer Arcade Live
[23/07/2008|10:56] C:\Program Files\Acer GameZone
[09/03/2008|05:30] C:\Program Files\Acer Inc
[03/12/2007|09:42] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[23/12/2008|23:04] C:\Program Files\Adobe
[15/08/2008|12:41] C:\Program Files\Ahead
[25/04/2008|21:37] C:\Program Files\ArcSoft
[02/08/2008|13:29] C:\Program Files\AskTBar
[09/03/2008|05:28] C:\Program Files\ATI
[28/12/2008|15:13] C:\Program Files\Azureus
[26/07/2008|14:26] C:\Program Files\CCleaner
[02/08/2008|13:53] C:\Program Files\CDBurnerXP
[24/07/2008|19:59] C:\Program Files\Common Files
[03/12/2007|09:59] C:\Program Files\CyberLink
[24/04/2008|18:03] C:\Program Files\directx
[03/12/2007|10:08] C:\Program Files\eSobi
[24/04/2008|09:17] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[07/05/2008|21:01] C:\Program Files\Future Pinball
[25/07/2008|22:29] C:\Program Files\Google
[29/12/2008|18:29] C:\Program Files\GRETECH
[23/07/2008|10:55] C:\Program Files\Incredijeux
[11/08/2008|20:14] C:\Program Files\IncrediMail
[29/11/2008|21:52] C:\Program Files\Innovative Solutions
[08/10/2008|19:35] C:\Program Files\InstallShield Installation Information
[20/07/2008|18:12] C:\Program Files\Internet Explorer
[25/04/2008|09:20] C:\Program Files\Java
[29/12/2008|19:48] C:\Program Files\K-Lite Codec Pack
[02/11/2006|13:37] C:\Program Files\Microsoft Games
[03/12/2007|09:42] C:\Program Files\Microsoft Office
[03/12/2007|09:42] C:\Program Files\Microsoft Works
[03/12/2007|09:39] C:\Program Files\Microsoft.NET
[20/07/2008|18:12] C:\Program Files\Movie Maker
[02/11/2006|13:37] C:\Program Files\MSBuild
[03/12/2007|09:06] C:\Program Files\MSXML 4.0
[29/12/2008|21:28] C:\Program Files\Navilog1
[24/04/2008|10:48] C:\Program Files\Neuf
[03/12/2007|09:47] C:\Program Files\NewTech Infosystems
[30/09/2008|18:13] C:\Program Files\Norton Internet Security
[28/12/2008|23:23] C:\Program Files\Norton Security Scan
[24/04/2008|17:39] C:\Program Files\OpenOffice.org 2.4
[15/10/2008|18:48] C:\Program Files\OptimCr‚dit
[25/04/2008|22:02] C:\Program Files\Panasonic
[25/04/2008|22:49] C:\Program Files\Picasa2
[07/05/2008|21:16] C:\Program Files\Plus!
[03/12/2007|09:34] C:\Program Files\Realtek
[02/11/2006|13:37] C:\Program Files\Reference Assemblies
[24/07/2008|19:59] C:\Program Files\ROUTE 66
[24/04/2008|18:03] C:\Program Files\Roxio
[21/10/2008|21:21] C:\Program Files\sina
[09/05/2008|18:34] C:\Program Files\Snapfish Livres de photo
[30/05/2008|22:15] C:\Program Files\Symantec
[24/04/2008|19:11] C:\Program Files\TVAnts
[02/11/2006|14:01] C:\Program Files\Uninstall Information
[24/04/2008|18:12] C:\Program Files\VideoLAN
[20/07/2008|18:12] C:\Program Files\Windows Calendar
[20/07/2008|18:12] C:\Program Files\Windows Collaboration
[20/07/2008|18:12] C:\Program Files\Windows Defender
[20/07/2008|18:12] C:\Program Files\Windows Journal
[20/07/2008|18:12] C:\Program Files\Windows Mail
[20/07/2008|18:12] C:\Program Files\Windows Media Player
[24/04/2008|09:17] C:\Program Files\Windows NT
[20/07/2008|18:12] C:\Program Files\Windows Photo Gallery
[20/07/2008|18:12] C:\Program Files\Windows Sidebar
[05/11/2008|21:46] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[24/04/2008|18:03] C:\Program Files\Common Files\Adaptec Shared
[23/12/2008|23:04] C:\Program Files\Common Files\Adobe
[15/08/2008|12:41] C:\Program Files\Common Files\Ahead
[25/04/2008|21:38] C:\Program Files\Common Files\ArcSoft
[03/12/2007|09:39] C:\Program Files\Common Files\DESIGNER
[03/12/2007|09:59] C:\Program Files\Common Files\InstallShield
[24/04/2008|17:38] C:\Program Files\Common Files\Java
[03/12/2007|09:47] C:\Program Files\Common Files\LightScribe
[03/12/2007|09:41] C:\Program Files\Common Files\microsoft shared
[03/12/2007|09:46] C:\Program Files\Common Files\muvee Technologies
[02/08/2008|13:18] C:\Program Files\Common Files\Nero
[03/12/2007|09:47] C:\Program Files\Common Files\NewTech Infosystems
[23/07/2008|10:48] C:\Program Files\Common Files\Oberon Media
[24/07/2008|19:59] C:\Program Files\Common Files\ROUTE 66
[24/04/2008|18:04] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[28/12/2008|23:23] C:\Program Files\Common Files\Symantec Shared
[20/07/2008|18:12] C:\Program Files\Common Files\System
--------------------\\ Process
( 67 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 22:42:11
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwEnumerateKey, ZwQueryKey, ZwOpenKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile, ZwQueryDirectoryFile, ZwQuerySystemInformation
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\AppData\Roaming\Microsoft\Windows\Recent\crack.lnk
[F:216][D:12]-> C:\Users\oliviane\AppData\Local\Temp
[F:138][D:1]-> C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies
[F:136][D:5]-> C:\Users\oliviane\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:15][D:3]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 29/12/2008|22:32 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 29/12/2008|22:43 - Option : [2]
--------------------\\ Fin du rapport a 22:43:14
[ UAC => 1 ]
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:79 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 29/12/2008|22:41 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\ProgramData\Okay meta anti lite\Dupe Deaf.dat
Supprime! - C:\ProgramData\Okay meta anti lite\Dupe Deaf.exe
Supprime! - C:\ProgramData\Okay meta anti lite\Roam view.dat
Supprime! - C:\ProgramData\Okay meta anti lite\Roam view.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\DivoCodec.zip
Supprime! - C:\Users\oliviane\AppData\Local\Temp\minime.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\HtmlControl.dll
Supprime! - C:\Users\oliviane\AppData\Local\Temp\codec_dv.bmp
Supprime! - C:\Users\oliviane\AppData\Local\Temp\NSISPromotion.dll
Supprime! - C:\ProgramData\Nouncloseclose.sb95u
Supprime! - C:\ProgramData\Nouncloseclose.u79ej
Supprime! - C:\ProgramData\surf cash remote.2cuff
Supprime! - C:\ProgramData\Nouncloseclose.wy4y37
Supprime! - C:\ProgramData\Plan Lite Chin.k5j4z84
Supprime! - C:\Users\oliviane\AppData\Local\Temp\bis75B6.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\bisAB37.exe
Supprime! - C:\ProgramData\THESEN~1\DvdEnc.exe
Supprime! - C:\ProgramData\THESEN~1\ifpqogra.exe
Supprime! - C:\ProgramData\THESEN~1\ptapehxi.exe
Supprime! - C:\ProgramData\Okay meta anti lite
Supprime! - C:\Program Files\DivoCodec
Supprime! - C:\ProgramData\THESEN~1
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[02/08/2008|10:41] C:\Users\oliviane\AppData\Local\Acer Arcade Live
[20/07/2008|17:37] C:\Users\oliviane\AppData\Local\Acer DVDivine
[24/04/2008|18:00] C:\Users\oliviane\AppData\Local\Adobe
[02/08/2008|13:37] C:\Users\oliviane\AppData\Local\Ahead
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Application Data
[24/07/2008|12:27] C:\Users\oliviane\AppData\Local\Apps
[25/04/2008|21:39] C:\Users\oliviane\AppData\Local\ArcSoft
[29/12/2008|17:48] C:\Users\oliviane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[24/07/2008|20:01] C:\Users\oliviane\AppData\Local\Deployment
[24/07/2008|12:30] C:\Users\oliviane\AppData\Local\Downloaded Installations
[25/04/2008|22:20] C:\Users\oliviane\AppData\Local\GDIPFONTCACHEV1.DAT
[25/04/2008|22:49] C:\Users\oliviane\AppData\Local\Google
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Historique
[29/12/2008|21:11] C:\Users\oliviane\AppData\Local\IconCache.db
[19/10/2008|19:41] C:\Users\oliviane\AppData\Local\IM
[29/11/2008|21:52] C:\Users\oliviane\AppData\Local\Innovative Solutions
[20/07/2008|17:38] C:\Users\oliviane\AppData\Local\MakeDisc
[29/12/2008|21:28] C:\Users\oliviane\AppData\Local\Microsoft
[14/09/2008|14:56] C:\Users\oliviane\AppData\Local\Microsoft Games
[24/04/2008|09:21] C:\Users\oliviane\AppData\Local\PowerCinema
[24/07/2008|20:00] C:\Users\oliviane\AppData\Local\ROUTE 66 Sync
[09/05/2008|23:01] C:\Users\oliviane\AppData\Local\Snapfish Livres de photo
[29/12/2008|22:42] C:\Users\oliviane\AppData\Local\Temp
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Temporary Internet Files
[24/04/2008|17:41] C:\Users\oliviane\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[29/12/2008 09:57][--a------] C:\Windows\tasks\Norton Security Scan for oliviane.job
[26/12/2008 20:56][--a------] C:\Windows\tasks\Norton Internet Security - Analyse systŠme complŠte - oliviane.job
[29/12/2008 21:12][--ah-----] C:\Windows\tasks\SA.DAT
[29/12/2008 21:11][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[03/12/2007|09:42] C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[23/12/2008|23:04] C:\ProgramData\Adobe
[24/04/2008|11:07] C:\ProgramData\Ahead
[02/11/2006|14:02] C:\ProgramData\Application Data
[25/04/2008|22:07] C:\ProgramData\ArcSoft
[18/05/2008|09:32] C:\ProgramData\Azureus
[24/04/2008|09:17] C:\ProgramData\Bureau
[24/04/2008|10:59] C:\ProgramData\CanonBJ
[20/07/2008|17:38] C:\ProgramData\CyberLink
[02/11/2006|14:02] C:\ProgramData\Desktop
[02/11/2006|14:02] C:\ProgramData\Documents
[24/04/2008|09:31] C:\ProgramData\eSobi
[24/04/2008|09:17] C:\ProgramData\Favoris
[02/11/2006|14:02] C:\ProgramData\Favorites
[25/04/2008|09:20] C:\ProgramData\Google
[29/12/2008|11:51] C:\ProgramData\Google Updater
[24/04/2008|12:54] C:\ProgramData\IM
[24/04/2008|12:53] C:\ProgramData\IncrediMail
[10/05/2008|18:35] C:\ProgramData\LightScribe
[24/04/2008|09:17] C:\ProgramData\Menu D‚marrer
[09/05/2008|18:38] C:\ProgramData\Microsoft
[03/12/2007|09:41] C:\ProgramData\Microsoft Help
[24/04/2008|09:17] C:\ProgramData\ModŠles
[13/06/2008|22:58] C:\ProgramData\Nero
[20/12/2008|00:11] C:\ProgramData\NVIDIA
[27/06/2008|13:03] C:\ProgramData\OceanMedia
[22/07/2008|20:47] C:\ProgramData\PlayFirst
[06/06/2008|13:50] C:\ProgramData\PlayPond
[09/05/2008|18:34] C:\ProgramData\Snapfish Livres de photo
[02/11/2006|14:02] C:\ProgramData\Start Menu
[28/12/2008|23:22] C:\ProgramData\Symantec
[22/07/2008|21:25] C:\ProgramData\TEMP
[02/11/2006|14:02] C:\ProgramData\Templates
[05/11/2008|21:46] C:\ProgramData\yahoo!
[19/12/2008|23:54] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[24/04/2008|19:02] C:\Program Files\7-Zip
[03/12/2007|10:08] C:\Program Files\Acer Arcade Live
[23/07/2008|10:56] C:\Program Files\Acer GameZone
[09/03/2008|05:30] C:\Program Files\Acer Inc
[03/12/2007|09:42] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[23/12/2008|23:04] C:\Program Files\Adobe
[15/08/2008|12:41] C:\Program Files\Ahead
[25/04/2008|21:37] C:\Program Files\ArcSoft
[02/08/2008|13:29] C:\Program Files\AskTBar
[09/03/2008|05:28] C:\Program Files\ATI
[28/12/2008|15:13] C:\Program Files\Azureus
[26/07/2008|14:26] C:\Program Files\CCleaner
[02/08/2008|13:53] C:\Program Files\CDBurnerXP
[24/07/2008|19:59] C:\Program Files\Common Files
[03/12/2007|09:59] C:\Program Files\CyberLink
[24/04/2008|18:03] C:\Program Files\directx
[03/12/2007|10:08] C:\Program Files\eSobi
[24/04/2008|09:17] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[07/05/2008|21:01] C:\Program Files\Future Pinball
[25/07/2008|22:29] C:\Program Files\Google
[29/12/2008|18:29] C:\Program Files\GRETECH
[23/07/2008|10:55] C:\Program Files\Incredijeux
[11/08/2008|20:14] C:\Program Files\IncrediMail
[29/11/2008|21:52] C:\Program Files\Innovative Solutions
[08/10/2008|19:35] C:\Program Files\InstallShield Installation Information
[20/07/2008|18:12] C:\Program Files\Internet Explorer
[25/04/2008|09:20] C:\Program Files\Java
[29/12/2008|19:48] C:\Program Files\K-Lite Codec Pack
[02/11/2006|13:37] C:\Program Files\Microsoft Games
[03/12/2007|09:42] C:\Program Files\Microsoft Office
[03/12/2007|09:42] C:\Program Files\Microsoft Works
[03/12/2007|09:39] C:\Program Files\Microsoft.NET
[20/07/2008|18:12] C:\Program Files\Movie Maker
[02/11/2006|13:37] C:\Program Files\MSBuild
[03/12/2007|09:06] C:\Program Files\MSXML 4.0
[29/12/2008|21:28] C:\Program Files\Navilog1
[24/04/2008|10:48] C:\Program Files\Neuf
[03/12/2007|09:47] C:\Program Files\NewTech Infosystems
[30/09/2008|18:13] C:\Program Files\Norton Internet Security
[28/12/2008|23:23] C:\Program Files\Norton Security Scan
[24/04/2008|17:39] C:\Program Files\OpenOffice.org 2.4
[15/10/2008|18:48] C:\Program Files\OptimCr‚dit
[25/04/2008|22:02] C:\Program Files\Panasonic
[25/04/2008|22:49] C:\Program Files\Picasa2
[07/05/2008|21:16] C:\Program Files\Plus!
[03/12/2007|09:34] C:\Program Files\Realtek
[02/11/2006|13:37] C:\Program Files\Reference Assemblies
[24/07/2008|19:59] C:\Program Files\ROUTE 66
[24/04/2008|18:03] C:\Program Files\Roxio
[21/10/2008|21:21] C:\Program Files\sina
[09/05/2008|18:34] C:\Program Files\Snapfish Livres de photo
[30/05/2008|22:15] C:\Program Files\Symantec
[24/04/2008|19:11] C:\Program Files\TVAnts
[02/11/2006|14:01] C:\Program Files\Uninstall Information
[24/04/2008|18:12] C:\Program Files\VideoLAN
[20/07/2008|18:12] C:\Program Files\Windows Calendar
[20/07/2008|18:12] C:\Program Files\Windows Collaboration
[20/07/2008|18:12] C:\Program Files\Windows Defender
[20/07/2008|18:12] C:\Program Files\Windows Journal
[20/07/2008|18:12] C:\Program Files\Windows Mail
[20/07/2008|18:12] C:\Program Files\Windows Media Player
[24/04/2008|09:17] C:\Program Files\Windows NT
[20/07/2008|18:12] C:\Program Files\Windows Photo Gallery
[20/07/2008|18:12] C:\Program Files\Windows Sidebar
[05/11/2008|21:46] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[24/04/2008|18:03] C:\Program Files\Common Files\Adaptec Shared
[23/12/2008|23:04] C:\Program Files\Common Files\Adobe
[15/08/2008|12:41] C:\Program Files\Common Files\Ahead
[25/04/2008|21:38] C:\Program Files\Common Files\ArcSoft
[03/12/2007|09:39] C:\Program Files\Common Files\DESIGNER
[03/12/2007|09:59] C:\Program Files\Common Files\InstallShield
[24/04/2008|17:38] C:\Program Files\Common Files\Java
[03/12/2007|09:47] C:\Program Files\Common Files\LightScribe
[03/12/2007|09:41] C:\Program Files\Common Files\microsoft shared
[03/12/2007|09:46] C:\Program Files\Common Files\muvee Technologies
[02/08/2008|13:18] C:\Program Files\Common Files\Nero
[03/12/2007|09:47] C:\Program Files\Common Files\NewTech Infosystems
[23/07/2008|10:48] C:\Program Files\Common Files\Oberon Media
[24/07/2008|19:59] C:\Program Files\Common Files\ROUTE 66
[24/04/2008|18:04] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[28/12/2008|23:23] C:\Program Files\Common Files\Symantec Shared
[20/07/2008|18:12] C:\Program Files\Common Files\System
--------------------\\ Process
( 67 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 22:42:11
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwEnumerateKey, ZwQueryKey, ZwOpenKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile, ZwQueryDirectoryFile, ZwQuerySystemInformation
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\AppData\Roaming\Microsoft\Windows\Recent\crack.lnk
[F:216][D:12]-> C:\Users\oliviane\AppData\Local\Temp
[F:138][D:1]-> C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies
[F:136][D:5]-> C:\Users\oliviane\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:15][D:3]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 29/12/2008|22:32 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 29/12/2008|22:43 - Option : [2]
--------------------\\ Fin du rapport a 22:43:14
[ UAC => 1 ]
encore merci
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:79 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 29/12/2008|22:41 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\ProgramData\Okay meta anti lite\Dupe Deaf.dat
Supprime! - C:\ProgramData\Okay meta anti lite\Dupe Deaf.exe
Supprime! - C:\ProgramData\Okay meta anti lite\Roam view.dat
Supprime! - C:\ProgramData\Okay meta anti lite\Roam view.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\DivoCodec.zip
Supprime! - C:\Users\oliviane\AppData\Local\Temp\minime.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\HtmlControl.dll
Supprime! - C:\Users\oliviane\AppData\Local\Temp\codec_dv.bmp
Supprime! - C:\Users\oliviane\AppData\Local\Temp\NSISPromotion.dll
Supprime! - C:\ProgramData\Nouncloseclose.sb95u
Supprime! - C:\ProgramData\Nouncloseclose.u79ej
Supprime! - C:\ProgramData\surf cash remote.2cuff
Supprime! - C:\ProgramData\Nouncloseclose.wy4y37
Supprime! - C:\ProgramData\Plan Lite Chin.k5j4z84
Supprime! - C:\Users\oliviane\AppData\Local\Temp\bis75B6.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\bisAB37.exe
Supprime! - C:\ProgramData\THESEN~1\DvdEnc.exe
Supprime! - C:\ProgramData\THESEN~1\ifpqogra.exe
Supprime! - C:\ProgramData\THESEN~1\ptapehxi.exe
Supprime! - C:\ProgramData\Okay meta anti lite
Supprime! - C:\Program Files\DivoCodec
Supprime! - C:\ProgramData\THESEN~1
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[02/08/2008|10:41] C:\Users\oliviane\AppData\Local\Acer Arcade Live
[20/07/2008|17:37] C:\Users\oliviane\AppData\Local\Acer DVDivine
[24/04/2008|18:00] C:\Users\oliviane\AppData\Local\Adobe
[02/08/2008|13:37] C:\Users\oliviane\AppData\Local\Ahead
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Application Data
[24/07/2008|12:27] C:\Users\oliviane\AppData\Local\Apps
[25/04/2008|21:39] C:\Users\oliviane\AppData\Local\ArcSoft
[29/12/2008|17:48] C:\Users\oliviane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[24/07/2008|20:01] C:\Users\oliviane\AppData\Local\Deployment
[24/07/2008|12:30] C:\Users\oliviane\AppData\Local\Downloaded Installations
[25/04/2008|22:20] C:\Users\oliviane\AppData\Local\GDIPFONTCACHEV1.DAT
[25/04/2008|22:49] C:\Users\oliviane\AppData\Local\Google
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Historique
[29/12/2008|21:11] C:\Users\oliviane\AppData\Local\IconCache.db
[19/10/2008|19:41] C:\Users\oliviane\AppData\Local\IM
[29/11/2008|21:52] C:\Users\oliviane\AppData\Local\Innovative Solutions
[20/07/2008|17:38] C:\Users\oliviane\AppData\Local\MakeDisc
[29/12/2008|21:28] C:\Users\oliviane\AppData\Local\Microsoft
[14/09/2008|14:56] C:\Users\oliviane\AppData\Local\Microsoft Games
[24/04/2008|09:21] C:\Users\oliviane\AppData\Local\PowerCinema
[24/07/2008|20:00] C:\Users\oliviane\AppData\Local\ROUTE 66 Sync
[09/05/2008|23:01] C:\Users\oliviane\AppData\Local\Snapfish Livres de photo
[29/12/2008|22:42] C:\Users\oliviane\AppData\Local\Temp
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Temporary Internet Files
[24/04/2008|17:41] C:\Users\oliviane\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[29/12/2008 09:57][--a------] C:\Windows\tasks\Norton Security Scan for oliviane.job
[26/12/2008 20:56][--a------] C:\Windows\tasks\Norton Internet Security - Analyse systŠme complŠte - oliviane.job
[29/12/2008 21:12][--ah-----] C:\Windows\tasks\SA.DAT
[29/12/2008 21:11][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[03/12/2007|09:42] C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[23/12/2008|23:04] C:\ProgramData\Adobe
[24/04/2008|11:07] C:\ProgramData\Ahead
[02/11/2006|14:02] C:\ProgramData\Application Data
[25/04/2008|22:07] C:\ProgramData\ArcSoft
[18/05/2008|09:32] C:\ProgramData\Azureus
[24/04/2008|09:17] C:\ProgramData\Bureau
[24/04/2008|10:59] C:\ProgramData\CanonBJ
[20/07/2008|17:38] C:\ProgramData\CyberLink
[02/11/2006|14:02] C:\ProgramData\Desktop
[02/11/2006|14:02] C:\ProgramData\Documents
[24/04/2008|09:31] C:\ProgramData\eSobi
[24/04/2008|09:17] C:\ProgramData\Favoris
[02/11/2006|14:02] C:\ProgramData\Favorites
[25/04/2008|09:20] C:\ProgramData\Google
[29/12/2008|11:51] C:\ProgramData\Google Updater
[24/04/2008|12:54] C:\ProgramData\IM
[24/04/2008|12:53] C:\ProgramData\IncrediMail
[10/05/2008|18:35] C:\ProgramData\LightScribe
[24/04/2008|09:17] C:\ProgramData\Menu D‚marrer
[09/05/2008|18:38] C:\ProgramData\Microsoft
[03/12/2007|09:41] C:\ProgramData\Microsoft Help
[24/04/2008|09:17] C:\ProgramData\ModŠles
[13/06/2008|22:58] C:\ProgramData\Nero
[20/12/2008|00:11] C:\ProgramData\NVIDIA
[27/06/2008|13:03] C:\ProgramData\OceanMedia
[22/07/2008|20:47] C:\ProgramData\PlayFirst
[06/06/2008|13:50] C:\ProgramData\PlayPond
[09/05/2008|18:34] C:\ProgramData\Snapfish Livres de photo
[02/11/2006|14:02] C:\ProgramData\Start Menu
[28/12/2008|23:22] C:\ProgramData\Symantec
[22/07/2008|21:25] C:\ProgramData\TEMP
[02/11/2006|14:02] C:\ProgramData\Templates
[05/11/2008|21:46] C:\ProgramData\yahoo!
[19/12/2008|23:54] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[24/04/2008|19:02] C:\Program Files\7-Zip
[03/12/2007|10:08] C:\Program Files\Acer Arcade Live
[23/07/2008|10:56] C:\Program Files\Acer GameZone
[09/03/2008|05:30] C:\Program Files\Acer Inc
[03/12/2007|09:42] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[23/12/2008|23:04] C:\Program Files\Adobe
[15/08/2008|12:41] C:\Program Files\Ahead
[25/04/2008|21:37] C:\Program Files\ArcSoft
[02/08/2008|13:29] C:\Program Files\AskTBar
[09/03/2008|05:28] C:\Program Files\ATI
[28/12/2008|15:13] C:\Program Files\Azureus
[26/07/2008|14:26] C:\Program Files\CCleaner
[02/08/2008|13:53] C:\Program Files\CDBurnerXP
[24/07/2008|19:59] C:\Program Files\Common Files
[03/12/2007|09:59] C:\Program Files\CyberLink
[24/04/2008|18:03] C:\Program Files\directx
[03/12/2007|10:08] C:\Program Files\eSobi
[24/04/2008|09:17] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[07/05/2008|21:01] C:\Program Files\Future Pinball
[25/07/2008|22:29] C:\Program Files\Google
[29/12/2008|18:29] C:\Program Files\GRETECH
[23/07/2008|10:55] C:\Program Files\Incredijeux
[11/08/2008|20:14] C:\Program Files\IncrediMail
[29/11/2008|21:52] C:\Program Files\Innovative Solutions
[08/10/2008|19:35] C:\Program Files\InstallShield Installation Information
[20/07/2008|18:12] C:\Program Files\Internet Explorer
[25/04/2008|09:20] C:\Program Files\Java
[29/12/2008|19:48] C:\Program Files\K-Lite Codec Pack
[02/11/2006|13:37] C:\Program Files\Microsoft Games
[03/12/2007|09:42] C:\Program Files\Microsoft Office
[03/12/2007|09:42] C:\Program Files\Microsoft Works
[03/12/2007|09:39] C:\Program Files\Microsoft.NET
[20/07/2008|18:12] C:\Program Files\Movie Maker
[02/11/2006|13:37] C:\Program Files\MSBuild
[03/12/2007|09:06] C:\Program Files\MSXML 4.0
[29/12/2008|21:28] C:\Program Files\Navilog1
[24/04/2008|10:48] C:\Program Files\Neuf
[03/12/2007|09:47] C:\Program Files\NewTech Infosystems
[30/09/2008|18:13] C:\Program Files\Norton Internet Security
[28/12/2008|23:23] C:\Program Files\Norton Security Scan
[24/04/2008|17:39] C:\Program Files\OpenOffice.org 2.4
[15/10/2008|18:48] C:\Program Files\OptimCr‚dit
[25/04/2008|22:02] C:\Program Files\Panasonic
[25/04/2008|22:49] C:\Program Files\Picasa2
[07/05/2008|21:16] C:\Program Files\Plus!
[03/12/2007|09:34] C:\Program Files\Realtek
[02/11/2006|13:37] C:\Program Files\Reference Assemblies
[24/07/2008|19:59] C:\Program Files\ROUTE 66
[24/04/2008|18:03] C:\Program Files\Roxio
[21/10/2008|21:21] C:\Program Files\sina
[09/05/2008|18:34] C:\Program Files\Snapfish Livres de photo
[30/05/2008|22:15] C:\Program Files\Symantec
[24/04/2008|19:11] C:\Program Files\TVAnts
[02/11/2006|14:01] C:\Program Files\Uninstall Information
[24/04/2008|18:12] C:\Program Files\VideoLAN
[20/07/2008|18:12] C:\Program Files\Windows Calendar
[20/07/2008|18:12] C:\Program Files\Windows Collaboration
[20/07/2008|18:12] C:\Program Files\Windows Defender
[20/07/2008|18:12] C:\Program Files\Windows Journal
[20/07/2008|18:12] C:\Program Files\Windows Mail
[20/07/2008|18:12] C:\Program Files\Windows Media Player
[24/04/2008|09:17] C:\Program Files\Windows NT
[20/07/2008|18:12] C:\Program Files\Windows Photo Gallery
[20/07/2008|18:12] C:\Program Files\Windows Sidebar
[05/11/2008|21:46] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[24/04/2008|18:03] C:\Program Files\Common Files\Adaptec Shared
[23/12/2008|23:04] C:\Program Files\Common Files\Adobe
[15/08/2008|12:41] C:\Program Files\Common Files\Ahead
[25/04/2008|21:38] C:\Program Files\Common Files\ArcSoft
[03/12/2007|09:39] C:\Program Files\Common Files\DESIGNER
[03/12/2007|09:59] C:\Program Files\Common Files\InstallShield
[24/04/2008|17:38] C:\Program Files\Common Files\Java
[03/12/2007|09:47] C:\Program Files\Common Files\LightScribe
[03/12/2007|09:41] C:\Program Files\Common Files\microsoft shared
[03/12/2007|09:46] C:\Program Files\Common Files\muvee Technologies
[02/08/2008|13:18] C:\Program Files\Common Files\Nero
[03/12/2007|09:47] C:\Program Files\Common Files\NewTech Infosystems
[23/07/2008|10:48] C:\Program Files\Common Files\Oberon Media
[24/07/2008|19:59] C:\Program Files\Common Files\ROUTE 66
[24/04/2008|18:04] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[28/12/2008|23:23] C:\Program Files\Common Files\Symantec Shared
[20/07/2008|18:12] C:\Program Files\Common Files\System
--------------------\\ Process
( 67 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 22:42:11
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwEnumerateKey, ZwQueryKey, ZwOpenKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile, ZwQueryDirectoryFile, ZwQuerySystemInformation
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\AppData\Roaming\Microsoft\Windows\Recent\crack.lnk
[F:216][D:12]-> C:\Users\oliviane\AppData\Local\Temp
[F:138][D:1]-> C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies
[F:136][D:5]-> C:\Users\oliviane\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:15][D:3]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 29/12/2008|22:32 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 29/12/2008|22:43 - Option : [2]
--------------------\\ Fin du rapport a 22:43:14
[ UAC => 1 ]
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:79 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 29/12/2008|22:41 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\ProgramData\Okay meta anti lite\Dupe Deaf.dat
Supprime! - C:\ProgramData\Okay meta anti lite\Dupe Deaf.exe
Supprime! - C:\ProgramData\Okay meta anti lite\Roam view.dat
Supprime! - C:\ProgramData\Okay meta anti lite\Roam view.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\DivoCodec.zip
Supprime! - C:\Users\oliviane\AppData\Local\Temp\minime.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\HtmlControl.dll
Supprime! - C:\Users\oliviane\AppData\Local\Temp\codec_dv.bmp
Supprime! - C:\Users\oliviane\AppData\Local\Temp\NSISPromotion.dll
Supprime! - C:\ProgramData\Nouncloseclose.sb95u
Supprime! - C:\ProgramData\Nouncloseclose.u79ej
Supprime! - C:\ProgramData\surf cash remote.2cuff
Supprime! - C:\ProgramData\Nouncloseclose.wy4y37
Supprime! - C:\ProgramData\Plan Lite Chin.k5j4z84
Supprime! - C:\Users\oliviane\AppData\Local\Temp\bis75B6.exe
Supprime! - C:\Users\oliviane\AppData\Local\Temp\bisAB37.exe
Supprime! - C:\ProgramData\THESEN~1\DvdEnc.exe
Supprime! - C:\ProgramData\THESEN~1\ifpqogra.exe
Supprime! - C:\ProgramData\THESEN~1\ptapehxi.exe
Supprime! - C:\ProgramData\Okay meta anti lite
Supprime! - C:\Program Files\DivoCodec
Supprime! - C:\ProgramData\THESEN~1
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[02/08/2008|10:41] C:\Users\oliviane\AppData\Local\Acer Arcade Live
[20/07/2008|17:37] C:\Users\oliviane\AppData\Local\Acer DVDivine
[24/04/2008|18:00] C:\Users\oliviane\AppData\Local\Adobe
[02/08/2008|13:37] C:\Users\oliviane\AppData\Local\Ahead
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Application Data
[24/07/2008|12:27] C:\Users\oliviane\AppData\Local\Apps
[25/04/2008|21:39] C:\Users\oliviane\AppData\Local\ArcSoft
[29/12/2008|17:48] C:\Users\oliviane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[24/07/2008|20:01] C:\Users\oliviane\AppData\Local\Deployment
[24/07/2008|12:30] C:\Users\oliviane\AppData\Local\Downloaded Installations
[25/04/2008|22:20] C:\Users\oliviane\AppData\Local\GDIPFONTCACHEV1.DAT
[25/04/2008|22:49] C:\Users\oliviane\AppData\Local\Google
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Historique
[29/12/2008|21:11] C:\Users\oliviane\AppData\Local\IconCache.db
[19/10/2008|19:41] C:\Users\oliviane\AppData\Local\IM
[29/11/2008|21:52] C:\Users\oliviane\AppData\Local\Innovative Solutions
[20/07/2008|17:38] C:\Users\oliviane\AppData\Local\MakeDisc
[29/12/2008|21:28] C:\Users\oliviane\AppData\Local\Microsoft
[14/09/2008|14:56] C:\Users\oliviane\AppData\Local\Microsoft Games
[24/04/2008|09:21] C:\Users\oliviane\AppData\Local\PowerCinema
[24/07/2008|20:00] C:\Users\oliviane\AppData\Local\ROUTE 66 Sync
[09/05/2008|23:01] C:\Users\oliviane\AppData\Local\Snapfish Livres de photo
[29/12/2008|22:42] C:\Users\oliviane\AppData\Local\Temp
[24/04/2008|09:20] C:\Users\oliviane\AppData\Local\Temporary Internet Files
[24/04/2008|17:41] C:\Users\oliviane\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[29/12/2008 09:57][--a------] C:\Windows\tasks\Norton Security Scan for oliviane.job
[26/12/2008 20:56][--a------] C:\Windows\tasks\Norton Internet Security - Analyse systŠme complŠte - oliviane.job
[29/12/2008 21:12][--ah-----] C:\Windows\tasks\SA.DAT
[29/12/2008 21:11][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[03/12/2007|09:42] C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[23/12/2008|23:04] C:\ProgramData\Adobe
[24/04/2008|11:07] C:\ProgramData\Ahead
[02/11/2006|14:02] C:\ProgramData\Application Data
[25/04/2008|22:07] C:\ProgramData\ArcSoft
[18/05/2008|09:32] C:\ProgramData\Azureus
[24/04/2008|09:17] C:\ProgramData\Bureau
[24/04/2008|10:59] C:\ProgramData\CanonBJ
[20/07/2008|17:38] C:\ProgramData\CyberLink
[02/11/2006|14:02] C:\ProgramData\Desktop
[02/11/2006|14:02] C:\ProgramData\Documents
[24/04/2008|09:31] C:\ProgramData\eSobi
[24/04/2008|09:17] C:\ProgramData\Favoris
[02/11/2006|14:02] C:\ProgramData\Favorites
[25/04/2008|09:20] C:\ProgramData\Google
[29/12/2008|11:51] C:\ProgramData\Google Updater
[24/04/2008|12:54] C:\ProgramData\IM
[24/04/2008|12:53] C:\ProgramData\IncrediMail
[10/05/2008|18:35] C:\ProgramData\LightScribe
[24/04/2008|09:17] C:\ProgramData\Menu D‚marrer
[09/05/2008|18:38] C:\ProgramData\Microsoft
[03/12/2007|09:41] C:\ProgramData\Microsoft Help
[24/04/2008|09:17] C:\ProgramData\ModŠles
[13/06/2008|22:58] C:\ProgramData\Nero
[20/12/2008|00:11] C:\ProgramData\NVIDIA
[27/06/2008|13:03] C:\ProgramData\OceanMedia
[22/07/2008|20:47] C:\ProgramData\PlayFirst
[06/06/2008|13:50] C:\ProgramData\PlayPond
[09/05/2008|18:34] C:\ProgramData\Snapfish Livres de photo
[02/11/2006|14:02] C:\ProgramData\Start Menu
[28/12/2008|23:22] C:\ProgramData\Symantec
[22/07/2008|21:25] C:\ProgramData\TEMP
[02/11/2006|14:02] C:\ProgramData\Templates
[05/11/2008|21:46] C:\ProgramData\yahoo!
[19/12/2008|23:54] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[24/04/2008|19:02] C:\Program Files\7-Zip
[03/12/2007|10:08] C:\Program Files\Acer Arcade Live
[23/07/2008|10:56] C:\Program Files\Acer GameZone
[09/03/2008|05:30] C:\Program Files\Acer Inc
[03/12/2007|09:42] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[23/12/2008|23:04] C:\Program Files\Adobe
[15/08/2008|12:41] C:\Program Files\Ahead
[25/04/2008|21:37] C:\Program Files\ArcSoft
[02/08/2008|13:29] C:\Program Files\AskTBar
[09/03/2008|05:28] C:\Program Files\ATI
[28/12/2008|15:13] C:\Program Files\Azureus
[26/07/2008|14:26] C:\Program Files\CCleaner
[02/08/2008|13:53] C:\Program Files\CDBurnerXP
[24/07/2008|19:59] C:\Program Files\Common Files
[03/12/2007|09:59] C:\Program Files\CyberLink
[24/04/2008|18:03] C:\Program Files\directx
[03/12/2007|10:08] C:\Program Files\eSobi
[24/04/2008|09:17] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[07/05/2008|21:01] C:\Program Files\Future Pinball
[25/07/2008|22:29] C:\Program Files\Google
[29/12/2008|18:29] C:\Program Files\GRETECH
[23/07/2008|10:55] C:\Program Files\Incredijeux
[11/08/2008|20:14] C:\Program Files\IncrediMail
[29/11/2008|21:52] C:\Program Files\Innovative Solutions
[08/10/2008|19:35] C:\Program Files\InstallShield Installation Information
[20/07/2008|18:12] C:\Program Files\Internet Explorer
[25/04/2008|09:20] C:\Program Files\Java
[29/12/2008|19:48] C:\Program Files\K-Lite Codec Pack
[02/11/2006|13:37] C:\Program Files\Microsoft Games
[03/12/2007|09:42] C:\Program Files\Microsoft Office
[03/12/2007|09:42] C:\Program Files\Microsoft Works
[03/12/2007|09:39] C:\Program Files\Microsoft.NET
[20/07/2008|18:12] C:\Program Files\Movie Maker
[02/11/2006|13:37] C:\Program Files\MSBuild
[03/12/2007|09:06] C:\Program Files\MSXML 4.0
[29/12/2008|21:28] C:\Program Files\Navilog1
[24/04/2008|10:48] C:\Program Files\Neuf
[03/12/2007|09:47] C:\Program Files\NewTech Infosystems
[30/09/2008|18:13] C:\Program Files\Norton Internet Security
[28/12/2008|23:23] C:\Program Files\Norton Security Scan
[24/04/2008|17:39] C:\Program Files\OpenOffice.org 2.4
[15/10/2008|18:48] C:\Program Files\OptimCr‚dit
[25/04/2008|22:02] C:\Program Files\Panasonic
[25/04/2008|22:49] C:\Program Files\Picasa2
[07/05/2008|21:16] C:\Program Files\Plus!
[03/12/2007|09:34] C:\Program Files\Realtek
[02/11/2006|13:37] C:\Program Files\Reference Assemblies
[24/07/2008|19:59] C:\Program Files\ROUTE 66
[24/04/2008|18:03] C:\Program Files\Roxio
[21/10/2008|21:21] C:\Program Files\sina
[09/05/2008|18:34] C:\Program Files\Snapfish Livres de photo
[30/05/2008|22:15] C:\Program Files\Symantec
[24/04/2008|19:11] C:\Program Files\TVAnts
[02/11/2006|14:01] C:\Program Files\Uninstall Information
[24/04/2008|18:12] C:\Program Files\VideoLAN
[20/07/2008|18:12] C:\Program Files\Windows Calendar
[20/07/2008|18:12] C:\Program Files\Windows Collaboration
[20/07/2008|18:12] C:\Program Files\Windows Defender
[20/07/2008|18:12] C:\Program Files\Windows Journal
[20/07/2008|18:12] C:\Program Files\Windows Mail
[20/07/2008|18:12] C:\Program Files\Windows Media Player
[24/04/2008|09:17] C:\Program Files\Windows NT
[20/07/2008|18:12] C:\Program Files\Windows Photo Gallery
[20/07/2008|18:12] C:\Program Files\Windows Sidebar
[05/11/2008|21:46] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[24/04/2008|18:03] C:\Program Files\Common Files\Adaptec Shared
[23/12/2008|23:04] C:\Program Files\Common Files\Adobe
[15/08/2008|12:41] C:\Program Files\Common Files\Ahead
[25/04/2008|21:38] C:\Program Files\Common Files\ArcSoft
[03/12/2007|09:39] C:\Program Files\Common Files\DESIGNER
[03/12/2007|09:59] C:\Program Files\Common Files\InstallShield
[24/04/2008|17:38] C:\Program Files\Common Files\Java
[03/12/2007|09:47] C:\Program Files\Common Files\LightScribe
[03/12/2007|09:41] C:\Program Files\Common Files\microsoft shared
[03/12/2007|09:46] C:\Program Files\Common Files\muvee Technologies
[02/08/2008|13:18] C:\Program Files\Common Files\Nero
[03/12/2007|09:47] C:\Program Files\Common Files\NewTech Infosystems
[23/07/2008|10:48] C:\Program Files\Common Files\Oberon Media
[24/07/2008|19:59] C:\Program Files\Common Files\ROUTE 66
[24/04/2008|18:04] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[28/12/2008|23:23] C:\Program Files\Common Files\Symantec Shared
[20/07/2008|18:12] C:\Program Files\Common Files\System
--------------------\\ Process
( 67 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 22:42:11
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwEnumerateKey, ZwQueryKey, ZwOpenKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile, ZwQueryDirectoryFile, ZwQuerySystemInformation
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\AppData\Roaming\Microsoft\Windows\Recent\crack.lnk
[F:216][D:12]-> C:\Users\oliviane\AppData\Local\Temp
[F:138][D:1]-> C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies
[F:136][D:5]-> C:\Users\oliviane\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:15][D:3]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 29/12/2008|22:32 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 29/12/2008|22:43 - Option : [2]
--------------------\\ Fin du rapport a 22:43:14
[ UAC => 1 ]
OK
Maintenant, fais un Hijackthis pour vérifier su'il n'y a pas d'autres problèmes :
Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
* Enregistre HJTInstall.exe sur ton bureau.
* Double-clique sur HJTInstall.exe pour lancer le programme
Tuto : https://www.malekal.com/tutoriel-hijackthis/
http://pagesperso-orange.fr/rginformatique/section%20virus/Hijenr.gif
http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
* Accepte la license en cliquant sur le bouton "I Accept"
* Choisis l'option "Do a system scan and save a log file"
* Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
* Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
* Colle le rapport que tu viens de copier sur ce forum
Maintenant, fais un Hijackthis pour vérifier su'il n'y a pas d'autres problèmes :
Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
* Enregistre HJTInstall.exe sur ton bureau.
* Double-clique sur HJTInstall.exe pour lancer le programme
Tuto : https://www.malekal.com/tutoriel-hijackthis/
http://pagesperso-orange.fr/rginformatique/section%20virus/Hijenr.gif
http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
* Accepte la license en cliquant sur le bouton "I Accept"
* Choisis l'option "Do a system scan and save a log file"
* Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
* Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
* Colle le rapport que tu viens de copier sur ce forum
excuse du retard j'apprends
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:26:24, on 29/12/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Innovative Solutions\DriverMax\devices.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Users\oliviane\Downloads\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file)
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/30.66/uploader2.cab
O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:26:24, on 29/12/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Innovative Solutions\DriverMax\devices.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Users\oliviane\Downloads\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file)
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/30.66/uploader2.cab
O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Une autre petite infection à traiter :
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
bonjour je rentre du boulo
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:81 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 30/12/2008|12:12 )
[ UAC => 1 ]
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskTBar
C:\Program Files\AskTBar\bar
C:\Program Files\AskTBar\SrchAstt
C:\Program Files\AskTBar\bar\1.bin
C:\Program Files\AskTBar\bar\Cache
C:\Program Files\AskTBar\bar\History
C:\Program Files\AskTBar\bar\Settings
C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
C:\Program Files\AskTBar\bar\Cache\0036DA29.bin
C:\Program Files\AskTBar\bar\Cache\0036DB90.bin
C:\Program Files\AskTBar\bar\Cache\0036DCC8.bin
C:\Program Files\AskTBar\bar\Cache\0036DE00.bin
C:\Program Files\AskTBar\bar\Cache\02925482
C:\Program Files\AskTBar\bar\Cache\files.ini
C:\Program Files\AskTBar\bar\History\search2
C:\Program Files\AskTBar\bar\Settings\prevcfg2.htm
C:\Program Files\AskTBar\SrchAstt\1.bin
C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies\oliviane@mysearch[1].txt
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl"
"SEARCH PAGE"="https://www.google.com/?gws_rd=ssl"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"Start Page Restore"="https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl"
"Url"="https://www.msn.com/fr-fr/actualite/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://fr.yahoo.com/"
"Default_Page_URL"="https://fr.yahoo.com/"
"Default_Search_URL"="https://actus.sfr.fr"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\AppData\Roaming\Microsoft\Windows\Recent\crack.lnk
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 30/12/2008|12:12 - Option : [1]
-----------\\ Fin du rapport a 12:12:38,03
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:81 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 30/12/2008|12:12 )
[ UAC => 1 ]
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskTBar
C:\Program Files\AskTBar\bar
C:\Program Files\AskTBar\SrchAstt
C:\Program Files\AskTBar\bar\1.bin
C:\Program Files\AskTBar\bar\Cache
C:\Program Files\AskTBar\bar\History
C:\Program Files\AskTBar\bar\Settings
C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
C:\Program Files\AskTBar\bar\Cache\0036DA29.bin
C:\Program Files\AskTBar\bar\Cache\0036DB90.bin
C:\Program Files\AskTBar\bar\Cache\0036DCC8.bin
C:\Program Files\AskTBar\bar\Cache\0036DE00.bin
C:\Program Files\AskTBar\bar\Cache\02925482
C:\Program Files\AskTBar\bar\Cache\files.ini
C:\Program Files\AskTBar\bar\History\search2
C:\Program Files\AskTBar\bar\Settings\prevcfg2.htm
C:\Program Files\AskTBar\SrchAstt\1.bin
C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies\oliviane@mysearch[1].txt
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl"
"SEARCH PAGE"="https://www.google.com/?gws_rd=ssl"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"Start Page Restore"="https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl"
"Url"="https://www.msn.com/fr-fr/actualite/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://fr.yahoo.com/"
"Default_Page_URL"="https://fr.yahoo.com/"
"Default_Search_URL"="https://actus.sfr.fr"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\AppData\Roaming\Microsoft\Windows\Recent\crack.lnk
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 30/12/2008|12:12 - Option : [1]
-----------\\ Fin du rapport a 12:12:38,03
Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.
NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.
NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
bonsoir et merci pour toute l'aide que tu m'apporte
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:79 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 30/12/2008|20:57 )
[ UAC => 1 ]
-----------\\ SUPPRESSION
Echec ! - C:\Program Files\AskTBar\bar
Echec ! - C:\Program Files\AskTBar\SrchAstt
Echec ! - C:\Program Files\AskTBar\bar\1.bin
Echec ! - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
Supprime! - C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies\oliviane@mysearch[1].txt
Echec ! - C:\Program Files\AskTBar
-----------\\ DEUXIEME PASSAGE
Echec ! - C:\Program Files\AskTBar\bar
Echec ! - C:\Program Files\AskTBar\SrchAstt
Echec ! - C:\Program Files\AskTBar\bar\1.bin
Echec ! - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
Echec ! - C:\Program Files\AskTBar
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskTBar
C:\Program Files\AskTBar\bar
C:\Program Files\AskTBar\SrchAstt
C:\Program Files\AskTBar\bar\1.bin
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
C:\Program Files\AskTBar\SrchAstt\1.bin
C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl"
"SEARCH PAGE"="https://www.google.com/?gws_rd=ssl"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"Start Page Restore"="https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl"
"Url"="https://www.msn.com/fr-fr/actualite/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="https://fr.yahoo.com/"
"Default_Search_URL"="https://actus.sfr.fr"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\AppData\Roaming\Microsoft\Windows\Recent\crack.lnk
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 30/12/2008|12:12 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 30/12/2008|20:57 - Option : [2]
-----------\\ Fin du rapport a 20:57:38,12
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:79 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 30/12/2008|20:57 )
[ UAC => 1 ]
-----------\\ SUPPRESSION
Echec ! - C:\Program Files\AskTBar\bar
Echec ! - C:\Program Files\AskTBar\SrchAstt
Echec ! - C:\Program Files\AskTBar\bar\1.bin
Echec ! - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
Supprime! - C:\Users\oliviane\AppData\Roaming\MICROS~1\Windows\Cookies\oliviane@mysearch[1].txt
Echec ! - C:\Program Files\AskTBar
-----------\\ DEUXIEME PASSAGE
Echec ! - C:\Program Files\AskTBar\bar
Echec ! - C:\Program Files\AskTBar\SrchAstt
Echec ! - C:\Program Files\AskTBar\bar\1.bin
Echec ! - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
Echec ! - C:\Program Files\AskTBar
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskTBar
C:\Program Files\AskTBar\bar
C:\Program Files\AskTBar\SrchAstt
C:\Program Files\AskTBar\bar\1.bin
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
C:\Program Files\AskTBar\SrchAstt\1.bin
C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl"
"SEARCH PAGE"="https://www.google.com/?gws_rd=ssl"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"Start Page Restore"="https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl"
"Url"="https://www.msn.com/fr-fr/actualite/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="https://fr.yahoo.com/"
"Default_Search_URL"="https://actus.sfr.fr"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\oliviane\AppData\Roaming\Microsoft\Windows\Recent\crack.lnk
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 30/12/2008|12:12 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 30/12/2008|20:57 - Option : [2]
-----------\\ Fin du rapport a 20:57:38,12
OK, tu peux refaire un Hijackthis stp.
voila
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:15:25, on 30/12/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Innovative Solutions\DriverMax\devices.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Users\oliviane\Downloads\Nettoyage Aide\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file)
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/30.66/uploader2.cab
O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:15:25, on 30/12/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Innovative Solutions\DriverMax\devices.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Users\oliviane\Downloads\Nettoyage Aide\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file)
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/30.66/uploader2.cab
O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Imprime ces instructions ou sauvegarde les sur ton Bureau car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :
https://download.cnet.com/Malwarebytes/3000-8022_4-10804572.html
A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.
Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.
Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.
MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :
Dans l'onglet analyse, vérifie que "Exécuter un examen rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.
MBAM analyse ton ordinateur. L'analyse peut prendre un certain teps. Il suffit de vérifier de temps en temps son avancement.
A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.
Si des malwares ont été détectés, leur liste s'affiche.
En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)
Ferme MBAM en cliquant sur Quitter.
Poste le rapport sur le forum.
Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :
https://download.cnet.com/Malwarebytes/3000-8022_4-10804572.html
A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.
Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.
Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.
MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :
Dans l'onglet analyse, vérifie que "Exécuter un examen rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.
MBAM analyse ton ordinateur. L'analyse peut prendre un certain teps. Il suffit de vérifier de temps en temps son avancement.
A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.
Si des malwares ont été détectés, leur liste s'affiche.
En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)
Ferme MBAM en cliquant sur Quitter.
Poste le rapport sur le forum.
bonsoir et
Une trés Bonne Année
voici le Rapport
Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1596
Windows 6.0.6001 Service Pack 1
02/01/2009 17:47:27
mbam-log-2009-01-02 (17-47-27).txt
Type de recherche: Examen rapide
Eléments examinés: 49551
Temps écoulé: 2 minute(s), 17 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Une trés Bonne Année
voici le Rapport
Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1596
Windows 6.0.6001 Service Pack 1
02/01/2009 17:47:27
mbam-log-2009-01-02 (17-47-27).txt
Type de recherche: Examen rapide
Eléments examinés: 49551
Temps écoulé: 2 minute(s), 17 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
* Télécharge CCleaner.
(attention à l'installation penser à DECOCHER l'installation de Yahoo toolbar discrètement proposé en plus de CCleaner).
https://www.pcastuces.com/logitheque/ccleaner.htm
https://www.commentcamarche.net/telecharger/ 168 ccleaner
Installe le dans un répertoire dédié.
Décoche pendant l'installation
--- les deux cases "Ajouter l'option ... "
--- Contrôler les mises à jour
* Lance Ccleaner pour un nettoyage complet :
Déconnecte-toi et ferme toutes les applications en cours
* va dans "nettoyeur" : fait analyse puis nettoyage
* va dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
Tutorial ici :
https://kerio.probb.fr/
https://www.malekal.com/tutoriel-ccleaner/
ET
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
(attention à l'installation penser à DECOCHER l'installation de Yahoo toolbar discrètement proposé en plus de CCleaner).
https://www.pcastuces.com/logitheque/ccleaner.htm
https://www.commentcamarche.net/telecharger/ 168 ccleaner
Installe le dans un répertoire dédié.
Décoche pendant l'installation
--- les deux cases "Ajouter l'option ... "
--- Contrôler les mises à jour
* Lance Ccleaner pour un nettoyage complet :
Déconnecte-toi et ferme toutes les applications en cours
* va dans "nettoyeur" : fait analyse puis nettoyage
* va dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
Tutorial ici :
https://kerio.probb.fr/
https://www.malekal.com/tutoriel-ccleaner/
ET
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 01/29/08 14:43:24 Ver: 08.00.15
USER : oliviane ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:79 Go)
D:\ (Local Disk) - NTFS - Total:144 Go (Free:143 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
Recherche executé en mode normal
*** Recherche Programmes installés ***
*** Recherche dossiers dans "C:\Windows" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***
*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***
*** Recherche dossiers dans "C:\ProgramData" ***
*** Recherche dossiers dans "c:\users\oliviane\appdata\roaming\micros~1\windows\startm~1\programs" ***
*** Recherche dossiers dans "C:\Users\oliviane\AppData\Local\virtualstore\Program Files" ***
*** Recherche dossiers dans "C:\Users\oliviane\AppData\Roaming" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\Windows\system32" *
* Recherche dans "C:\Users\oliviane\AppData\Local\Microsoft" *
* Recherche dans "C:\Users\oliviane\AppData\Local\virtualstore\windows\system32" *
* Recherche dans "C:\Users\oliviane\AppData\Local" *
*** Recherche fichiers ***
*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\Windows\system32" :
* Dans "C:\Users\oliviane\AppData\Local\Microsoft" :
* Dans "C:\Users\oliviane\AppData\Local\virtualstore\windows\system32" :
* Dans "C:\Users\oliviane\AppData\Local" :
3)Recherche Certificats :
Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche autres dossiers et fichiers connus :
C:\ProgramData\Nouncloseclose.sb95u trouvé ! Infection Lop possible non traitée par cet outil !
C:\ProgramData\Nouncloseclose.u79ej trouvé ! Infection Lop possible non traitée par cet outil !
C:\ProgramData\surf cash remote.2cuff trouvé ! Infection Lop possible non traitée par cet outil !
C:\ProgramData\Nouncloseclose.wy4y37 trouvé ! Infection Lop possible non traitée par cet outil !
C:\ProgramData\Plan Lite Chin.k5j4z84 trouvé ! Infection Lop possible non traitée par cet outil !
*** Analyse terminée le 29/12/2008 à 21:28:27,90 ***